Advanced IP Defense EDL-Based Protection
Focus
Focus
Advanced IP Defense

Advanced IP Defense EDL-Based Protection

Table of Contents

Advanced IP Defense EDL-Based Protection

Learn how enforcement points receive Advanced IP Defense intelligence through predefined external dynamic lists (EDLs) delivered via the antivirus content package.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by Strata Cloud Manager)
  • NGFW (Managed by PAN-OS or Panorama)
  • VM-Series
  • Advanced IP Defense license
  • PAN-OS 11.1 and later
Enforcement points running PAN-OS 11.1 through 12.2.2 cannot use Advanced IP Defense profile-based controls. You can protect these enforcement points against high-risk IP-based threats using predefined External Dynamic Lists (EDLs) that deliver curated subsets of Advanced IP Defense intelligence. On PAN-OS 12.2.3 or later release, predefined EDLs are available as an alternative to the profile-based controls. Enforcement points running PAN-OS 11.0 or earlier do not support Advanced IP Defense EDLs.
Predefined Advanced IP Defense EDLs support single-vsys configurations only. Multi-vsys NGFW environments cannot deploy these predefined EDLs across multiple virtual systems.
Ensure all NGFW are updated to the content version that includes the Advanced IP Defense EDLs before committing your configuration. Enforcement points running an older content version may encounter commit errors.

How It Works

Advanced IP Defense generates ranked lists of malicious IP addresses organized by threat category. The antivirus content package compiles these lists into predefined EDLs and delivers them automatically through the same update channel your enforcement points already use for threat signatures. Because Advanced IP Defense EDLs are delivered through the antivirus content package, your enforcement point must have an active Threat Prevention subscription to receive content updates. After you install the content update, the EDL objects appear alongside your existing predefined EDLs and you can reference them in Security policy rules.

What Is Supported

  • Predefined EDLs covering: C2 infrastructure, malware (hardcoded in samples), commercial VPNs, proxies (open and private), scanners and brute-force, and exposed vulnerable services
  • Automatic EDL sizing (Standard and Extended tiers) based on hardware platform capacity determined at install time with no manual selection required
  • Logging via standard threat logs with the EDL name in the source/destination EDL columns
  • Standard EDL workflows for HA, reporting, REST API, and Open Config

What EDL-Based Protection Does Not Support

  • Direct-to-IP detection
  • Real-time cloud lookups for IP attributes
  • Granular profile-based controls (zone-based profiles, match rules, actions per category)
  • Enhanced logging with the ip-defense threat log subtype
  • Advanced IP Defense dashboard and reporting in Strata Cloud Manager

Predefined EDL Reference

The following predefined EDLs deliver curated subsets of Advanced IP Defense intelligence through the antivirus content package.
EDL NameEDL Object NameDescription
C2 Infrastructurepanw-aipd-c2-infra-ip-listIP addresses used for Command and Control (C2) communications, including those hosting C2 services or resolved from known C2 domains. Block this list for both inbound and outbound traffic to prevent malicious activity.
Hardcoded in Malwarepanw-aipd-in-malware-ip-listIP addresses embedded in malware samples or exploitation shellcode. Block this list for both inbound and outbound traffic to prevent communication with hardcoded malicious endpoints.
Commercial VPNspanw-aipd-vpn-ip-listIP addresses owned by commercial Virtual Private Network (VPN) service providers. Traffic from VPNs can obscure malicious origins. Block this list for inbound traffic to prevent attack attempts from commercial VPN services.
Proxy Servicespanw-aipd-proxies-ip-listIP addresses hosting suspicious open (no authentication required) or private (authentication required) proxy services (such as HTTP, SOCKS, OpenVPN) not associated with known, legitimate commercial VPN providers. These services mask attacker identity and are a common source of malicious activity. Block this list for inbound traffic.
Scanner & Brute Forcepanw-aipd-scanning-ip-listIP addresses actively engaged in malicious network scanning or automated brute-force attacks. Block this list for inbound traffic to prevent reconnaissance and initial access attempts from reaching your systems. Known, non-malicious scanners (such as shodan.io and Censys) are excluded.
Exposed Vulnerable Servicespanw-aipd-vuln-svcs-ip-listIP addresses hosting publicly reachable services vulnerable to known CVEs or exploits (such as exposed RDP, SMB, VNC, or unpatched web servers). Attackers use these compromised systems as launching points for further attacks. Block this list for inbound traffic to protect against exploitation attempts originating from these hosts.
The antivirus content package delivers the same set of EDL files to all platforms. At install time, the content update automatically trims each list to the appropriate size based on your platform's hardware capacity. You do not need to select a tier manually; the content update determines the correct size for your enforcement point.
If an IP has multiple attributes, it appears in only one EDL based on severity priority (highest to lowest): C2 infrastructure, Hardcoded in malware, VPN, Proxies, Scanner and brute-force, Exposed vulnerable services.
Each EDL ranks IPs by priority in descending order. If platform capacity requires truncation, the list retains the highest-priority entries.

Platform EDL Capacity

The Standard and Extended tier sizes in the following table apply to enforcement points with a valid Advanced IP Defense license. Enforcement points without a license receive only the Free tier, which contains a limited subset of entries regardless of platform capacity.
PlatformSupported Tier
PA-1410/1420, PA-1510-POE, PA-1520/1530-POEExtended
PA-3220/3250/3260, PA-3410–3440, PA-3510–3540, PA-5510–5530Standard
PA-5220–5280, PA-5400 series, PA-5410–5445, PA-5540–5580, PA-7500Extended
VM-Series (all models)Extended
The following platforms will only receive the Free tier of the Advanced IP Defense predefined EDLs: PA-410–460, PA-415-5G/LTE, PA-500 series.

EDL Priority and Deduplication

  • The Standard tier is a strict subset of the Extended tier. Every IP in the Standard EDL also appears in the Extended EDL.
  • Your enforcement point receives only one tier per EDL category based on its hardware profile. The content update handles tier selection automatically.

Licensing

The antivirus content package delivers predefined Advanced IP Defense EDL objects to all enforcement points, regardless of whether you hold an Advanced IP Defense license. The tier of intelligence you receive depends on your license status:
  • Licensed (Standard or Extended tier)—Your enforcement point receives the full EDL content sized to your platform's hardware capacity.
  • Unlicensed (Free tier)—Your enforcement point receives the Free tier, which contains a limited subset of entries.
Because the EDL objects are present on all enforcement points regardless of license status, you can reference them in Security policy rules without error. This is expected behavior. On an unlicensed enforcement point, the EDLs contain only Free tier entries and do not reflect the full Advanced IP Defense intelligence.
If your license expires, your enforcement point retains the last-known-good EDL content until you renew.

PAN-OS Upgrade and Downgrade Behavior

When you upgrade an enforcement point to PAN-OS 12.2.3 or later release and activate the Advanced IP Defense license, profile-based configuration becomes available in addition to EDL-based protection. When you downgrade the enforcement point below PAN-OS 12.2.3, the system automatically removes the profile-based configuration. The license remains active, and EDL-based protection continues to function. The profile-based configuration becomes available again when you upgrade back to PAN-OS 12.2.3 or later release.