Skip to main content

Setup guide

Palo Alto EDL blocklist of malicious IPs and domains, sized to PAN-OS limits

PAN-OS loads isMalicious lists as External Dynamic Lists with client authentication and a certificate profile. The 50,000 riskiest critical IPs fit the IP budget of every model; block them in security rules, and domains by DNS sinkholing.

No credit card required · Free API key

Data path
  1. isMalicious

    api.ismalicious.com

    blocklist-ips-critical50k.txt

    Rebuilt every 12 h

  2. Palo Alto Networks

    Step 3

    Add the IP list

  3. Deny the list in security rules

    Step 4
On this page08

What you get

PA-3400, PA-5400, PA-5500 and PA-7500 hold 150,000 IPs across every EDL used in policy, as do the older PA-5200 and PA-7000; the PA-400, PA-500, PA-800 and PA-1400 Series and most VM-Series sizes hold 50,000. List Capacities shows your firewall’s figure. The smallest models hold 50,000 domains, so the three domain lists fit every model.

ListEntriesRebuiltPlans
blocklist-ips-critical50k.txtDefault IP EDL on every model: the 50,000 critical IPs with the highest risk score, highest first.50,000, cappedevery 12 hBasic, Pro, and Enterprise
blocklist-ips-c2.txtCommand-and-control IPs reported by C2 trackers: leaves room for another IP EDL on a 50,000-IP model.about 44,000every 12 hBasic, Pro, and Enterprise
blocklist-ips-critical.txtOnly where List Capacities shows 150,000 IPs.about 89,000every 12 hBasic, Pro, and Enterprise
blocklist-domains-c2.txtDomain EDL: command-and-control domains reported by C2 trackers.about 22,000every 12 hBasic, Pro, and Enterprise
blocklist-domains-ransomware.txtDomain EDL: domains in the ransomware category, whatever their level.about 3,600every 12 hBasic, Pro, and Enterprise
blocklist-domains-cryptomining.txtDomain EDL: domains in the cryptomining category, whatever their level.about 6,100every 12 hBasic, Pro, and Enterprise

Entries rounded from the build of ; each list is rebuilt every 12 hours. Today’s counts are public and need no key.

What each plan receives

  • FreeFree account, or no key: the first 10% of each list, marked X-Blocklist-Version: lite.
  • Basic, Pro, and EnterpriseBasic, Pro, and Enterprise: every list in full.
  • Pro and EnterpriseTAXII 2.1 collections, for platforms that read STIX indicators: Pro and Enterprise.

Compare plans

What a download returnsHTTP

GET https://api.ismalicious.com/blocklist/download/blocklist-ips-critical50k.txt

Full list or 10% sample

FieldBasic, Pro, and EnterpriseFree
X-Blocklist-Version:fulllite
X-Blocklist-Percentage:10010
Total entries:<COUNT><COUNT> (Lite Version - 10% of <TOTAL>)

First lines of the file

# IsMalicious.com Blocklist - IPs (Critical)
# Format: Plain
# Generated: <BUILD_TIME>
# Total entries: <COUNT>
# Update frequency: every 12 hours
# Category: Top 50000 by risk score
# Threat level: Critical
# Website: https://ismalicious.com
# © <YEAR> IsMalicious (compilation). Licensed to the downloading account under https://ismalicious.com/terms; redistribution of the compilation prohibited. Third-party entries remain under their providers' licences — see https://ismalicious.com/sources.
# Filtered by category: top 50000 by risk score
#

Values in angle brackets are set by each build.

Prerequisites

  • A supported PAN-OS release: 10.2 (Extended Support until 31 March 2027), 11.1, 11.2, 12.1 or 12.2. Client authentication on EDLs dates from PAN-OS 8.0.
  • PAN-OS fetches the lists from the management interface, or from a dedicated External Dynamic Lists service route (Device › Setup › Services › Service Route Configuration), and the firewall’s DNS servers (Device › Setup › Services) must resolve api.ismalicious.com.
  • For the domain lists only: a Threat Prevention or Advanced Threat Prevention license.
  • An isMalicious API key and secret, from Account › API access.
  • Outbound HTTPS (TCP 443) over IPv4 from PAN-OS to api.ismalicious.com, which has no IPv6 address.

