Enable Advanced IP Defense (PAN-OS 12.1.x and 11.2.x)
Focus
Focus
Advanced IP Defense

Enable Advanced IP Defense (PAN-OS 12.1.x and 11.2.x)

Table of Contents


Enable Advanced IP Defense (PAN-OS 12.1.x and 11.2.x)

Configure Advanced IP Defense on PAN-OS 12.1.x and 11.2.x using predefined External Dynamic Lists (EDLs) to block malicious IP addresses.
Where Can I Use This?What Do I Need?
  • PAN-OS 12.1.x
  • PAN-OS 11.2.x
  • Panorama
  • Advanced IP Defense license
  • Latest content package installed
  • Admin access to firewall or Panorama
For PAN-OS 12.1.x and 11.2.x, Advanced IP Defense is available through predefined External Dynamic Lists (EDLs) that are automatically delivered via content updates. These EDLs contain a curated subset of high-risk malicious IP addresses identified by the Advanced IP Defense cloud service, allowing you to block threats without requiring the latest AIPD security profiles.
  1. Log in to your firewall or Panorama.
    Use your admin credentials to access the web interface.
  2. Verify that you have an active Advanced IP Defense license.
    Select DeviceLicenses and verify that the Advanced IP Defense license is available and has not expired.
  3. Update to the latest content package.
    Select DeviceDynamic Updates and check for the latest content release. The Advanced IP Defense EDLs are delivered through the content package.
  4. Verify that the Advanced IP Defense EDLs are available.
    Select ObjectsExternal Dynamic Lists and look for predefined EDLs with names containing "Advanced IP Defense" or "AIPD". These EDLs are available in two sizes (16K and 100K) to accommodate different hardware platform capacity limits.
  5. Create security policy rules that reference the Advanced IP Defense EDLs.
    Select PoliciesSecurity and create or edit a security policy rule. In the rule configuration:
    • Set the source and destination addresses as needed
    • In the destination address field, add the Advanced IP Defense EDL you want to use
    • Specify the action (Allow, Deny, or Alert)
    • Configure logging to track EDL hits
  6. Configure the rule action.
    For inbound traffic, you can block traffic from anonymizers and proxies. For outbound traffic, you can block traffic to malware C2 servers and vulnerable services. Choose the appropriate action based on your security requirements.
  7. Enable logging for the rule.
    In the rule configuration, enable logging so that you can track when traffic matches the Advanced IP Defense EDL. This provides visibility into blocked threats.
  8. Commit your changes.
    Click Commit to apply the security policy rules to your firewall.
  9. Monitor EDL hits and traffic logs.
    Select MonitorLogsTraffic to view logs for traffic that matched the Advanced IP Defense EDL rules. The EDL name will be displayed in the source EDL or destination EDL columns of the logs.
After enabling Advanced IP Defense EDLs, monitor the logs regularly to track blocked threats and validate policy effectiveness. As your organization prepares to upgrade to PAN-OS 12.2 or later, you can migrate to the full Advanced IP Defense profile-based implementation for enhanced capabilities including direct-to-IP detection and granular attribute-based controls.