This guide is for administrators setting up the integration on PAN-OS. It covers the prerequisites, how to create the External Dynamic Lists and how to reference them in a Security policy so malicious traffic is blocked.
Before you start, create your API key and feed URLs in the portal. See Get your threat feeds. Use a refresh interval of 20 minutes or longer.
Available indicator lists
- Malware IP (
feed_type=malware_ip) - Malware domains (
feed_type=malware_domains) - Malicious URLs (
feed_type=malicious_urls)
Example URL (replace placeholders with your values):
https://api.qfeeds.com/api?feed_type=malware_ip&limit=50000
Test with:
curl -v -u api_token:YOUR_TOKEN "https://api.qfeeds.com/api?feed_type=malware_ip&limit=50000"
Service route for External Dynamic Lists
- Open Device > Setup > Services > Service Route Configuration > Customize.
- Edit the service External Dynamic Lists so the firewall can reach
api.qfeeds.com.
Add an External Dynamic List
- Go to Objects > External Dynamic Lists and select Add.
- Enter a clear Name for the list.
- Set Type to IP, Domain or URL to match the feed. For domain lists you can enable Automatically expand to include subdomains.
- In Source, paste the feed URL and replace placeholders with your API key and an appropriate
limitfor your model (see capacity table below). - Download the Q-Feeds CA certificates from https://api.qfeeds.com/download_cert_PA.php. The file is a ZIP of individual PEM files. Import one certificate per file.
- Under Device > Certificate Management > Certificates, import each CA PEM with Certificate Type set to Local and File Format PEM. Do not import a private key. Then create a Certificate Profile, add those certificates under CA Certificates, and assign the profile to the EDL.
- Enable Client Authentication. Username is
api_token; password is your Q-Feeds API key. - Set Check for updates to 20 minutes (or your license interval).
- Commit. The list appears under Objects > External Dynamic Lists and can be used in security policies.
- Repeat for each feed type you need (IPs, domains, URLs).
Model capacity limits
Choose a limit that fits your platform. Palo Alto enforces platform-wide totals; when the IP limit is reached the firewall generates a syslog message. Predefined IP lists do not count toward the limit.
- IP addresses: PA-3200 / PA-5200 / PA-7000 series up to 150,000 total; other models up to 50,000 total.
- URL / domain list entry limits (examples):
- PA-5200 / PA-7000 (with high-capacity NPC): up to 250,000 URL / 4,000,000 domain
- VM-500 / VM-700: 100,000 URL / 2,000,000 domain
- PA-850 / PA-820 / PA-3200: 100,000 URL / 1,000,000 domain
- PA-220 / VM-50 / VM-100: 50,000 URL / 50,000 domain
Consult current Palo Alto documentation for your exact model and PAN-OS version.
Use in policies
Where you reference the EDL depends on its type. An IP list is an address object, so it goes in the source or destination of a Security policy rule. A URL list behaves as a custom URL category instead, so you add it on the Categories tab of a URL Filtering profile, or use it as a URL match criterion in a Security, Decryption or QoS rule. It is not an address object and will not appear in the source and destination lists.
The malicious URL feed needs a Q-Feeds Premium licence, and the firewall has to see the HTTP request to match a path, so enforcing the full path takes a Decryption policy. Without decryption only the hostname is matched. Keep one feed per EDL as well: a URL list silently skips entries that are not URLs, so a mixed list looks like it loaded while most of it was dropped.