Skip to main content

Palo Alto

Palo Alto Integration CardPalo Alto Integration Card

The CrowdSec Palo Alto integration connects CrowdSec's hosted blocklist endpoint to your Palo Alto firewall.
Palo Alto calls this feature External Dynamic Lists (EDL), which allow you to import and automatically update blocklists from external sources.

info

Ensure your Palo Alto device supports External Dynamic Lists (EDL).
The vendor documentation is available in the References section below.

Create a Palo Alto Integration Endpoint​

Step 1 - Create an integration in the CrowdSec Console​

In your CrowdSec Console account, navigate to the Blocklist tab in the top menu bar, then select the Integrations sub-menu. Choose the integration type you need, then click Connect.

info

If you don't have a CrowdSec Console account, sign up here. On mobile, use the menu icon in the top-right corner, tap Blocklist, then Integrations.

CrowdSec Integrations ScreenCrowdSec Integrations Screen

Configure Palo Alto​

Create an External Dynamic List​

Go to Objects > External Dynamic Lists > Add.

info

Embed the credentials in the URL using Basic Auth:

TEXT
https://<username>:<password>@admin.api.crowdsec.net/v1/integrations/<integration_id>/content

Set your desired update frequency.

Create a security policy​

Go to Policies > Security > Add.

In the General tab, add the policy name and description.

In the Source tab, select your source zone and the External Dynamic List as the source address.

In the Actions tab, select Drop and enable logging (recommended).

Click Commit to apply the configuration.

Manage integration size limits with pagination​

If you want to learn how to manage integration size limits with pagination, please refer to the Managing integrations size limits with pagination section.

This integration uses the plain text format. When pulling without compression, keep page_size at or below ~300,000 entries to stay under the ~5 MB response limit; beyond that the response is truncated. Enabling compression avoids this limit entirely.

Troubleshooting​

Palo Alto not pulling EDL, check this troubleshooting: Checking Credentials and Certificate

References​

Next Steps​

Subscribe to blocklists in the Blocklist Catalog to populate your integration.

CrowdSec Docs
We use cookies

This site uses cookies to help us improve your experience. You can accept or decline below.