- Home
- Integrations
- Palo Alto Networks
Setup guide
Palo Alto EDL blocklist of malicious IPs and domains, sized to PAN-OS limits
No credit card required · Free API key
On this page
On this page08
What you get
PA-3400, PA-5400, PA-5500 and PA-7500 hold 150,000 IPs across every EDL used in policy, as do the older PA-5200 and PA-7000; the PA-400, PA-500, PA-800 and PA-1400 Series and most VM-Series sizes hold 50,000. List Capacities shows your firewall’s figure. The smallest models hold 50,000 domains, so the three domain lists fit every model.
| List | Entries | Rebuilt | Plans |
|---|---|---|---|
| blocklist-ips-critical50k.txtDefault IP EDL on every model: the 50,000 critical IPs with the highest risk score, highest first. | 50,000, capped | every 12 h | Basic, Pro, and Enterprise |
| blocklist-ips-c2.txtCommand-and-control IPs reported by C2 trackers: leaves room for another IP EDL on a 50,000-IP model. | about 44,000 | every 12 h | Basic, Pro, and Enterprise |
| blocklist-ips-critical.txtOnly where List Capacities shows 150,000 IPs. | about 89,000 | every 12 h | Basic, Pro, and Enterprise |
| blocklist-domains-c2.txtDomain EDL: command-and-control domains reported by C2 trackers. | about 22,000 | every 12 h | Basic, Pro, and Enterprise |
| blocklist-domains-ransomware.txtDomain EDL: domains in the ransomware category, whatever their level. | about 3,600 | every 12 h | Basic, Pro, and Enterprise |
| blocklist-domains-cryptomining.txtDomain EDL: domains in the cryptomining category, whatever their level. | about 6,100 | every 12 h | Basic, Pro, and Enterprise |
Entries rounded from the build of ; each list is rebuilt every 12 hours. Today’s counts are public and need no key.
What each plan receives
- FreeFree account, or no key: the first 10% of each list, marked
X-Blocklist-Version: lite. - Basic, Pro, and EnterpriseBasic, Pro, and Enterprise: every list in full.
- Pro and EnterpriseTAXII 2.1 collections, for platforms that read STIX indicators: Pro and Enterprise.
GET https:/
Full list or 10% sample
| Field | Basic, Pro, and Enterprise | Free |
|---|---|---|
X-Blocklist-Version: | full | lite |
X-Blocklist-Percentage: | 100 | 10 |
Total entries: | <COUNT> | <COUNT> |
First lines of the file
# IsMalicious.com Blocklist - IPs (Critical)
# Format: Plain
# Generated: <BUILD_TIME>
# Total entries: <COUNT>
# Update frequency: every 12 hours
# Category: Top 50000 by risk score
# Threat level: Critical
# Website: https://ismalicious.com
# © <YEAR> IsMalicious (compilation). Licensed to the downloading account under https://ismalicious.com/terms; redistribution of the compilation prohibited. Third-party entries remain under their providers' licences — see https://ismalicious.com/sources.
# Filtered by category: top 50000 by risk score
#Values in angle brackets are set by each build.
Prerequisites
- A supported PAN-OS release: 10.2 (Extended Support until 31 March 2027), 11.1, 11.2, 12.1 or 12.2. Client authentication on EDLs dates from PAN-OS 8.0.
- PAN-OS fetches the lists from the management interface, or from a dedicated External Dynamic Lists service route (Device › Setup › Services › Service Route Configuration), and the firewall’s DNS servers (Device › Setup › Services) must resolve
api.ismalicious.com. - For the domain lists only: a Threat Prevention or Advanced Threat Prevention license.
- An isMalicious API key and secret, from Account › API access.
- Outbound HTTPS (TCP 443) over IPv4 from PAN-OS to
api.ismalicious.com, which has no IPv6 address.
Set it up
Copy your API key and secret
Open Account › API access and copy the API Key and the API Secret. The full list needs a Basic, Pro, or Enterprise plan; a Free key, or a lapsed plan, loads the 10% sample.Create a certificate profile for the api host
- Client authentication only works with server authentication, so the EDL needs a certificate profile holding the root and intermediate certificates of
api.ismalicious.com, which uses Let’s Encrypt. - Download the files below and import each one under Device › Certificate Management › Certificates, tab Device Certificates (Custom Certificates from PAN-OS 12.1), Import, File Format Base64 Encoded Certificate (PEM), no private key.
