Configure PAN Prisma Access for Arctic Wolf Active Response
With the Active Response service, Arctic Wolf® can perform network-based response actions in your network using PAN Prisma Access.
PAN Prisma Access supports these response actions:
- Add a malicious IP address to a denylist
These resources are required:
- Administrator access to PAN Prisma Access, including access to External Dynamic Lists and Security Policies.
These actions are required:
- Contact your CST to validate the Active Response integration. Have an IP address ready that Arctic Wolf can use to validate the desired response actions without causing interruptions.
Create an external dynamic list
Create a security policy to allow EDL access
- Set the Configuration Scope to Mobile Users Container.
- Navigate to .
- Click Pre-Rule.
- In the Source section, set Zone to trust.
- In the Destination section:
- Set Zone to untrust.
- In Address, select the EDL list.
- In Application, select web-browsing.
- Under Actions, select Allow.
- Click Save, and then click Push Config to apply the configuration.
Create a security policy to block traffic by source IP
- Set the Configuration Scope to Mobile Users Container.
- Navigate to .
- Click Pre-Rule.
- In the Source section, select the EDL list in Addresses, and set Zones, Devices, and Users to Any.
- In the Destination section, set Zones, Addresses, and Devices to Any.
- Under Application, select Any.
- Under Actions, select Deny.
- Click Save, and then click Push Config to apply the configuration.
Create a security policy to block traffic by destination IP
- Set the Configuration Scope to Mobile Users Container.
- Navigate to .
- Click Pre-Rule.
- In the Source section, set Addresses, Zones, Users, and Devices to Any.
- In the Destination section, select the EDL list in Addresses, and then set Zones and Devices to Any.
- Under Application, select Any.
- Under Actions, select Deny.
- Click Save, and then click Push Config to apply the configuration.