<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to block traffic coming from known malicious IP addresses R81.10 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137274#M25567</link>
    <description>&lt;P&gt;Exactly that is my point,&amp;nbsp;i would like to know how to check the feeds are working properly if&amp;nbsp; &amp;nbsp;I use smart console. I had a case with the TAC and told me is a must to run the CLI commands to make it work&lt;/P&gt;</description>
    <pubDate>Mon, 27 Dec 2021 20:06:28 GMT</pubDate>
    <dc:creator>DDiaz</dc:creator>
    <dc:date>2021-12-27T20:06:28Z</dc:date>
    <item>
      <title>How to block traffic coming from known malicious IP addresses R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137116#M25561</link>
      <description>&lt;P&gt;Hi everyone.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;After spending some time trying to configure (via SmartConsole R81.10) the blocking of IP addresses known as malicious, based on sk103154, I finally managed to make it work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was using the Check Point list (&lt;A href="https://secureupdates.checkpoint.com/IP-list/TOR.txt" target="_blank"&gt;https://secureupdates.checkpoint.com/IP-list/TOR.txt&lt;/A&gt;) and whenever I looked at the logs I got the error "Feed format problem. Feed format not supported".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is that we are not declaring a file in .csv format.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To solve this problem, just select "IP Address" in the type field, and enter "1" in the "Value" field of the custom feed settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cp_feeds.png" style="width: 338px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14686i9E63339EC489D40E/image-dimensions/338x511?v=v2" width="338" height="511" role="button" title="cp_feeds.png" alt="cp_feeds.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good luck to everyone.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 16:21:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137116#M25561</guid>
      <dc:creator>Rodrigo_Silva</dc:creator>
      <dc:date>2021-12-23T16:21:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to block traffic coming from known malicious IP addresses R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137125#M25562</link>
      <description>&lt;P&gt;Well done sir, thank you for sharing this. Happy holidays!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 19:30:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137125#M25562</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-12-23T19:30:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to block traffic coming from known malicious IP addresses R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137133#M25563</link>
      <description>&lt;P&gt;Yes, we were recently exploring the feature/function to block IP using custom IOC as&amp;nbsp;sk132193 described. Most of time the issue we ran into with the feed is format. Since different feed come in different format, each IOC feed need to have the format defined correctly. (In your example, type is IP address, and Value is located on 1st column). In some feed column 1 is name and column 2 is value (IP address).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any luck with Threat Intel feed that require API key access?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Dec 2021 01:14:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137133#M25563</guid>
      <dc:creator>Cyber_Serge</dc:creator>
      <dc:date>2021-12-24T01:14:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to block traffic coming from known malicious IP addresses R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137252#M25564</link>
      <description>&lt;P&gt;That's exactly it.&lt;BR /&gt;I haven't tested it with API key yet.&lt;BR /&gt;I'm researching it and as soon as I get something I'll post it here.&lt;BR /&gt;If you can get something post it here too, please.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Dec 2021 15:30:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137252#M25564</guid>
      <dc:creator>Rodrigo_Silva</dc:creator>
      <dc:date>2021-12-27T15:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to block traffic coming from known malicious IP addresses R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137253#M25565</link>
      <description>&lt;P&gt;Hi Rodrigo&lt;/P&gt;&lt;P&gt;Do you get output form this command?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Printing existing feeds&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;EM&gt;[Expert@HostName:0]# ioc_feeds show&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Regards&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Dec 2021 15:46:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137253#M25565</guid>
      <dc:creator>DDiaz</dc:creator>
      <dc:date>2021-12-27T15:46:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to block traffic coming from known malicious IP addresses R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137259#M25566</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/52346"&gt;@DDiaz&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I noticed that feeds added via SmartConsole only appear in SmartConcole, and the same is true for feeds added via cli.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 331px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14706iB0C9764C133EF445/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14707iD43B8F30E8FA9A0E/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 458px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14708i7826886912398DDD/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I didn't find this limitation in the documentation.&lt;/P&gt;&lt;P&gt;On sk132193 you can find the list of cli commands.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 27 Dec 2021 17:27:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137259#M25566</guid>
