Advanced IP Defense Predefined EDLs
Focus
Focus
Advanced IP Defense

Advanced IP Defense Predefined EDLs

Table of Contents

Advanced IP Defense Predefined EDLs

Reference for the predefined external dynamic lists (EDLs) that deliver Advanced IP Defense intelligence to enforcement points using Advanced IP Defense.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by Strata Cloud Manager)
  • NGFW (Managed by PAN-OS or Panorama)
  • VM-Series
  • Cloud NGFW for AWS
  • Cloud NGFW on Azure
  • Prisma Access
  • Advanced IP Defense license
  • Latest AV content update
  • Single vsys only (not supported on multi-vsys firewalls)
The following predefined External Dynamic Lists (EDL) deliver curated subsets of Advanced IP Defense intelligence through the Anti-Virus content package. On PAN-OS 12.2.3 or later releases, you can use the Advanced IP Defense profile-based controls instead.
Predefined Advanced IP Defense EDLs are supported on single-vsys configurations only. Multi-vsys firewall environments cannot deploy these predefined EDLs across multiple virtual systems.
EDL NameDescription
C2 InfrastructureIP addresses used for command-and-control (C2) communications, including those hosting C2 services or resolved from known C2 domains. Recommended for blocking both inbound and outbound traffic.
Hardcoded in MalwareIP addresses embedded in malware samples or exploitation shellcode. Recommended for blocking both inbound and outbound traffic.
Commercial VPNsIP addresses owned by commercial VPN service providers. Recommended for blocking inbound traffic to prevent attacks that use VPNs to obscure origin.
Proxy ServicesIP addresses hosting open or private proxy services (HTTP, SOCKS, OpenVPN) not associated with known commercial VPN providers. Recommended for blocking inbound traffic.
Scanner & Brute ForceIP addresses actively engaged in network scanning or brute-force attacks. Known non-malicious scanners are excluded. Recommended for blocking inbound traffic.
Exposed Vulnerable ServicesIP addresses hosting publicly reachable services vulnerable to known CVEs or exploits (such as exposed RDP, SMB, VNC, or unpatched web servers). Recommended for blocking inbound traffic.
The AV content package delivers the same set of EDL files to all platforms. At install time, the content update automatically trims each list to the appropriate size based on your platform's hardware capacity. You do not need to select a tier manually — the content update determines the correct size for your enforcement point.
If an IP has multiple attributes, it appears in only one EDL based on severity priority (highest to lowest): C2 infrastructure, Hardcoded in malware, VPN, Proxies, Scanner and brute-force, Exposed vulnerable services.
Each EDL ranks IPs by priority in descending order. If platform capacity requires truncation, the list retains the highest-priority entries.

Platform EDL Capacity

The Standard and Extended tier sizes in the following table apply to enforcement points with a valid Advanced IP Defense license. Enforcement points without a license receive only the Free tier, which contains a limited subset of entries regardless of platform capacity.
PlatformSupported Tier
PA-1410/1420, PA-1510-POE, PA-1520/1530-POEExtended
PA-3220/3250/3260, PA-3410–3440, PA-3510–3540, PA-5510–5530Standard
PA-5220–5280, PA-5400 series, PA-5410–5445, PA-5540–5580, PA-7500Extended
VM-Series (all models)Extended
Cloud NGFW for AWSExtended
Cloud NGFW on AzureExtended
Prisma AccessExtended
The following platforms will only receive the Free tier of the Advanced IP Defense predefined EDLs: PA-410–460, PA-415-5G/LTE, PA-500 series.

EDL Priority and Deduplication

  • The Standard tier is a strict subset of the Extended tier. Every IP in the Standard EDL also appears in the Extended EDL.
  • Your enforcement point receives only one tier per EDL category based on its hardware profile. The content update handles tier selection automatically.