EDL in Panorama

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

EDL in Panorama

L1 Bithead

Hi all,

i've configured a couple of EDL in Panorama as shared list and pushed to all the devices.

No problem at this point.

Now,if i check the accessibility of the URL is normally available

test (002).png

But if i try to list all the domains ,the output is always 0 entries.

 

list_entry (002).png

the test source URL is successfull from both Panorama and local device.

I tried to connect to local device trough Panorama and trough his own MGMT IP and result is the same.

I've to say that i not still configured EDL in any policy,so is possible that is working anyway(altough i don't believe).

Any tips?

TIA,

MG

1 accepted solution

Accepted Solutions

L2 Linker

Hi @MGMGMG 

 

You are right to think that the EDL should be called in a security policy for the IPs/Domains to the reflected. The idea behind is that the firewall does not fetch the EDL information which are not being referenced in a policy on firewall. 

This is a similar post. Also, this KB can be helpful.

 

Regards,

View solution in original post

4 REPLIES 4

L2 Linker

Hi @MGMGMG 

 

You are right to think that the EDL should be called in a security policy for the IPs/Domains to the reflected. The idea behind is that the firewall does not fetch the EDL information which are not being referenced in a policy on firewall. 

This is a similar post. Also, this KB can be helpful.

 

Regards,

L1 Bithead

Hi Arnesh,

many thanks for your answer.

Just one more advise,i configured an iplist.txt and a domainlist.txt both as URL list,is this best practice or better configure them as IP list and DOMAIN list respectively?

TIA,

 

MG

Hi MG,

 

We need to make sure that the an external dynamic list of one type —IP address, URL or Domain—must include entries of that type only. Please refer Formatting Guidelines for an External Dynamic List

 

Regards,

L1 Bithead

Hi there,

again thanks for your reply.

Checked the link and found that  domain ending in .txt has to be URL.

Solved!

Thanks,

MG

  • 1 accepted solution
  • 1916 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!