Configure PAN Prisma Access for Arctic Wolf Active Response

With the Active Response service, Arctic Wolf® can perform network-based response actions in your network using PAN Prisma Access.

PAN Prisma Access supports these response actions:
  • Add a malicious IP address to a denylist
For more information, see Response action descriptions.

These resources are required:

  • Administrator access to PAN Prisma Access, including access to External Dynamic Lists and Security Policies.

These actions are required:

  • Contact your CST to validate the Active Response integration. Have an IP address ready that Arctic Wolf can use to validate the desired response actions without causing interruptions.

Create an external dynamic list

  1. In Strata Cloud Manager, set the Configuration Scope to Global.
  2. Navigate to Objects > External Dynamic Lists, and then click Add.
  3. Complete the required fields for the external dynamic list.
  4. Optional: If you are using Basic Auth:
    1. Download the PEM certificate for CN=Amazon Root CA 1,O=Amazon,C=US from the AWS certificate repository.
    2. Click Add Certificate Profile and upload the certificate.
  5. Click Save.
    Note: If the S3 bucket is changed to contain no entries, the EDL continues using the last populated version until at least one entry is added.

Create a security policy to allow EDL access

  1. Set the Configuration Scope to Mobile Users Container.
  2. Navigate to Security Services > Security Policy > Add Rule > Security Rule.
  3. Click Pre-Rule.
  4. In the Source section, set Zone to trust.
  5. In the Destination section:
    1. Set Zone to untrust.
    2. In Address, select the EDL list.
  6. In Application, select web-browsing.
  7. Under Actions, select Allow.
  8. Click Save, and then click Push Config to apply the configuration.

Create a security policy to block traffic by source IP

  1. Set the Configuration Scope to Mobile Users Container.
  2. Navigate to Security Services > Security Policy > Add Rule > Security Rule.
  3. Click Pre-Rule.
  4. In the Source section, select the EDL list in Addresses, and set Zones, Devices, and Users to Any.
  5. In the Destination section, set Zones, Addresses, and Devices to Any.
  6. Under Application, select Any.
  7. Under Actions, select Deny.
  8. Click Save, and then click Push Config to apply the configuration.

Create a security policy to block traffic by destination IP

  1. Set the Configuration Scope to Mobile Users Container.
  2. Navigate to Security Services > Security Policy > Add Rule > Security Rule.
  3. Click Pre-Rule.
  4. In the Source section, set Addresses, Zones, Users, and Devices to Any.
  5. In the Destination section, select the EDL list in Addresses, and then set Zones and Devices to Any.
  6. Under Application, select Any.
  7. Under Actions, select Deny.
  8. Click Save, and then click Push Config to apply the configuration.