Advanced IP Defense EDL-Based Protection
Focus
Focus
Advanced IP Defense

Advanced IP Defense EDL-Based Protection

Table of Contents

Advanced IP Defense EDL-Based Protection

Learn how enforcement points receive Advanced IP Defense intelligence through predefined external dynamic lists (EDLs) delivered via the AV content package.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by Strata Cloud Manager)
  • NGFW (Managed by PAN-OS or Panorama)
  • VM-Series
  • Advanced IP Defense license
  • PAN-OS 11.1 and later
Enforcement points running PAN-OS 11.1 through 12.2.2 cannot use Advanced IP Defense profile-based controls. You can protect these enforcement points against high-risk IP-based threats using predefined External Dynamic Lists (EDLs) that deliver curated subsets of Advanced IP Defense intelligence. On PAN-OS 12.2.3 or later release, predefined EDLs are available as an alternative to the profile-based controls. Enforcement points running PAN-OS 11.0 or earlier do not support Advanced IP Defense EDLs.
Predefined Advanced IP Defense EDLs are supported on single-vsys configurations only. Multi-vsys NGFW environments cannot deploy these predefined EDLs across multiple virtual systems.
Ensure all firewalls are updated to the content version that includes the Advanced IP Defense EDLs before committing your configuration. Enforcement points running an older content version may encounter commit errors.

How It Works

The Advanced IP Defense cloud service generates ranked lists of malicious IP addresses organized by threat category. The AV content package compiles these lists into predefined EDLs and delivers them automatically through the same update channel your enforcement points already use for threat signatures. After you install the content update, the EDL objects appear alongside your existing predefined EDLs and you can reference them in Security policy rules.

What Is Supported

  • Predefined EDLs covering: C2 infrastructure, malware (hardcoded in samples), commercial VPNs, proxies (open and private), scanners and brute-force, and exposed vulnerable services
  • Automatic EDL sizing (Standard and Extended tiers) based on hardware platform capacity — determined at install time with no manual selection required
  • Logging via standard threat logs with the EDL name in the source/destination EDL columns
  • Standard EDL workflows for HA, reporting, REST API, and Open Config

What EDL-Based Protection Does Not Support

  • Direct-to-IP detection
  • Real-time cloud lookups for IP attributes
  • Granular profile-based controls (zone-based profiles, match rules, actions per category)
  • Enhanced logging with the ip-defense threat log subtype
  • Advanced IP Defense dashboard and reporting in Strata Cloud Manager

Predefined EDL Reference

The following predefined EDLs deliver curated subsets of Advanced IP Defense intelligence through the Anti-Virus content package.
EDL NameEDL Object NameDescription
C2 Infrastructurepanw-aipd-c2-infra-ip-listIP addresses used for Command and Control (C2) communications, including those hosting C2 services or resolved from known C2 domains. Blocking this list is recommended for both inbound and outbound traffic to prevent malicious activity.
Hardcoded in Malwarepanw-aipd-in-malware-ip-listIP addresses embedded in malware samples or exploitation shellcode. Blocking this list is recommended for both inbound and outbound traffic to prevent communication with hardcoded malicious endpoints.
Commercial VPNspanw-aipd-vpn-ip-listIP addresses owned by commercial Virtual Private Network (VPN) service providers. As traffic from VPNs can obscure malicious origins, blocking this list is recommended for inbound traffic to prevent attack attempts. Ideal for organizations whose security policies prohibit inbound connections from commercial VPN services.
Proxy Servicespanw-aipd-proxies-ip-listIP addresses hosting suspicious open (no auth needed) or private (auth needed) proxy services (such as HTTP, SOCKS, OpenVPN) that are not associated with known, legitimate commercial VPN providers. These services mask attacker identity and are a common source of malicious activity, making blocking them recommended for inbound traffic.
Scanner & Brute Forcepanw-aipd-scanning-ip-listIP addresses actively engaged in malicious network scanning or automated brute-force attacks. Blocking this list is recommended for inbound traffic to prevent reconnaissance and initial access attempts from reaching your systems. Known, non-malicious scanners (such as shodan.io and Censys) are excluded.
Exposed Vulnerable Servicespanw-aipd-vuln-svcs-ip-listIP addresses hosting publicly reachable services vulnerable to known CVEs or exploits (such as exposed RDP, SMB, VNC, or unpatched web servers). Attackers use these compromised systems as launching points for further attacks, so blocking these is recommended for inbound traffic to protect against exploitation attempts originating from these hosts.
The AV content package delivers the same set of EDL files to all platforms. At install time, the content update automatically trims each list to the appropriate size based on your platform's hardware capacity. You do not need to select a tier manually — the content update determines the correct size for your enforcement point.
If an IP has multiple attributes, it appears in only one EDL based on severity priority (highest to lowest): C2 infrastructure, Hardcoded in malware, VPN, Proxies, Scanner and brute-force, Exposed vulnerable services.
Each EDL ranks IPs by priority in descending order. If platform capacity requires truncation, the list retains the highest-priority entries.

Platform EDL Capacity

The Standard and Extended tier sizes in the following table apply to enforcement points with a valid Advanced IP Defense license. Enforcement points without a license receive only the Free tier, which contains a limited subset of entries regardless of platform capacity.
PlatformSupported Tier
PA-1410/1420, PA-1510-POE, PA-1520/1530-POEExtended
PA-3220/3250/3260, PA-3410–3440, PA-3510–3540, PA-5510–5530Standard
PA-5220–5280, PA-5400 series, PA-5410–5445, PA-5540–5580, PA-7500Extended
VM-Series (all models)Extended
The following platforms will only receive the Free tier of the Advanced IP Defense predefined EDLs: PA-410–460, PA-415-5G/LTE, PA-500 series.

EDL Priority and Deduplication

  • The Standard tier is a strict subset of the Extended tier. Every IP in the Standard EDL also appears in the Extended EDL.
  • Your enforcement point receives only one tier per EDL category based on its hardware profile. The content update handles tier selection automatically.

Licensing

An Advanced IP Defense license is required to receive the full predefined EDLs through the AV content package. Without a valid license, the EDL files contain only stub records and provide no protection. If your license expires, your enforcement point retains the last-known-good EDL content until you renew.

PAN-OS Upgrade and Downgrade Behavior

When you upgrade an enforcement point to PAN-OS 12.2.3 or later release and activate the Advanced IP Defense license, profile-based configuration becomes available in addition to EDL-based protection. When you downgrade the enforcement point below PAN-OS 12.2.3, the system automatically removes the profile-based configuration. The license remains active, and EDL-based protection continues to function. The profile-based configuration becomes available again when you upgrade back to PAN-OS 12.2.3 or later release.
Adding new IP attribute categories or tags to Advanced IP Defense does not require a PAN-OS upgrade. Content updates deliver new attributes, and they become available on the enforcement point after you install the update.