Configure an external dynamic list (EDL) hosted on a server inside an Azure VNet
for use in Cloud NGFW for Azure security policies.
| Where Can I Use This? | What Do I Need? |
A private EDL is hosted on a server inside an Azure VNet rather than on a public
web server. Cloud NGFW for Azure reaches the private server through a
loopback.3 service route that routes traffic through peered
VNets. This keeps the EDL server off the public internet while still allowing the
firewall to fetch and enforce the list.
The
CNGFW-Azure-Loopback-3-Default snippet provisions the
loopback.3 interface required for the private EDL service
route. If you already have a loopback.3 interface manually defined
and referenced in a committed configuration, importing this snippet fails. If you
plan to reuse an existing loopback.3 interface, ensure its IP
address is set to 172.200.255.253.