- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-29-2026 02:29 PM
We are currently experiencing a situation in which we are receiving requests to our public segment pool. According to a syslog that Palo Alto sends to our SIEM, many of these IP addresses are part of a botnet. However, when we checked Palo Alto, we did not see this information in the traffic log.
However, the cliente cannot apply 24 ip address because they do not have an internal server to feed the firewall. My recommendation was to get GITHUB and its raw. Then, we applied as a source , but they firewall did not show up the IPS in question.
By any chance that you have any recommendations about it.
Any kind of help would be highly cherished.
Best Regards,
06-29-2026 04:27 PM - edited 06-29-2026 04:44 PM
Hello @F.Pinar
thank you for post!
It is common to see IP addresses associated with known scanners, attackers, malicious actors in the logs hitting resources that are publicly available. When it comes to security detection you should be looking into Threat logs instead of Traffic logs. In the Threat logs refer to columns: Type, Threat ID/Name, Threat Category. As a basic layer of protection I would recommend to configure a policy with Palo Alto's built-in EDL lists: Built-in External Dynamic Lists as a source and destination your public subnet and action deny. With this policy in place you can block know IP addresses based on Palo Alto's threat intelligence before it even gets to signature based inspection.
Additionally, Firewall can only block traffic that can inspect, therefore if you have publicly available services serving HTTPS you should consider to implement Inbound SSL Decryption. Here is a reference: How to Configure SSL Decryption. With Inbound SSL Decryption in place Firewall has a certificate that server has and is able to block traffic based on threat type before it reaches server.
Regarding points you highlighted below are my comments:
Regarding your last comment with GitHub, could you provide more information? Palo Alto has hosted EDL with all GitHub IPs: EDL Hosting Service GitHub.
Thank you and Regards
Pavel
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

