External Dynamic Lists on Cloud NGFW for Azure
Focus
Focus
Cloud NGFW for Azure

External Dynamic Lists on Cloud NGFW for Azure

Table of Contents

External Dynamic Lists on Cloud NGFW for Azure

Learn how external dynamic lists (EDLs) work with Cloud NGFW for Azure and the supported deployment topologies.
Where Can I Use This?What Do I Need?
  • Cloud NGFW for Azure
  • Cloud NGFW subscription
  • Palo Alto Networks Customer Support Portal account
  • Azure Marketplace subscription
  • Strata Cloud Manager access
An external dynamic list (EDL) is a text file hosted on a web server that Cloud NGFW for Azure imports to enforce security policies. The firewall periodically polls the list to retrieve updates, so changes take effect without requiring a policy commit. You reference EDLs in security rules to control traffic based on IP addresses, URLs, or domain names.
Using EDLs with Cloud NGFW for Azure provides the following advantages:
  • Dynamic security policy enforcement: Security policies automatically adjust as the source list changes, eliminating manual updates and firewall commits.
  • Feature parity with Panorama: If you are migrating from Panorama to Strata Cloud Manager, you retain existing EDL workflows and architecture without disrupting established policy structures.
  • Uninterrupted resiliency: The firewall retains the last successfully fetched list and continues to apply it across reboots, data plane restarts, and upgrades, so enforcement remains active during network disruptions or EDL host downtime.
  • Flexible hybrid infrastructure support: Supports custom-hosted EDLs across both public internet endpoints and private Azure VNet environments.
  • Optimized resource allocation: The firewall only fetches and updates EDL objects that are actively referenced in enforced security policies or profiles, preserving processing capacity.

EDL Deployment Topologies

Cloud NGFW for Azure supports two deployment topologies based on where your EDL server resides.
Public EDL: The EDL server is accessible over the public internet. Cloud NGFW for Azure fetches the list using its management interface. This is the simplest topology and requires no additional network configuration.
Private EDL: The EDL server runs on a virtual machine inside an Azure VNet within the same Azure tenant. Cloud NGFW for Azure fetches the list through a loopback.3 service route that routes traffic through peered VNets to reach the private server. This topology requires the CNGFW-Azure-Loopback-3-Default snippet and, if the EDL server is on a different VNet than the firewall, VNet peering between the two VNets.
When your private EDL server is referenced by a fully qualified domain name (FQDN) rather than a static IP address, you must also configure a DNS service route so Cloud NGFW for Azure resolves the FQDN through a private DNS server reachable via the loopback.3 interface. For more information, see Configuring Snippets.