Blocking external IP addresses and blacklists

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Blocking external IP addresses and blacklists

L0 Member

Hi,

 

I have some questions regarding the PAN-OS and blocking IP addresses. 

 

We are getting daily emails with lists of IP's that are port scanning and probing th FW. The customer wants all these addresses blocked. For example over the last 2 weeks I have around 60 addresses to add. At the minute the process is to add each IP under objects > Addresses and then add the address object in to an address group object that blocks these addresses.

 

Is there a better way of doing this? I have found an article on External Dynamic Lists and using an interal web server which looks like a good option. 

 

The other question I have is when I put these addresses in to a blacklist checker most of the come up on external blacklists. Is there a way of using these blacklists to block the traffic instead of keeping our own list?

 

Thanks in advance,

Luke

11 REPLIES 11

L2 Linker

Question what pan os version are you using . I'm on 8.0.x and it has a built in  External Block list that you can add to your Security rules.

L1 Bithead

This will show you how to blacklist IP addresses automatically and place them in a firewall rule autoamtically.

 

https://www.smartcloudcomputing.net/2021/02/22/how-to-automatically-blacklist-an-attackers-ip-on-pal...

@ OtakarKlier

I am Access Denied to both of those links.

 

Hello,

I would say just go with the several built in lists. Stay with more behavioral based approaches along with a secure DNS provider.

 

https://live.paloaltonetworks.com/t5/learning-articles/working-with-external-block-list-ebl-formats-...

 

Regards,

RGPT-asmith_0-1617981732986.png

 

A bit frustrating when looking for help and all the links come up like this.  Including this latest one.

Agreed. Hope you got the info you needed.

Have you tried MineMeld?

unfortunately - those links don't work anymore, so there is no point in trying to see them...


Please mark helpful responses, so others know as well

so I did the next best thing and googled it...

 

https://www.google.com/search?q=how-to-automatically-blacklist-an-attackers-ip-on-palo-alto&rlz=1C1G...

 Thank you for the likes 🙂


Please mark helpful responses, so others know as well
  • 22001 Views
  • 11 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!