A knowledge base article about How to block outgoing traffic to known malicious hostnames provided by the UC Berkeley IT Service Hub - Knowledge Portal
Overview
These instructions describe how to create a custom Anti-Spyware profile to block malicious hostnames (Fully Qualified Domain Names or FQDNs) using the campus list derived from trusted sources.
Best Practice: For most administrators, these steps are unnecessary. ISO already includes malicious FQDN feeds in all shared Anti-Spyware profiles (which start with ucbsec-). If you need to customize a profile, the best option is to clone an existing ISO rule to ensure the malicious hostname blocking is preserved.
The following instructions should only be used when creating a completely new profile or when using a Palo Alto “Predefined” profile that lacks local campus customizations.
Steps to Create a Custom Anti-Spyware Profile
- Log into https://panorama.net.berkeley.edu using single sign-on.
- Select the Objects tab from the top navigation bar.
- Under the Security Profiles menu in the left pane, choose Anti-Spyware.

- Click Add at the bottom of the window to open the Anti-Spyware Profile window.

- Enter a descriptive Name and optional Description for the new profile.
- Create any custom rules and exceptions as required for your environment (refer to vendor documentation for specific rule logic).
- Select the DNS Signatures tab and click Add under the "External Dynamic List Domains" section.
- From the External Dynamic List drop-down, choose
threat-malicious_FQDN.

- Click OK.
- From the Commit menu at the top of the screen, choose Commit to Panorama. When finished, select Push to Device from the same menu.

Applying the New Profile
The new Anti-Spyware profile is now available to be added to your firewall rules:
- Individual Hosts: Add the profile to specific rules via the Actions tab by setting the Profile Type to “Profiles” and selecting your custom Anti-Spyware entry.
- Multiple Devices: Create a Profile Group to ensure consistent application of this and other profiles (AntiVirus, Vulnerability Protection, etc.) across multiple firewall rules.
- Default Use: If the profile should apply to all rules created on a vsys, it can be added to the default profile group.