How to block outgoing traffic to known malicious hostnames

A knowledge base article about How to block outgoing traffic to known malicious hostnames provided by the UC Berkeley IT Service Hub - Knowledge Portal

These instructions deal with how to create a custom “Anti-Spyware” profile to block malicious hostnames (i.e. Fully Qualified Domain Names) using the campus list of malicious hostnames derived from trusted sources. For most firewall administrators these steps will not be necessary as the existing feeds of malicious FQDNs are already in all of the Anti-Spyware profiles created by ISP and these are the recommended profiles for administrators to use. Those recommended profiles all start with “ucbsec-” and their location in the Panorama hierarchy is “Global.” If an administrator needs to customize one the best option is to clone an existing rule in which case the malicious hostname blocking will also be cloned. The following instructions should only be necessary when a completely new “Anti-Spyware” profile is being created or an administrator is creating a profile from one of the Palo Alto “Predefined” profiles since they would lack our local customization.

  1.  Log into https://panorama.net.berkeley.edu using single sign-on
  2. From the tabs at the top of the window choose “Objects”
  3. Under “Security Profiles” in the left pane choose “Anti-Spyware”
  4. Click “Add” from the bottom of the window. This should bring up a “Anti-Spyware Profile” window.
  5. Enter an appropriate name and, optionally, description in the Name and Description fields of the new profile.
  6. Create the custom rules and exceptions as required for this profile (see the online Palo Alto documentation and training for information on accomplishing this)
  7. Under the “DNS Signatures” tab click “Add” under “External Dynamic List Domains”
  8. From the “External Dynamic List” choose “threat-malicious_FQDN” 
  9. Click “OK”
  10. From the “Commit” menu near the top of the screen chose “Commit to Panorama“ and then when the commit option is finished, from the same menu select “Push to Device”


 

At this point the new Anti-Spyware profile is available to add to any firewall rules.  If the custom profile is only to be used for individual hosts then it’s fine to add it and any other profiles to the rule from its “Actions” tab and, using the Profile Type “Profiles”, to set all of the individual profiles (AntiVirus, Vulnerability Protection, etc.) individually. However, if this selection of profiles is to be used across multiple devices, then it is recommended to create a Profile Group that can be applied to a rule so that all of the individual Profiles are set consistently with only one Profile Group selection. If this profile should be used for all rules created on the vsys, it can be used in the default profile group.