<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with fetching Malicious IP feeds using sk103154 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-fetching-Malicious-IP-feeds-using-sk103154/m-p/101231#M10365</link>
    <description>&lt;P&gt;I am using the method described in&amp;nbsp;&lt;SPAN&gt;sk103154 Section 3. Not using ioc_feeds commands but scripts.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 05 Nov 2020 15:06:49 GMT</pubDate>
    <dc:creator>Antonis_Hassiot</dc:creator>
    <dc:date>2020-11-05T15:06:49Z</dc:date>
    <item>
      <title>Problem with fetching Malicious IP feeds using sk103154</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-fetching-Malicious-IP-feeds-using-sk103154/m-p/98991#M10363</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Trying to block incoming traffic from Malicious IPs using:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103154" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103154&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This is Section [3]&amp;nbsp; How to block traffic from custom IP feeds (managed from Management Server)&lt;/P&gt;&lt;P&gt;It seems to work ok for:&amp;nbsp;&lt;EM&gt;&lt;A href="https://secureupdates.checkpoint.com/IP-list/TOR.txt" target="_blank"&gt;https://secureupdates.checkpoint.com/IP-list/TOR.txt&lt;/A&gt;&amp;nbsp;as I can see the following output on the Gateway:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;operation=add uid=&amp;lt;5f85babb,000005d7,f102020a,0000132f&amp;gt; target=all timeout=3575 action=drop log=log comment=threatcloud_ip_block service=any source=range:199.249.230.165 pkt-rate=0 req_type=quota&lt;BR /&gt;operation=add uid=&amp;lt;5f85babb,000005d9,f102020a,0000132f&amp;gt; target=all timeout=3575 action=drop log=log comment=threatcloud_ip_block service=any source=range:199.249.230.167 pkt-rate=0 req_type=quota&lt;BR /&gt;operation=add uid=&amp;lt;5f85babb,000005da,f102020a,0000132f&amp;gt; target=all timeout=3575 action=drop log=log comment=threatcloud_ip_block service=any source=range:158.69.63.54 pkt-rate=0 req_type=quota&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;when issuing:&amp;nbsp; fw samp get | grep threatcloud_ip_block&lt;/P&gt;&lt;P&gt;Subsequently I have tried adding other feeds in there, but I don't see any new rules created as above. Examples:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.talosintelligence.com/documents/ip-blacklist" target="_blank"&gt;http://www.talosintelligence.com/documents/ip-blacklist&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://api.blocklist.de/getlast.php?time=600" target="_blank"&gt;https://api.blocklist.de/getlast.php?time=600&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Any idea on how to troubleshoot this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 14:50:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-fetching-Malicious-IP-feeds-using-sk103154/m-p/98991#M10363</guid>
      <dc:creator>Antonis_Hassiot</dc:creator>
      <dc:date>2020-10-13T14:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with fetching Malicious IP feeds using sk103154</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-fetching-Malicious-IP-feeds-using-sk103154/m-p/99440#M10364</link>
      <description>&lt;P&gt;Are you using ioc_feeds or something else?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 01:31:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-fetching-Malicious-IP-feeds-using-sk103154/m-p/99440#M10364</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-19T01:31:04Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with fetching Malicious IP feeds using sk103154</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-fetching-Malicious-IP-feeds-using-sk103154/m-p/101231#M10365</link>
      <description>&lt;P&gt;I am using the method described in&amp;nbsp;&lt;SPAN&gt;sk103154 Section 3. Not using ioc_feeds commands but scripts.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2020 15:06:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-fetching-Malicious-IP-feeds-using-sk103154/m-p/101231#M10365</guid>
      <dc:creator>Antonis_Hassiot</dc:creator>
      <dc:date>2020-11-05T15:06:49Z</dc:date>
    </item>
  </channel>
</rss>

