Configuring EDLs on your firewall
Most firewalls have the capability to support external lists or External Dynamic Lists (EDLs) directly via configuration, additionally most Linux based firewalls can be made to support EDLs with the addition of some simple scripting.
Supported Firewalls and EDL configuration locations:
The firewall type structure the files and content in a way that is supported by firewall vendors, if your firewall vendor is not listed here, please contact us with the details and we’ll work out what is possible.
| Firewall Vendor | Feature Name | UI Configuration Path | API – FW_Type to use |
| Fortinet Fortigate | Block List / Threat Feed | Security Fabric > External Connectors | fortigate |
| Palo Alto Networks | External Dynamic List (EDL) | Objects > External Dynamic Lists | paloalto |
| Cisco ASA / FTD | Security Intelligence Feed | Objects > Security Intelligence | cisco * |
| CheckPoint >= R81.20 | External IoC Feed | Threat Prevention > Custom Intelligence | checkpoint |
| pfSense OPNsense | URL Alias (IP List) | Firewall > Aliases > URL Table | pfsense * |
| Sophos XG Limitations due to lack of FW support including polling interval apply. | IP Threat Feed | System Services > Dynamic Threat Feeds | sophos * |
| SonicWall | Dynamic External Objects | Manage > Objects > Dynamic External Objects | sonicwall * |
| IPTables / UFW | Scripting required | Scripting required | Custom, contact support for more information. |
* API FW_Type currently in Beta testing.
A general guide for configuring EDLs on a firewall:
- Create the list definition in the appropriate firewall UI location.
Often this involves choosing a name, adding the URL for the list source, the refresh frequency and some other options.
Some firewalls will fetch the EDL immediately after a configuration commit, some will require the EDL to be referenced in an active policy entry first.
There may be a ‘test’ option to make sure the URL for the EDL can be reached. - Check our API documentation, we have options for different firewalls, which have optimised the lists for individual firewall functionality and wildcard use.
- Configure the EDLs in a policy, for different types of EDL, the policy location may vary. IP Address lists may be part of the main security policy, URL lists part of a URL / category / security profile policy, and DNS filtering lists may be elsewhere, for example Palo Alto have this configured under Anti-Spyware security profile.
Most likely these security profiles may need to be correctly configured in the main firewall security policy as well.
Some firewalls do not process IPv4 and IPv6 lists correctly in the same policy line, you may need to duplicate policy lines for different IP version lists. - Make sure you have the EDL based securtity rules at an appropriate place in your policy, rule order matters, and as many VPN’s pretent to be other applications, HTTPS, Social media apps, News media apps, DNS, NTP etc. It’s important to ensure the IP based blocking is done early in the policy. Similar applies to allow rules based on EDLs.
- Commit your configuration changes, one of the main benefits of using EDLs is that updates occur periodically and automatically from this point onwards, no manual intervention is required.
- Verify the EDL’s have download correctly.
- Verify the Allow / Blocking policies based on EDLs work as expected for IPv4, IPv6, URL’s and DNS.
Common EDL Types:
There are common types of EDL, most firewalls support IP address and URL lists, some add domains, other options are more specific often to individual firewall vendors.
IP Addresses, IPv4, IPv6, these often support singlets, networks and in some cases ranges, must be in a valid format.
URLs, text strings that identifies a URL or multiple URL’s, often these support wildcards and other special characters for more advanced matching, although the implementation varies between firewall vendors, some vendors do not support wildcards.
Domain, text strings that identify a host, hosts, or an entire domain or subdomain, often these support wildcards and other special characters for more advanced matching, although the implementation varies between firewall vendors, some vendors do not support wildcards.
Hash, some firewalls support a text string ‘hash’ list type that identifies files by hash, often used for Malware blocking. Mixing hash functions in a single EDL can result in sub-optimal performance on some firewalls.
IMEI / IMSI, some firewalls support IMEI and IMSI’s in EDL’s for 4G / 5G security policies.
MAC Address, some firewalls support MAC address list, used for enforcing Layer 2 policies.
EDL Limitations:
Check your firewall vendor and firewall model specific documentation for the limitations on EDL use. There are often limits on the number of EDLs that can be configured, the length of the lists and the overall size of the lists, both individually and / or all lists in total.
The Firewall system log should indicate if any list overruns have taken place, as well as any failed scheduled updates or other errors.
Firewalls often keep using older lists if updates fail, for at least some period of time. Again, this is typically vendor specific.
Many of our EDL API endpoints allow aggregation of results, for example including multiple AS numbers in the request to aggregate them with the main response to optimise EDL use.
Likewise you can request combined IP lists if your firewall properly supports mixing IP versions, networks and ranges in a single list. while firewall vendors or models with smaller list capacity may require some customer parameters to split large EDL sources into multiple EDLs. Please contact our support team if you need to do this.
