<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IOC FEED import does not work in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-FEED-import-does-not-work/m-p/151164#M24630</link>
    <description>&lt;P&gt;Always happy to be wrong if the right answer comes out as a result &lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Jun 2022 20:37:48 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-06-17T20:37:48Z</dc:date>
    <item>
      <title>IOC FEED import does not work</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-FEED-import-does-not-work/m-p/150836#M24529</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i am using the checkpoint IOC feed import feature for some known IOC feeds .&lt;/P&gt;&lt;P&gt;one of the know IOC feed is at location&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://raw.githubusercontent.com/ktsaou/blocklist-ipsets/master/firehol_level1.netset" target="_blank" rel="noopener"&gt;https://raw.githubusercontent.com/ktsaou/blocklist-ipsets/master/firehol_level1.netset&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is from firehol&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when i try to add in gateway using below command it gives me error&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;ioc_feeds add --feed_name Firehol --transport https --resource "&lt;/SPAN&gt;&lt;A href="https://raw.githubusercontent.com/ktsaou/blocklist-ipsets/master/firehol_level1.netset" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://raw.githubusercontent.com/ktsaou/blocklist-ipsets/master/firehol_level1.netset&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;" --format [value:1,type:ip] &lt;/SPAN&gt;&lt;SPAN&gt;--comment ["#"]&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;$FWDIR/bin/ioc_feeder -d -f&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;gives below&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Feed status Firehol :: IOC_FAILED_WHILE_PARSING&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;cat $FWDIR/log/ioc_feeder.elg | grep Firehol&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;gives below info&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;packFeeds: [WARN] Feed Firehol cannot be pushed.&lt;BR /&gt;Firehol: Feed format problem. Feed format not supported" severity 0&lt;BR /&gt;&amp;nbsp;Feed status Firehol :: IOC_FAILED_WHILE_PARSING&lt;BR /&gt;Firehol: Feed format problem. Feed format not supported&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The gateway is R81.10 take 55&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;there is case open with checkpoint support but as of now they can not tell me reason why it is not workin .&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2022 20:06:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-FEED-import-does-not-work/m-p/150836#M24529</guid>
      <dc:creator>Prashant_YADAV1</dc:creator>
      <dc:date>2022-06-14T20:06:53Z</dc:date>
    </item>
    <item>
      <title>Re: IOC FEED import does not work</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-FEED-import-does-not-work/m-p/150839#M24530</link>
      <description>&lt;P&gt;That file is not in the correct format and thus won’t work with ioc_feeder.&lt;BR /&gt;The formats supported are described here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk132193" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk132193&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;That file might be suitable for the Network Feed feature available in R81.20 (currently in public EA):&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Product-Announcements/R81-20-Public-EA-Program/ba-p/150291" target="_blank"&gt;https://community.checkpoint.com/t5/Product-Announcements/R81-20-Public-EA-Program/ba-p/150291&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2022 20:46:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-FEED-import-does-not-work/m-p/150839#M24530</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-06-14T20:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: IOC FEED import does not work</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-FEED-import-does-not-work/m-p/151043#M24598</link>
      <description>&lt;P&gt;Normally, I would never argue with PhoneBoy, but I think he is wrong here.&lt;/P&gt;
&lt;P&gt;Your feed seems supported and working (even on R80.40 where this IOC feed feature is missing some features). When you look at the&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk132193" target="_self"&gt;sk132193&lt;/A&gt;&amp;nbsp; PhoneBoy links to, it is even shown as example "&lt;STRONG&gt;Original CSV structure is a list of IP addresses in CIDR format&lt;/STRONG&gt;"&lt;/P&gt;
&lt;P&gt;I think your problem is not the feed format itself.&lt;/P&gt;
&lt;P&gt;Please post your $FWDIR/conf/ioc_feeder.conf.&lt;/P&gt;
&lt;P&gt;I guess it is missing the comment statement you provided within your ioc_feeds add command. This is known bug at least in R80.40, R&amp;amp;D is currently working on (yes, I have a TAC case running for this). Maybe you see this also on R81.10.&lt;/P&gt;
&lt;P&gt;TLDR:&lt;/P&gt;