- Then Device › Certificate Management › Certificate Profile › Add: name it
isMalicious-LE, add every imported certificate under CA Certificates, and leave OCSP off, since Let’s Encrypt no longer runs OCSP responders.
Certificates to importURL # Import each file (Base64 Encoded Certificate (PEM), no private key), then add # all of them as CA Certificates of one Certificate Profile (isMalicious-LE). https://letsencrypt.org/certs/isrgrootx1.pem https://letsencrypt.org/certs/isrg-root-x2.pem https://letsencrypt.org/certs/gen-y/root-ye.pem https://letsencrypt.org/certs/gen-y/root-x2-by-x1.pem https://letsencrypt.org/certs/gen-y/root-ye-by-x2.pem https://letsencrypt.org/certs/gen-y/int-ye1.pem https://letsencrypt.org/certs/gen-y/int-ye2.pem https://letsencrypt.org/certs/gen-y/int-ye3.pem- Client authentication only works with server authentication, so the EDL needs a certificate profile holding the root and intermediate certificates of
Add the IP list
Objects › External Dynamic Lists › Add: nameisMalicious-IPs, Type IP List, Source the URL below, Certificate ProfileisMalicious-LE. Turn on Client Authentication with the API key as Username and the API secret as Password and Confirm Password. Set Check for updates to Hourly (the documented default differs between pages) and click OK. Test Source URL is not available once authentication is on.Source URLURL https://api.ismalicious.com/blocklist/download/blocklist-ips-critical50k.txtDeny the list in security rules
Policies › Security › Add two rules above your allow rules: one withisMalicious-IPsas Destination Address for outbound traffic, one with it as Source Address for inbound traffic, both with Application any, Service any (a new rule defaults to application-default, which matches each application on its standard ports only), Action Deny and logging on. Then Commit.Import the list and check its size
Select the list under Objects › External Dynamic Lists and click Import Now. List Entries and Exceptions should then hold 50,000 entries forblocklist-ips-critical50k.. About 5,000 is the 10% sample: the firewall did not send the credentials (see Troubleshooting).txt Sinkhole the domains (optional)
- Add a second EDL,
isMalicious-Domains, with Type Domain List,blocklist-domains-c2.txtas the source, the same certificate profile and client authentication, and Check for updates set to Hourly. - In Objects › Security Profiles › Anti-Spyware, edit or clone a profile and, on the DNS Policies tab, add the EDL under External Dynamic Lists and set its Policy Action to sinkhole (it defaults to allow), keeping DNS Sinkhole enabled.
- Attach the profile to the security rule that allows DNS, then Commit.
- Add a second EDL,
Verify it works
- List Entries and Exceptions shows the entries the firewall retrieved: 50,000 for
critical50k, since the header lines do not count. Filter for an address to check it. - List Capacities, on the same page, shows the entries used against what the model supports, per type.
- Monitor › Logs › System shows a rejected username or password as
edl-cli-auth-failureand a certificate failure astls-edl-auth-failure. A failed fetch reads “EDL(isMalicious-IPs) Unable to fetch external dynamic list”, followed by the reason and “Using old copy for refresh.” - Monitor › Logs › Traffic shows the denied sessions; Device › Troubleshooting › Security Policy Match tests a listed address against your rules.
# Operational mode. The output shows 100 entries: read "Total valid entries".
request system external-list show type ip name isMalicious-IPs
request system external-list show type domain name isMalicious-Domains
# The EDL capacities of this model:
show system state | match max-edl
# Monitor > Logs > System, authentication and certificate failures:
(eventid eq edl-cli-auth-failure)
(eventid eq tls-edl-auth-failure)Troubleshooting
edl-cli-auth-failure in the System log
The key or the secret is wrong or incomplete. Palo Alto’s pages differ on whether the firewall keeps enforcing the last list after an authentication failure, so treat it as lost protection and fix it at once. The response body reads “Blocklist not found or empty”; trust the status code. Copy both values again from Account › API access: regenerating the key there invalidates the old pair.