Set it up

  1. Copy your API key and secret

    Open Account › API access and copy the API Key and the API Secret. The full list needs a Basic, Pro, or Enterprise plan; a Free key, or a lapsed plan, loads the 10% sample.
  2. Create a certificate profile for the api host

    • Client authentication only works with server authentication, so the EDL needs a certificate profile holding the root and intermediate certificates of api.ismalicious.com, which uses Let’s Encrypt.
    • Download the files below and import each one under Device › Certificate Management › Certificates, tab Device Certificates (Custom Certificates from PAN-OS 12.1), Import, File Format Base64 Encoded Certificate (PEM), no private key.
    • Then Device › Certificate Management › Certificate Profile › Add: name it isMalicious-LE, add every imported certificate under CA Certificates, and leave OCSP off, since Let’s Encrypt no longer runs OCSP responders.
    Certificates to importURL
    # Import each file (Base64 Encoded Certificate (PEM), no private key), then add
    # all of them as CA Certificates of one Certificate Profile (isMalicious-LE).
    https://letsencrypt.org/certs/isrgrootx1.pem
    https://letsencrypt.org/certs/isrg-root-x2.pem
    https://letsencrypt.org/certs/gen-y/root-ye.pem
    https://letsencrypt.org/certs/gen-y/root-x2-by-x1.pem
    https://letsencrypt.org/certs/gen-y/root-ye-by-x2.pem
    https://letsencrypt.org/certs/gen-y/int-ye1.pem
    https://letsencrypt.org/certs/gen-y/int-ye2.pem
    https://letsencrypt.org/certs/gen-y/int-ye3.pem
  3. Add the IP list

    Objects › External Dynamic Lists › Add: name isMalicious-IPs, Type IP List, Source the URL below, Certificate Profile isMalicious-LE. Turn on Client Authentication with the API key as Username and the API secret as Password and Confirm Password. Set Check for updates to Hourly (the documented default differs between pages) and click OK. Test Source URL is not available once authentication is on.
    Source URLURL
    https://api.ismalicious.com/blocklist/download/blocklist-ips-critical50k.txt
  4. Deny the list in security rules

    Policies › Security › Add two rules above your allow rules: one with isMalicious-IPs as Destination Address for outbound traffic, one with it as Source Address for inbound traffic, both with Application any, Service any (a new rule defaults to application-default, which matches each application on its standard ports only), Action Deny and logging on. Then Commit.
  5. Import the list and check its size

    Select the list under Objects › External Dynamic Lists and click Import Now. List Entries and Exceptions should then hold 50,000 entries for blocklist-ips-critical50k.txt. About 5,000 is the 10% sample: the firewall did not send the credentials (see Troubleshooting).
  6. Sinkhole the domains (optional)

    • Add a second EDL, isMalicious-Domains, with Type Domain List, blocklist-domains-c2.txt as the source, the same certificate profile and client authentication, and Check for updates set to Hourly.
    • In Objects › Security Profiles › Anti-Spyware, edit or clone a profile and, on the DNS Policies tab, add the EDL under External Dynamic Lists and set its Policy Action to sinkhole (it defaults to allow), keeping DNS Sinkhole enabled.
    • Attach the profile to the security rule that allows DNS, then Commit.

Verify it works

  • List Entries and Exceptions shows the entries the firewall retrieved: 50,000 for critical50k, since the header lines do not count. Filter for an address to check it.
  • List Capacities, on the same page, shows the entries used against what the model supports, per type.
  • Monitor › Logs › System shows a rejected username or password as edl-cli-auth-failure and a certificate failure as tls-edl-auth-failure. A failed fetch reads “EDL(isMalicious-IPs) Unable to fetch external dynamic list”, followed by the reason and “Using old copy for refresh.”
  • Monitor › Logs › Traffic shows the denied sessions; Device › Troubleshooting › Security Policy Match tests a listed address against your rules.
CLI and log filtersPAN-OS
# Operational mode. The output shows 100 entries: read "Total valid entries".
request system external-list show type ip name isMalicious-IPs
request system external-list show type domain name isMalicious-Domains

# The EDL capacities of this model:
show system state | match max-edl

# Monitor > Logs > System, authentication and certificate failures:
(eventid eq edl-cli-auth-failure)
(eventid eq tls-edl-auth-failure)

Troubleshooting

edl-cli-auth-failure in the System log

The key or the secret is wrong or incomplete. Palo Alto’s pages differ on whether the firewall keeps enforcing the last list after an authentication failure, so treat it as lost protection and fix it at once. The response body reads “Blocklist not found or empty”; trust the status code. Copy both values again from Account › API access: regenerating the key there invalidates the old pair.

