EDLs
EDLs are dynamic objects that are periodically updated by fetching information from an external source. This source can be an external subscription-based or free threat-intelligence feed such as Spamhaus, Proofpoint's Emerging Threats, or blocklist.de, to name just a few.
Or, it can be an internally hosted tool such as MineMeld that can consolidate different feeds for ease of use.
When creating an EDL in Objects > External Dynamic Lists, there are five different types to choose from (which you can see in Figure 5.21), as follows:
- Predefined IP List lets you select one of the IP lists provided through dynamic updates (Bulletproof, known malicious IP, and high-risk IP as part of the Threat Prevention license).
- Predefined URL List lets you select one of the URL lists provided through content updates (a list of sites Palo Alto Networks trusts so that they can be excluded from authentication).
- IP List is a group of IP version 4 (IPv4) and/or IP version...