&lt;P&gt;I got this feed working with the same ioc_feeds add command, you used. The only thing I did: I added the missing comment line to $FWDIR/conf/ioc_feeder.conf:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;{
    "external_ioc": "on",
    "interval": "300",
    "ioc_bundle": "/database/ca_bundle.pem",
    "feeds": {
        "Firehol": {
            "feed_action": "prevent",
            "resource": "https://raw.githubusercontent.com/ktsaou/blocklist-ipsets/master/firehol_level1.netset",
            "format": "[value:1,type:ip]",
            "comment": "#",
            "input_name": "Firehol_https",
            "active": "true",
            "feed_format": "custom_csv",
            "transport": "https"
        }
    }
}&lt;/LI-CODE&gt;
&lt;P&gt;After that, I refetched the feeds with:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[Expert@gateway:0]# $FWDIR/bin/ioc_feeder -d -f
Convert your csv format to Check Point's supported csv format. Supported fields: [name,value,type,confidence,severity,product,comment]
All content coming after  ['#']  will be ignored

[Name, Value, Type]
observ1,0.0.0.0-0.255.255.255,ip range,,,,
observ2,1.10.16.0-1.10.31.255,ip range,,,,
observ3,1.19.0.0-1.19.255.255,ip range,,,,
observ4,1.32.128.0-1.32.191.255,ip range,,,,
observ5,2.56.192.0-2.56.195.255,ip range,,,,
observ6,2.57.185.0-2.57.185.255,ip range,,,,
observ7,2.57.186.0-2.57.187.255,ip range,,,,
observ8,2.57.232.0-2.57.235.255,ip range,,,,
observ9,2.59.200.0-2.59.203.255,ip range,,,,
observ10,5.134.128.0-5.134.159.255,ip range,,,,
observ11,5.180.4.0-5.180.7.255,ip range,,,,

Successfully converted
IPS package: Compiled OK.
Signatures loaded successfully&lt;/LI-CODE&gt;
&lt;P&gt;Working fine.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 10:41:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-FEED-import-does-not-work/m-p/151043#M24598</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2022-06-16T10:41:45Z</dc:date>
    </item>
    <item>
      <title>Re: IOC FEED import does not work</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-FEED-import-does-not-work/m-p/151164#M24630</link>
      <description>&lt;P&gt;Always happy to be wrong if the right answer comes out as a result &lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2022 20:37:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-FEED-import-does-not-work/m-p/151164#M24630</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-06-17T20:37:48Z</dc:date>
    </item>
    <item>
      <title>Re: IOC FEED import does not work</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-FEED-import-does-not-work/m-p/151176#M24633</link>
      <description>&lt;P&gt;I tried it the easy way - using Infinity NDR Intel.&lt;/P&gt;
&lt;P&gt;There are 2,538 IoCs here - all of them get imported cleanly if you define an input feed on this URL.&lt;/P&gt;
&lt;P&gt;You can see the output feed from my test domain - published at:&amp;nbsp;&lt;A href="https://feeds.now.checkpoint.com/public_feeds/testIOCs-firehol_level1-detect.csv" target="_blank"&gt;https://feeds.now.checkpoint.com/public_feeds/testIOCs-firehol_level1-detect.csv&lt;/A&gt;. Should be compatible with R80.30 and above.&lt;/P&gt;
&lt;P&gt;Here's all I did - defined the feed as single-type list (IP) without header, and the IOCs started to populate automatically:&lt;/P&gt;
&lt;DIV id="tinyMceEditor_da437a5f765714Nir_Naaman_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Feed.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16973i80B27086AD447ECF/image-size/large?v=v2&amp;amp;px=999" role="button" title="Feed.PNG" alt="Feed.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Feed II.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16974iCA67011D8EFF0006/image-size/large?v=v2&amp;amp;px=999" role="button" title="Feed II.PNG" alt="Feed II.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2022 22:07:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-FEED-import-does-not-work/m-p/151176#M24633</guid>
      <dc:creator>Nir_Naaman</dc:creator>
      <dc:date>2022-06-17T22:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: IOC FEED import does not work</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-FEED-import-does-not-work/m-p/151236#M24654</link>
      <description>&lt;P&gt;Thanks a Lot Nir, i will try and see if this works&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 08:18:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-FEED-import-does-not-work/m-p/151236#M24654</guid>
      <dc:creator>Prashant_YADAV1</dc:creator>
      <dc:date>2022-06-20T08:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: IOC FEED import does not work</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-FEED-import-does-not-work/m-p/151237#M24655</link>
      <description>&lt;P&gt;Thanks a Tobias, i will try and see if this works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 08:19:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-FEED-import-does-not-work/m-p/151237#M24655</guid>
      <dc:creator>Prashant_YADAV1</dc:creator>
      <dc:date>2022-06-20T08:19:09Z</dc:date>
    </item>
  </channel>
</rss>

