Configure a Private External Dynamic List
Focus
Focus
Cloud NGFW for Azure

Configure a Private External Dynamic List

Table of Contents

Configure a Private External Dynamic List

Configure an external dynamic list (EDL) hosted on a server inside an Azure VNet for use in Cloud NGFW for Azure security policies.
Where Can I Use This?What Do I Need?
  • Cloud NGFW for Azure
  • Cloud NGFW subscription
  • Palo Alto Networks Customer Support Portal account
  • Azure Marketplace subscription
  • Strata Cloud Manager access
  • EDL server running on a virtual machine inside an Azure VNet within the same Azure tenant as Cloud NGFW for Azure
A private EDL is hosted on a server inside an Azure VNet rather than on a public web server. Cloud NGFW for Azure reaches the private server through a loopback.3 service route that routes traffic through peered VNets. This keeps the EDL server off the public internet while still allowing the firewall to fetch and enforce the list.
The CNGFW-Azure-Loopback-3-Default snippet provisions the loopback.3 interface required for the private EDL service route. If you already have a loopback.3 interface manually defined and referenced in a committed configuration, importing this snippet fails. If you plan to reuse an existing loopback.3 interface, ensure its IP address is set to 172.200.255.253.
  1. Verify that your EDL server is running on a virtual machine inside an Azure VNet within the same Azure tenant as your Cloud NGFW for Azure resource.
  2. If the EDL server VNet and the Cloud NGFW VNet are different, configure VNET Peering between them to open the data plane pathways.
  3. Import the CNGFW-Azure-Loopback-3-Default snippet in Strata Cloud Manager to provision the loopback.3 interface:
    1. Log in to Strata Cloud Manager.
    2. Select ConfigurationNGFW and Prisma Access and choose your target folder.
    3. Navigate to Snippets and import the CNGFW-Azure-Loopback-3-Default snippet.
    After importing the snippet, it may take a short amount of time for the loopback.3 configuration to appear in the interface.
  4. Configure the service route for EDL traffic:
    1. Select DeviceDevice SetupService Route Settings and click Customize.
    2. Locate the EDL application listing and click it.
    3. For Source Interface, choose loopback.3.
    4. For Source Address, choose the IP address assigned to loopback.3 (172.200.255.253).
    5. Click OK.
  5. Create the private EDL object:
    1. Select ObjectsExternal Dynamic List and click Add External Dynamic List.
    2. For Name, enter a descriptive name for the EDL.
    3. For Type, choose IP List, URL List, or Domain List.
    4. For Source, enter the private IP address URL of your EDL server (for example, http://10.1.0.4/edl.txt).
    5. For Check Frequency, set the polling interval.
    6. Click Save.
  6. Select Security Policies and click Add to create a security rule that references the private EDL object.
    • For Source Address or Destination Address, add the private EDL object you created.
    • For Action, choose Allow, Deny, or Drop.
  7. Click Save.
  8. Click Push Config to deliver the configuration to your Cloud NGFW for Azure firewalls.
  9. Verify that Cloud NGFW for Azure successfully fetched the EDL:
    1. Select ObjectsExternal Dynamic List.
    2. Click the name of your EDL object.
    3. Confirm that Strata Cloud Manager displays the list of IP addresses fetched from your private EDL server.