How to block outgoing traffic to known malicious hostnames

A knowledge base article about How to block outgoing traffic to known malicious hostnames provided by the UC Berkeley IT Service Hub - Knowledge Portal

Table of Contents

Overview

These instructions describe how to create a custom Anti-Spyware profile to block malicious hostnames (Fully Qualified Domain Names or FQDNs) using the campus list derived from trusted sources.

Best Practice: For most administrators, these steps are unnecessary. ISO already includes malicious FQDN feeds in all shared Anti-Spyware profiles (which start with ucbsec-). If you need to customize a profile, the best option is to clone an existing ISO rule to ensure the malicious hostname blocking is preserved.

The following instructions should only be used when creating a completely new profile or when using a Palo Alto “Predefined” profile that lacks local campus customizations.


Steps to Create a Custom Anti-Spyware Profile

  1. Log into https://panorama.net.berkeley.edu using single sign-on.
  2. Select the Objects tab from the top navigation bar.
  3. Under the Security Profiles menu in the left pane, choose Anti-Spyware.
    Panorama Objects tab with Anti-Spyware selected in the sidebar.
  4. Click Add at the bottom of the window to open the Anti-Spyware Profile window.
    Anti-Spyware profile dialog box.
  5. Enter a descriptive Name and optional Description for the new profile.
  6. Create any custom rules and exceptions as required for your environment (refer to vendor documentation for specific rule logic).
  7. Select the DNS Signatures tab and click Add under the "External Dynamic List Domains" section.
  8. From the External Dynamic List drop-down, choose threat-malicious_FQDN.
    Selecting threat-malicious_FQDN from the External Dynamic List menu.
  9. Click OK.
  10. From the Commit menu at the top of the screen, choose Commit to Panorama. When finished, select Push to Device from the same menu.
    Commit and Push to Device menu options.

Applying the New Profile

The new Anti-Spyware profile is now available to be added to your firewall rules: