Firewall integrations

Set up a Palo Alto EDL

This setup guide covers Palo Alto EDL configuration step by step, not the product overview. Add Q-Feeds to your Palo Alto Networks firewall as External Dynamic Lists (EDLs) so it blocks known malicious IPs, domains and URLs with regularly refreshed threat intelligence.

This guide is for administrators setting up the integration on PAN-OS. It covers the prerequisites, how to create the External Dynamic Lists and how to reference them in a Security policy so malicious traffic is blocked.

Before you start, create your API key and feed URLs in the portal. See Get your threat feeds. Use a refresh interval of 20 minutes or longer.

Available indicator lists

  • Malware IP (feed_type=malware_ip)
  • Malware domains (feed_type=malware_domains)
  • Malicious URLs (feed_type=malicious_urls)

Example URL (replace placeholders with your values):

https://api.qfeeds.com/api?feed_type=malware_ip&limit=50000

Test with:

curl -v -u api_token:YOUR_TOKEN "https://api.qfeeds.com/api?feed_type=malware_ip&limit=50000"

Service route for External Dynamic Lists

  1. Open Device > Setup > Services > Service Route Configuration > Customize.
  2. Edit the service External Dynamic Lists so the firewall can reach api.qfeeds.com.

Add an External Dynamic List

  1. Go to Objects > External Dynamic Lists and select Add.
  2. Enter a clear Name for the list.
  3. Set Type to IP, Domain or URL to match the feed. For domain lists you can enable Automatically expand to include subdomains.
  4. In Source, paste the feed URL and replace placeholders with your API key and an appropriate limit for your model (see capacity table below).
  5. Download the Q-Feeds CA certificates from https://api.qfeeds.com/download_cert_PA.php. The file is a ZIP of individual PEM files. Import one certificate per file.
  6. Under Device > Certificate Management > Certificates, import each CA PEM with Certificate Type set to Local and File Format PEM. Do not import a private key. Then create a Certificate Profile, add those certificates under CA Certificates, and assign the profile to the EDL.
  7. Enable Client Authentication. Username is api_token; password is your Q-Feeds API key.
  8. Set Check for updates to 20 minutes (or your license interval).
  9. Commit. The list appears under Objects > External Dynamic Lists and can be used in security policies.
  10. Repeat for each feed type you need (IPs, domains, URLs).

Model capacity limits

Choose a limit that fits your platform. Palo Alto enforces platform-wide totals; when the IP limit is reached the firewall generates a syslog message. Predefined IP lists do not count toward the limit.

  • IP addresses: PA-3200 / PA-5200 / PA-7000 series up to 150,000 total; other models up to 50,000 total.
  • URL / domain list entry limits (examples):
    • PA-5200 / PA-7000 (with high-capacity NPC): up to 250,000 URL / 4,000,000 domain
    • VM-500 / VM-700: 100,000 URL / 2,000,000 domain
    • PA-850 / PA-820 / PA-3200: 100,000 URL / 1,000,000 domain
    • PA-220 / VM-50 / VM-100: 50,000 URL / 50,000 domain

Consult current Palo Alto documentation for your exact model and PAN-OS version.

Use in policies

Where you reference the EDL depends on its type. An IP list is an address object, so it goes in the source or destination of a Security policy rule. A URL list behaves as a custom URL category instead, so you add it on the Categories tab of a URL Filtering profile, or use it as a URL match criterion in a Security, Decryption or QoS rule. It is not an address object and will not appear in the source and destination lists.

The malicious URL feed needs a Q-Feeds Premium licence, and the firewall has to see the HTTP request to match a path, so enforcing the full path takes a Decryption policy. Without decryption only the hostname is matched. Keep one feed per EDL as well: a URL list silently skips entries that are not URLs, so a mixed list looks like it loaded while most of it was dropped.

Download the PDF manual

Evaluate our intelligence today!

Simplify your security operations, start your free Q-Feeds trial and experience the difference.

Activate free access