S I E M
S I E M
Perch offers the ability to generate text files of blacklisted IP, Domain and URL lists to consume as dynamic block lists into a customer firewall.
This enables dynamic block lists to be serves from the sensor (this can take up to 24 hours to become fully functional)
There are options to consume 3 different URL’s into the dynamic block list configuration of the firewall.
http://sensorip/palo/ips.txt
contains IP addresses that are added to the list.
http://sensorip/palo/domains.txt
contains domains that are added to the list.
http://sensorip/palo/urls.txt
contains URLs that are added to the list.
Below is documentation from vendors on how to enable dynamic block list functionality in various platforms.
Palo Alto: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFOCA0