Submit IP to known malicious IP or High Risk IP

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Submit IP to known malicious IP or High Risk IP

L2 Linker

Can an IP be submitted to Palo Alto to be included in the high-risk or known-malicious IP address lists? We have an IP that has been discovered to be a major DDOS attack BOT coordination point but it's not listed in PAN's threat vault and is not being blocked by our IP list block rules. Talos and other sites lists this as a high risk IP but I'm not seeing anyway to get it on PANs list short of trying to deliver some questionable traffic to the IP and hope that Wildfire picks it up.

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

@JoshuaSanders,

There's not a process for customers to request an IP get added to either of these lists. I'd recommend setting up something that you can easily feed into the firewall for manual IP blocking in cases like this. That can be a manual blacklist entry that you manually update, or you could setup an EDL that can be dynamically updated on a schedule on the firewall so you aren't having to commit just to block an address.

As for sending telemetry to the firewall, you can review the documentation on that HERE

View solution in original post

4 REPLIES 4

Cyber Elite
Cyber Elite

Hello,

I'm sure you can open a ticket and enter all of you evidence. What I do is just setup my telemetry to send to PAN so they make the calls that way. Since your PAN should be blocking it, honestly playing IP whack a mole is tough and not really worth the effort. Submit a ticket to the owner abuse email address?

Regards,

How are you sending your telemetry to PAN?

Cyber Elite
Cyber Elite

@JoshuaSanders,

There's not a process for customers to request an IP get added to either of these lists. I'd recommend setting up something that you can easily feed into the firewall for manual IP blocking in cases like this. That can be a manual blacklist entry that you manually update, or you could setup an EDL that can be dynamically updated on a schedule on the firewall so you aren't having to commit just to block an address.

As for sending telemetry to the firewall, you can review the documentation on that HERE

L0 Member

I found an IP in our logs that has been scanning our network lately. I do not see the IP address in any of the PA Predefined External Dynamic Lists (I.e. Tor Exist IP Address, Bulletproof IP, etc.). However, I do see it on https://www.abuseipdb.com/ as a repeat offender. 

Any suggestions on what URL I could use to pull the this IP address. 

  • 1 accepted solution
  • 15610 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!