With an active Threat Prevention license, Palo Alto Networks provides built-in IP
address EDLs that you can use to protect against malicious hosts.
| Where Can I Use
This? | What Do I Need? |
- NGFW (Cloud Managed)
- NGFW (PAN-OS & Panorama Managed)
- Prisma Access (Managed by Strata Cloud Manager)
- Prisma Access (Managed by Panorama)
| Check for any license or role requirements for the products you're using. |
Configuring your configuration to access an external dynamic list is a
critical aspect of optimizing network security and ensuring real-time threat
intelligence updates. An external dynamic list, often referred to as an external
dynamic list, allows your configuration to dynamically update its security rules based on external threat indicators. This integration ensures that your
configuration remains up-to-date with the latest threat intelligence, enhancing its
ability to detect and mitigate emerging cyberthreats effectively.
To begin the configuration process, it's essential to gather the necessary
information about the external dynamic list, such as the list URL, list type (IPv4,
IPv6, domain, etc.), and any authentication credentials required to access the list.
Once you have this information, you’ll:
- Define your external dynamic list profile
Navigate to the
Objects tab and select External
Dynamic Lists. Here, you will create a new external dynamic
list profile by providing a name, description, and the URL of the external
list. Specify the refresh interval, which determines how frequently the your
configuration fetches updates from the specified URL. Configure any
necessary authentication parameters, if applicable.
- Incorporate your external dynamic list profile into your Security policy
rules
This is done by referencing the external dynamic list
within security rules, allowing your configuration to utilize the external
list to match and enforce policies dynamically. Update the rules
accordingly, considering the specific use case and security requirements of
your network.
- Monitor your external dynamic list configuration
Regularly
monitoring and validating the external dynamic list configuration is crucial
to ensure that your configuration continues to receive timely threat
intelligence updates. Additionally, ongoing adjustments and fine-tuning of
security rules based on the acquired threat intelligence will help maintain an
effective and robust security posture against evolving
cyberthreats.
Follow these steps to configure your environment to access an external dynamic list