---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Supported External Dynamic Lists for Palo Alto Networks Next-Generation Firewall

# Supported External Dynamic Lists for Palo Alto Networks Next-Generation Firewall {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The ServiceNow
Palo Alto Networks Next-Generation Firewall
integration supports External Dynamic Lists (EDLs) that accept IP, URL, and domain
observables.

## Supported EDLs and observables {#paloalto_supported_edls__section_rfp_gzf_5db}

An External Dynamic List is a text file that is hosted on an external
web server, which for this integration is the ServiceNow AI Platform instance. The Palo Alto Networks Next-Generation Firewall can then import objects --- IP addresses, URLs, domains --- included in the list and
enforce policy. To enforce policy on the EDL entries, the list is referenced in a
policy rule or profile.  
This integration supports three types of EDLs:

* IP (This includes a single IP Address, as well as CIDR blocks (ranges) of addresses).
* URL
* Domain
{#paloalto_supported_edls__ul_v3x_jzf_5db}

The following table lists descriptions of the observables supported by this
integration and example formats for each type.
{#paloalto_supported_edls__table_chs_vzf_5db__entry__3}

| Observable | Example formats | Description |
|-|-|-|
| IP Address | * 95.153.103.54 (IPv4) * (IPv6): 2001:00B8:130F:FE03:0000:09C0:080F:130B {#paloalto_supported_edls__ul_mrq_j1g_5db} | Represents a single, distinct interface address. The integration supports IPv4, IPv6, and CIDR formats. Support for IP address observables includes CIDR (Classless Inter-Domain Routing) ranges, for example, 95.153.100.0/22. Note: An error message is displayed when you try to attach a single IP address to an EDL that you have already blocked as a part of a CIDR range. For example, the single address 95.153.103.54 is part of the CIDR range represented by 95.153.100.0/22 (95.153.100.0-95.153.103.255). |
| URL | * www.example.com * www.example.com/article.html * example.com * \*.example.com {#paloalto_supported_edls__ul_csz_l1g_5db} | Wildcards are supported. The ServiceNow AI Platform reformats URL entries to comply with Palo Alto Networks EDL format requirements. |
| Domain | * www.example.com * example.com * mail.example.com {#paloalto_supported_edls__ul_zl2_v1g_5db} | Wildcards are not supported. |
[Table 1. Supported observables and example formats]

{#paloalto_supported_edls__table_chs_vzf_5db}

For more information about formatting guidelines and EDLs, see ["Formatting Guidelines for an External Dynamic
List" in the PAN-OS 10.0 Administrator's Guide](https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/policy/use-an-external-dynamic-list-in-policy/formatting-guidelines-for-an-external-dynamic-list.html) on the Palo Alto Networks website.
**Previous topic:** [Create the API account role for Palo Alto Networks Next-Generation Firewall](https://servicenow-prod.fluidtopics.net/IjRyfz73NXHlZ_jo6ym24g "An API account role is required in your ServiceNow AI Platform instance for this integration. The Username and Password associated with this account are created in the ServiceNow AI Platform and entered in Palo Alto Networks so the Palo Alto Networks Next-Generation Firewall authenticates with the ServiceNow AI Platform when retrieving EDL entries.")  
**Next topic:** [Create an EDL for Palo Alto Networks Next-Generation Firewall](https://servicenow-prod.fluidtopics.net/rmKqx0JXpQzWtQVP6qxz5w "Create an External Dynamic List (EDL) in your ServiceNow AI Platform instance. Once approved and activated, you can create entries for EDLs from observables determined to be malicious on ServiceNow AI Platform Security Incident Response (SIR) incidents and request approval to block them.")

