← Files CrowdStrike Falcon FusionARCHIVED FILE

skills/authoring/examples/response-actions/pan-ngfw-allowlist-edl-exception.yaml

2.98 KB · Oct 5, 2026 · 18:32 UTC

↓ Download file

# Example: PAN NGFW - Allowlist (Add to EDL Exception List)
# Category: response-actions
# Source: CrowdStrike Content Library

name: PAN NGFW - Allowlist - Add to EDL Exception List
description: Adds an exception entry (IP, domain, or URL) to a specified External Dynamic List (EDL) on a PAN NGFW firewall, then commits the configuration. Use this to allowlist an indicator that would otherwise be blocked by an EDL-based security policy.
trigger:
  next:
    - SetEDLException
  name: On demand
  type: On demand
  parameters:
    properties:
      EDLName:
        type: string
        description: Exact name of the EDL object on the firewall to add the exception to
      EntryValue:
        type: string
        description: IP address, domain, or URL to add to the exception list (e.g. 1.2.3.4)
      FirewallIP:
        type: string
        description: IP address or hostname of the PAN NGFW management interface
    required:
      - EDLName
      - EntryValue
      - FirewallIP
    type: object
actions:
  CommitConfiguration:
    id: 50b8a7cc77ea4ebb9d0bbe96d8def095
    class: Inline.HTTPRequest
    name: Commit Configuration
    version_constraint: ~1
    properties:
      authentication_option: UseExisting
      definition_id: 31fd9a5893df4127b93f9d27e80a1ea9
      deployment_model: on_prem
      http_transaction:
        request_body: '{}'
        request_content_type: JSON
        request_headers: {}
        request_http_method: POST
        request_query:
          065101a4-20c5-4861-a03b-a858a6289c10:
            name: cmd
            value: <commit></commit>
          67549652-6f62-4f51-b959-d3241f203238:
            name: type
            value: commit
        request_url: https://${data['FirewallIP']}/api
        response_body: ''
        response_status_code: 200
  SetEDLException:
    id: 50b8a7cc77ea4ebb9d0bbe96d8def095
    class: Inline.HTTPRequest
    name: Set EDL Exception
    version_constraint: ~1
    next:
      - CommitConfiguration
    properties:
      authentication_option: UseExisting
      definition_id: 31fd9a5893df4127b93f9d27e80a1ea9
      deployment_model: on_prem
      host_group_id: 4775ad67cafd4edb90aa9d250678c871
      http_transaction:
        request_body: '{}'
        request_content_type: JSON
        request_headers: {}
        request_http_method: POST
        request_query:
          1e79e667-45ce-4bb6-90c0-3d8082954b35:
            name: type
            value: config
          6add92e5-3fb1-450a-9616-af2d6ebc06b8:
            name: action
            value: set
          b7b4d751-f536-4629-a065-a895848320b9:
            name: element
            value: <member>${data['EntryValue']}</member>
          fe204fdb-9a8b-4aec-91d1-b58ddf50b532:
            name: xpath
            value: /config/devices/entry[@name='localhost.localdomain']/vsys/entry[@name='vsys1']/external-list/entry[@name='${data['EDLName']}']/exception
        request_url: https://${data['FirewallIP']}/api
        response_body: ''
        response_status_code: 200
      insecure_skip_verify: true

SHA-256: f0d002058aca826f327259ed20ec5cc86755bbc0f5a7258f58aec9ac77f8fac0