Advanced IP Defense Predefined EDLs
Reference for the predefined external dynamic lists (EDLs) that deliver Advanced IP Defense intelligence to enforcement points using Advanced IP Defense.
| Where Can I Use This? | What Do I Need? |
- NGFW (Managed by Strata Cloud Manager)
- NGFW (Managed by PAN-OS or Panorama)
- VM-Series
- Cloud NGFW for AWS
- Cloud NGFW on Azure
- Prisma Access
|
- Advanced IP Defense license
- Latest AV content update
- Single vsys only (not supported on multi-vsys firewalls)
|
The following predefined External Dynamic Lists (EDL) deliver curated subsets of
Advanced IP Defense intelligence through the Anti-Virus content package. On
PAN-OS 12.2.3 or later releases, you can use the
Advanced IP Defense
profile-based controls instead.
Predefined Advanced IP Defense EDLs are supported on single-vsys configurations
only. Multi-vsys firewall environments cannot deploy these predefined EDLs across
multiple virtual systems.
| EDL Name | Description |
| C2 Infrastructure | IP addresses used for command-and-control (C2) communications,
including those hosting C2 services or resolved from known C2 domains.
Recommended for blocking both inbound and outbound traffic. |
| Hardcoded in Malware | IP addresses embedded in malware samples or exploitation shellcode.
Recommended for blocking both inbound and outbound traffic. |
| Commercial VPNs | IP addresses owned by commercial VPN service providers. Recommended
for blocking inbound traffic to prevent attacks that use VPNs to obscure
origin. |
| Proxy Services | IP addresses hosting open or private proxy services (HTTP, SOCKS,
OpenVPN) not associated with known commercial VPN providers. Recommended
for blocking inbound traffic. |
| Scanner & Brute Force | IP addresses actively engaged in network scanning or brute-force
attacks. Known non-malicious scanners are excluded. Recommended for
blocking inbound traffic. |
| Exposed Vulnerable Services | IP addresses hosting publicly reachable services vulnerable to known
CVEs or exploits (such as exposed RDP, SMB, VNC, or unpatched web
servers). Recommended for blocking inbound traffic. |
The AV content package delivers the same set of EDL files to all platforms. At install
time, the content update automatically trims each list to the appropriate size based on your
platform's hardware capacity. You do not need to select a tier manually — the content
update determines the correct size for your enforcement point.
If an IP has multiple attributes, it appears in only one EDL based on severity priority
(highest to lowest): C2 infrastructure, Hardcoded in malware, VPN, Proxies, Scanner and
brute-force, Exposed vulnerable services.
Each EDL ranks IPs by priority in descending order. If platform capacity requires
truncation, the list retains the highest-priority entries.
EDL Priority and Deduplication
- The Standard tier is a strict subset of the Extended tier. Every IP in the Standard
EDL also appears in the Extended EDL.
- Your enforcement point receives only one tier per EDL category based on its
hardware profile. The content update handles tier selection automatically.