Domain list EDL is not visible in the Destination IP address field in Security policy rule
26746
Created On 02/07/20 21:20 PM - Last Modified 04/30/26 15:23 PM
Question
Is there is a way we can apply dynamic domain list from EDL to be used in security policy as destination address?
Environment
- All PAN-OS
- Panorama
- Next Generation firewall
Answer
- Destination Address field in security policy is only for the IP address list EDL.
- Domain List EDL cannot be used instead of destination IP.
- In order to enforce a security policy based on Domain list EDL we can create a DNS sinkhole in Anti-Spyware security profile and associate this with a security policy:
Objects > Security Profiles > Anti-Spyware - Under DNS Signatures tab,
Add and select Domain List External Dynamic Lists in the drop-down
Add and select Domain List External Dynamic Lists in the drop-down
Additional Information
For more information regarding EDL Domain please refer to the following link:
https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/policy/use-an-external-dynamic-list-in-policy/external-dynamic-list
For more information on DNS sinkholing refer to the following link:
https://docs.paloaltonetworks.com/advanced-threat-prevention/administration/configure-threat-prevention/use-dns-queries-to-identify-infected-hosts-on-the-network/configure-dns-sinkholing-for-a-list-of-custom-domains