A knowledge base article about How To Block Known Malicious Ip Addresses From Connecting To Your Systems Using Shared Objects provided by the UC Berkeley IT Service Hub - Knowledge Portal
Through its work, Information Policy and Security (ISP) has access to a number of feeds that are made up of IP addresses that are known to be actively attacking hosts on the internet, or are hosting malicious content. The number of these addresses and the frequency at which they change have always made sharing and acting on this information in a timely manner difficult. With the move to the Palo Alto Firewalls, External Dynamic Lists (EDLs) can now be used to make this threat intelligence available to firewall administrators enabling real-time blocking of known bad actors and IP addresses hosting malicious content.
Below are the steps to create a rule that blocks these malicious IP addresses from accessing devices protected by the Palo Alto Firewalls.
- Log into https://panorama.net.berkeley.edu using single sign-on
- From the tabs at the top of the window choose “Policies”
- Under “Security” in the left pane choose “Pre Rules”
- Click “Add” from the bottom of the window. This should bring up a “Security Policy Rule” window.
- In the “General” tab provide an appropriate name such as ‘Block Malicious IP Addresses’ in the Name field

- On the “Source” tab click the “Any” box above “Source Zone” and then click “Add” below the “Source Address” column.
- In the drop down list that will appear for “Source Address” select each of the following “threat-AID_list”, “threat-malicious_IPv4” and “threat-malicious_IPv6”

- On the “Destination” tab select the appropriate Zone and Destinations. We recommend setting the Zone drop down box to ‘any’ and the “Destination Address” also as Any so that these known malicious IP addresses will not be able to connect to any of your systems.

- On the “Actions” tab set the Action option to “Deny” to block any traffic from these IP addresses

- “Click “OK” to return to the list of all of your rules
- Find the new rule ‘Block Malicious IP Addresses’ (in this example) and click on it to highlight that rule.
- At the bottom of the screen select “Move to Top” from the “Move” menu (If they are not at the top other blocking rules may supercede this policy and prevent it from being effective.)
- From the “Commit” menu near the top of the screen chose “Commit to Panorama“ and then when the commit option is finished, from the same menu select “Push to Device”