About 5,000 entries instead of 50,000
That is the 10% sample: no credential reached the server, or the plan is Free or lapsed (past due, unpaid, canceled, incomplete or paused counts as Free). Check the plan and the client authentication fields. If both are right and the count stays at a tenth, serve the firewall a copy from a relay you control, as in the pfSense guide: the same netrc file, script and units.
Entries skipped for capacity
A System log reports the limit and List Capacities shows the use. Keep blocklist-ips-critical50k. or blocklist-ips-c2.txt, or reorder the EDLs: the one evaluated first fills the budget first. To reorder, clear Group By Type and use the arrows at the bottom of Objects › External Dynamic Lists.
Header lines in the list
PAN-OS has no whole-line comments, so it skips each # header line as an entry that does not match the list type: nothing to fix. Never point an IP list at a domain file, or the reverse.
tls-edl-auth-failure in the System log
The certificate profile lacks the root or the intermediate the api host now presents. Import the current files from letsencrypt.org/certs/ again: this can recur at a renewal, about every 60 days, when Let’s Encrypt switches intermediates. Do not disable server authentication instead: it also disables client authentication, which leaves the firewall with the 10% sample.
A timeout on a large list
A download that takes longer than 30 seconds on our side ends in a timeout or a 502: use a tier or category list from the table.
403 from ismalicious.com
The ismalicious.com edge refuses some sources. Use api.ismalicious.com, the host meant for appliances.
Limits
- Whether PAN-OS sends the credentials with its first request, or only after a 401, is not documented and was not verified on a device. The download endpoint answers a request without credentials with the 10% sample rather than a 401, which is why the import step checks the count.
- Where List Capacities shows 50,000 IPs,
blocklist-ips-critical50k.fills the budget and leaves nothing for other IP lists; Palo Alto’s predefined lists do not count toward it.txt - No header-less file is served: the header lines are skipped, which is harmless, but they are there.
- The certificate profile must follow Let’s Encrypt’s intermediates as they rotate. The certificate is ECDSA today; an RSA reissue would need the RSA chain from the same page.
- No CIDR or ranges are served: PAN-OS accepts them, but the IP lists hold single addresses.
- Domain lists need a Threat Prevention or Advanced Threat Prevention license.
- The 10% sample is the first tenth of an unsorted file, not the riskiest tenth.
Questions
Can a Palo Alto EDL send an API key?
It sends a username and password with Client Authentication, available since PAN-OS 8.0 on HTTPS sources: the API key is the username, the API secret the password. It requires a certificate profile. Check the entry count after the first import: about a tenth means the credentials were not used.
How many IPs can a Palo Alto EDL hold?
150,000 across all EDLs used in policy on the PA-3400, PA-5400, PA-5500 and PA-7500, and on the older PA-5200 and PA-7000; 50,000 on the PA-400, PA-500, PA-800 and PA-1400 Series and most VM-Series sizes. List Capacities shows your firewall’s figure. blocklist-ips-critical50k. holds the 50,000 critical IPs with the highest risk score, so it fits every model.
Which certificate profile does the EDL need?
One that holds the Let’s Encrypt root and intermediate certificates the api host presents: PAN-OS needs both. Import the current files from letsencrypt.org/certs/, and import them again if a renewal moves to another intermediate.
How often should the EDL check for updates?
Hourly. The lists are rebuilt every 12 hours. Palo Alto’s pages disagree on the default interval, so set it explicitly.
Can PAN-OS block the domain lists?
Yes, as a Domain List EDL in the DNS policies of an Anti-Spyware profile, with the sinkhole action. It needs a Threat Prevention or Advanced Threat Prevention license. The C2, ransomware and cryptomining lists fit every model.
Related
IP and domain feeds with basic authentication
A URL Table alias or pfBlockerNG feed through a relay
URL Table aliases with Basic authorization
Threat domains as a RouterOS DNS adlist
Threat IPs as nftables sets on any Linux host
Keep firewall blocklists current
Every list, level and category
TAXII 2.1 collections for SIEMs and TIPs
Authentication, endpoints and limits
Check one address before you block it
Get Started
Ready to get started?
No credit card required · Free API key