Skip to main content

Overview

This guide explains how to ingest OneFirewall Alliance IP feeds into a Palo Alto firewall using External Dynamic Lists (EDL), using a proxy method to support Bearer Token authentication.

Prerequisites

Use PAN-OS 10.0+, which supports HTTPS-based EDLs and certificate profiles.

Step 1: Generate API Token

  1. Log into your OneFirewall Alliance profile.
  2. Navigate to the API Access section.
  3. Generate a JWT token.
  4. Save this token securely — it will be used for authenticating feed requests.

Step 2: Create the External Dynamic List (EDL)

  1. In the Palo Alto Web UI, go to Objects → External Dynamic Lists.
  2. Click Add.
  3. Fill in the fields:
    • Name: onefirewall_ipv4_feed
    • Type: IP List
    • Source: If Client Authentication is available, use basic auth in that section and set the source to:
      Use the credentials as shown in the figure. If Client Authentication is not available, pass credentials directly in the URL:
    • Recurring: Every 15 minutes (or as needed)
    • Certificate Profile: (optional, only needed for HTTPS with custom certs)
  4. Click OK and then Commit your changes.
See the Official Palo Alto EDL Configuration Guide for further details.

Step 3: Apply the EDL in a Security Policy

  1. Go to Policies → Security.
  2. Create a new rule or edit an existing one:
    • Source / Destination Zone: According to your environment
    • Destination Address: Add an address object referencing the EDL (onefirewall_ipv4_feed)
    • Action: Deny or Drop
  3. Name and place the rule in the correct policy order.
  4. Commit the configuration.

Step 4: Verify EDL Status

Verify whether the EDL was successfully downloaded using the CLI: