Create an Advanced IP Defense Profile (PAN-OS 11.1 and Later)
Focus
Focus
Advanced IP Defense

Create an Advanced IP Defense Profile (PAN-OS 11.1 and Later)

Table of Contents


Create an Advanced IP Defense Profile (PAN-OS 11.1 and Later)

Configure Advanced IP Defense on PAN-OS 11.1 and later using predefined External Dynamic Lists (EDLs) to block malicious IP addresses.
For PAN-OS 11.1 and later, Advanced IP Defense is available through predefined External Dynamic Lists (EDLs) that are automatically delivered via content updates. These EDLs contain curated, priority-ranked lists of malicious IP addresses identified by Advanced IP Defense, allowing you to block threats using your existing security policy rules. On PAN-OS 12.2.3 and later, you can also use the full Advanced IP Defense profile-based architecture for granular attribute-level matching and direct-to-IP detection.
The Advanced IP Defense EDLs are delivered in the antivirus content package and installed automatically when you update dynamic content. The system performs Top-K trimming at install time based on your hardware platform's EDL capacity, so the same content package works across all supported devices. Each list is ranked by priority in descending order (first entry = highest priority).
Predefined Advanced IP Defense EDLs are supported on single-vsys configurations only. Multi-vsys enforcement point environments cannot deploy these EDLs across multiple virtual systems.
  1. Log in to the PAN-OS web interface.
  2. Select DeviceDynamic Updates and check for the latest antivirus content release. The Advanced IP Defense EDLs are delivered through this package. Schedule automatic updates to Schedule automatic updates to keep your enforcement point content current with the latest antivus content package.
  3. Select ObjectsExternal Dynamic Lists look for the predefined Advanced IP Defense EDLs are available.
    The AV content package delivers the same set of EDL files to all platforms. At install time, the system automatically trims each list to the appropriate size based on your hardware platform's capacity. You do not need to select a tier manually. Standard tier platforms (such as PA-3200, PA-3400, PA-3500, and PA-5500 series) receive a condensed record set, while Extended tier platforms (such as PA-1400, PA-5200, PA-5400, PA-7500 series, VM-Series, and Prisma Access) receive the complete record set.
    An IP address appears in only one EDL even if it has multiple attributes. When an IP qualifies for multiple lists, it is placed in the highest-severity list based on the following priority (highest to lowest): C2 infrastructure, Hardcoded in malware, VPN, Proxies, Scanner and brute-force, Exposed vulnerable services.
  4. Select PoliciesSecurity and create a Security Policy rule for each Advanced IP Defense EDL you want to enforce.
    For each rule:
    • In the Source or Destination tab, click Add and select the Advanced IP Defense EDL. Use the Source Address field to match inbound traffic from malicious IPs, or the Destination Address field to match outbound traffic to malicious IPs.
    • In the Actions tab, set the action to Deny (block and drop) or Allow with logging enabled (alert-only mode for initial monitoring).
    • In the Actions tab, enable Log at Session End and attach a log forwarding profile to forward matches to your SIEM or Strata Logging Service.
    Position the Advanced IP Defense EDL rules before your general allow rules in the policy rulebase to ensure they are evaluated first. See Security Policy for more information about rule ordering and evaluation.
  5. Commit your changes.
  6. Select MonitorLogsTraffic to view logs for traffic that matched the Advanced IP Defense EDL rules.
    Filter by the rule name or use the destination/source EDL columns to identify which EDL triggered the match.
The Advanced IP Defense EDLs are updated with each content package release. Schedule automatic content updates to ensure your EDLs reflect the latest threat intelligence. On PAN-OS 12.2.3 and later, you can also enable the full Advanced IP Defense profile-based architecture for granular attribute-level matching, direct-to-IP detection, and real-time cloud lookups. The predefined EDLs remain available alongside profile-based controls.
When you upgrade from an earlier PAN-OS release to 12.2.3 or later, your existing Advanced IP Defense predefined EDLs and the security policy rules that reference them remain intact. You do not need to reconfigure EDL-based policies after the upgrade. You can continue using the EDLs for IP-based blocking while you evaluate and deploy the full profile-based controls.