Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who Me Too'd this solution

L1 Bithead

Ok i have found thats the problem.

After creating EDL even if you see "source is accessible" with url test button it ALWAYS display 0.0.0.0/32 same in CLI.

Even if you do CLI request system external-list show type ip name EDL_NAME it will show the erorr from previous post.

To fix it you need to have policy rule which is pointing to the EDL. If you do so, after policy push edl will display IPs inside. This is imo stupid and should be changed, unless there is some more deeper logic which i cant understand due to limitation of my small brain:)

admin@Firewall_PA-220> request system external-list show type ip name apache2_steam2

apache2_steam2
Total valid entries : 56
Total ignored entries : 0
Total invalid entries : 0
Total displayed entries : 56
Valid ips:
103.10.124.0/24
103.10.125.0/24
103.28.54.0/23
146.66.152.0/23

 

wjt82918_0-1596884786820.png

 

View solution in original post

Who Me Too'd this solution