Skip to main content

Palo Alto

Palo Alto Integration CardPalo Alto Integration Card

The CrowdSec Palo Alto integration connects CrowdSec's hosted blocklist endpoint to your Palo Alto firewall.
Palo Alto calls this feature External Dynamic Lists (EDL), which allow you to import and automatically update blocklists from external sources.

Ensure your Palo Alto device supports External Dynamic Lists (EDL).
The vendor documentation is available in the References section below.

Create a Palo Alto Integration Endpoint

Step 1 — Create an integration in the CrowdSec Console

In your CrowdSec Console account, navigate to the Blocklist tab in the top menu bar, then select the Integrations sub-menu. Choose the integration type you need, then click Connect.

If you don't have a CrowdSec Console account, sign up here. On mobile, use the menu icon in the top-right corner, tap Blocklist, then Integrations.

CrowdSec Integrations ScreenCrowdSec Integrations Screen

Configure Palo Alto

Create an External Dynamic List

Go to Objects > External Dynamic Lists > Add.

Embed the credentials in the URL using Basic Auth:

https://<username>:<password>@admin.api.crowdsec.net/v1/integrations/<integration_id>/content

Set your desired update frequency.

Create a security policy

Go to Policies > Security > Add.

In the General tab, add the policy name and description.

In the Source tab, select your source zone and the External Dynamic List as the source address.

In the Actions tab, select Drop and enable logging (recommended).

Click Commit to apply the configuration.

Manage integration size limits with pagination

If you want to learn how to manage integration size limits with pagination, please refer to the Managing integrations size limits with pagination section.

References

Next Steps

Subscribe to blocklists in the Blocklist Catalog to populate your integration.