This guide explains how to ingest OneFirewall Alliance IP feeds into a Palo Alto firewall using External Dynamic Lists (EDL), with a secure proxy method to support Bearer Token authentication.
In the Palo Alto Web UI, go to Objects → External Dynamic Lists.
Click Add.
Fill in the fields:
Name: onefirewall_ipv4_feed
Type: IP List
Source:
If the Client Authentication appears like in figure, you can also put basic auth in the required section and the source will be like the following:
the credentials should be like explained in the figure.If the Client Authentication is not present, you can pass credentials like in the following section:
Copy
https://FIRST_63_CHAR_OF_TOKEN:[email protected](or your local on prem installation)/api/v1/ipv4/200?agid=827c65d86a44&plugin=paloalto"i.e. https://eyJh********************************.***********************Z3:VpZC************************************************************.*******************************************@app.onefirewall.com/api/v1/ipv4/200?agid=827c65d86a44&plugin=paloalto
Recurring: Every 15 minutes (or as needed)
Certificate Profile: (optional, only needed for HTTPS with custom certs)