Configure Advanced IP Defense EDL Exceptions (PAN-OS and Panorama)
Focus
Focus
Advanced IP Defense

Configure Advanced IP Defense EDL Exceptions (PAN-OS and Panorama)

Table of Contents


Configure Advanced IP Defense EDL Exceptions (PAN-OS and Panorama)

Reference External Dynamic Lists (EDLs) in your Advanced IP Defense profile to exclude known-good IP addresses from Advanced IP Defense evaluation.
EDL exceptions allow you to exclude traffic destined to or originating from known-good IP addresses from Advanced IP Defense evaluation. When a connection's IP matches an entry in a referenced EDL, the firewall skips Advanced IP Defense checks for that connection. Use EDL exceptions for dynamic infrastructure where IP addresses change frequently, such as your own cloud services or CDN providers.
  1. Log in to the PAN-OS web interface.
  2. Select ObjectsSecurity ProfilesAdvanced IP Defense and select the profile where you want to add exceptions.
  3. Click the Exceptions tab.
    Exceptions tab
  4. Click Add to add an EDL exception.
    Selecting an External Dynamic List
    In the External Dynamic List dialog, select an existing IP-based EDL from the External Dynamic List dropdown. The EDL must already be configured under ObjectsExternal Dynamic Lists. The exception applies to all traffic matching the EDL. See External Dynamic Lists for EDL configuration details.
  5. Click OK to save the exception, then click OK to save the profile.
    Exceptions tab with an EDL exception configured
  6. Commit your changes.
After committing, verify that the exception is working correctly by monitoring MonitorLogsThreat to confirm that traffic matching the EDL is no longer triggering Advanced IP Defense rules.