About 5,000 entries instead of 50,000

That is the 10% sample: no credential reached the server, or the plan is Free or lapsed (past due, unpaid, canceled, incomplete or paused counts as Free). Check the plan and the client authentication fields. If both are right and the count stays at a tenth, serve the firewall a copy from a relay you control, as in the pfSense guide: the same netrc file, script and units.

Entries skipped for capacity

A System log reports the limit and List Capacities shows the use. Keep blocklist-ips-critical50k.txt or blocklist-ips-c2.txt, or reorder the EDLs: the one evaluated first fills the budget first. To reorder, clear Group By Type and use the arrows at the bottom of Objects › External Dynamic Lists.

Header lines in the list

PAN-OS has no whole-line comments, so it skips each # header line as an entry that does not match the list type: nothing to fix. Never point an IP list at a domain file, or the reverse.

tls-edl-auth-failure in the System log

The certificate profile lacks the root or the intermediate the api host now presents. Import the current files from letsencrypt.org/certs/ again: this can recur at a renewal, about every 60 days, when Let’s Encrypt switches intermediates. Do not disable server authentication instead: it also disables client authentication, which leaves the firewall with the 10% sample.

A timeout on a large list

A download that takes longer than 30 seconds on our side ends in a timeout or a 502: use a tier or category list from the table.

403 from ismalicious.com

The ismalicious.com edge refuses some sources. Use api.ismalicious.com, the host meant for appliances.

Limits

  • Whether PAN-OS sends the credentials with its first request, or only after a 401, is not documented and was not verified on a device. The download endpoint answers a request without credentials with the 10% sample rather than a 401, which is why the import step checks the count.
  • Where List Capacities shows 50,000 IPs, blocklist-ips-critical50k.txt fills the budget and leaves nothing for other IP lists; Palo Alto’s predefined lists do not count toward it.
  • No header-less file is served: the header lines are skipped, which is harmless, but they are there.
  • The certificate profile must follow Let’s Encrypt’s intermediates as they rotate. The certificate is ECDSA today; an RSA reissue would need the RSA chain from the same page.
  • No CIDR or ranges are served: PAN-OS accepts them, but the IP lists hold single addresses.
  • Domain lists need a Threat Prevention or Advanced Threat Prevention license.
  • The 10% sample is the first tenth of an unsorted file, not the riskiest tenth.

Questions

Can a Palo Alto EDL send an API key?

It sends a username and password with Client Authentication, available since PAN-OS 8.0 on HTTPS sources: the API key is the username, the API secret the password. It requires a certificate profile. Check the entry count after the first import: about a tenth means the credentials were not used.

How many IPs can a Palo Alto EDL hold?

150,000 across all EDLs used in policy on the PA-3400, PA-5400, PA-5500 and PA-7500, and on the older PA-5200 and PA-7000; 50,000 on the PA-400, PA-500, PA-800 and PA-1400 Series and most VM-Series sizes. List Capacities shows your firewall’s figure. blocklist-ips-critical50k.txt holds the 50,000 critical IPs with the highest risk score, so it fits every model.

Which certificate profile does the EDL need?

One that holds the Let’s Encrypt root and intermediate certificates the api host presents: PAN-OS needs both. Import the current files from letsencrypt.org/certs/, and import them again if a renewal moves to another intermediate.

How often should the EDL check for updates?

Hourly. The lists are rebuilt every 12 hours. Palo Alto’s pages disagree on the default interval, so set it explicitly.

Can PAN-OS block the domain lists?

Yes, as a Domain List EDL in the DNS policies of an Anti-Spyware profile, with the sinkhole action. It needs a Threat Prevention or Advanced Threat Prevention license. The C2, ransomware and cryptomining lists fit every model.

Get Started

Ready to get started?

No credit card required · Free API key