      <dc:creator>Rodrigo_Silva</dc:creator>
      <dc:date>2021-12-27T17:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to block traffic coming from known malicious IP addresses R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137274#M25567</link>
      <description>&lt;P&gt;Exactly that is my point,&amp;nbsp;i would like to know how to check the feeds are working properly if&amp;nbsp; &amp;nbsp;I use smart console. I had a case with the TAC and told me is a must to run the CLI commands to make it work&lt;/P&gt;</description>
      <pubDate>Mon, 27 Dec 2021 20:06:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137274#M25567</guid>
      <dc:creator>DDiaz</dc:creator>
      <dc:date>2021-12-27T20:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to block traffic coming from known malicious IP addresses R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137279#M25568</link>
      <description>&lt;P&gt;First check if the updates are ok.&lt;BR /&gt;You can check this by filtering the logs through the Anti-Bot and Anti-Virus blades.&lt;BR /&gt;blade:(Anti-Bot OR Anti-Virus).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="4.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14712iF18C57CFB1CA50B6/image-size/large?v=v2&amp;amp;px=999" role="button" title="4.png" alt="4.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If everything is fine, you will see the Prevents in the logs on those same blades.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="5.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14715iD37FD1F3CCE25BF6/image-size/large?v=v2&amp;amp;px=999" role="button" title="5.png" alt="5.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In my environment, I only see outgoing traffic being prevented.&lt;/P&gt;&lt;P&gt;My expectation was that all traffic originating from IPs known to be malicious would be blocked.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Dec 2021 21:28:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137279#M25568</guid>
      <dc:creator>Rodrigo_Silva</dc:creator>
      <dc:date>2021-12-27T21:28:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to block traffic coming from known malicious IP addresses R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137426#M25569</link>
      <description>&lt;P&gt;I can not find this logs in my environment, even if i curls the Urls meaning they are being downloading properly. I would appreciate if CP edit the SK with more details. Is not clear the steps on this. I had all this questions and TAC told us we must to run the cli commands. I can see in your environment works in another way&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 11:52:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137426#M25569</guid>
      <dc:creator>DDiaz</dc:creator>
      <dc:date>2021-12-30T11:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to block traffic coming from known malicious IP addresses R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137428#M25570</link>
      <description>&lt;P&gt;I agree with you. SK could definitely be edited with more details.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 13:01:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137428#M25570</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-12-30T13:01:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to block traffic coming from known malicious IP addresses R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137475#M25571</link>
      <description>&lt;P&gt;For my experience, the feed I added through smart console are added to all gateway managed by the smart management server (which is what I want).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since your feed is Tor Exit node, it make sense to observe it in outgoing traffic not incoming traffic.&lt;/P&gt;&lt;P&gt;If you want to see something for incoming traffic, try the Talos feed or AlienVault feed, you will see some external IP probing the firewall and prevented by the IPS/IOC feed.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 19:19:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137475#M25571</guid>
      <dc:creator>Cyber_Serge</dc:creator>
      <dc:date>2021-12-30T19:19:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to block traffic coming from known malicious IP addresses R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137476#M25572</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/52346"&gt;@DDiaz&lt;/a&gt;&amp;nbsp;, there is a troubleshooting section all the way at the bottom of&amp;nbsp;sk132193. It includes many commands you can use to narrow down the issue.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;First have to make sure the feed is pulling correctly, then have to make sure in read/ingest/interpret correctly by Check Point Gateway.&lt;BR /&gt;&lt;BR /&gt;In my experience, the first issue was feed not pulling correctly since I put http instead of https; 2nd issue was the format which I corrected it like&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25590"&gt;@Rodrigo_Silva&lt;/a&gt;&amp;nbsp;screenshot show us.&lt;BR /&gt;&lt;BR /&gt;Note that another issue I ran into is: if you are not pulling a remote feed and are importing a csv file locally from smart console, the csv file need to follow exact format as&amp;nbsp;sk132193 describe under the section&amp;nbsp;&amp;nbsp;"CSV (*.csv) format", which contain 7 fields:&amp;nbsp;UNIQ-NAME,VALUE,TYPE,CONFIDENCE,SEVERITY,PRODUCT,COMMENT&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 19:26:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137476#M25572</guid>
      <dc:creator>Cyber_Serge</dc:creator>
      <dc:date>2021-12-30T19:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to block traffic coming from known malicious IP addresses R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137477#M25573</link>
      <description>&lt;P&gt;Thank you very much&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25334"&gt;@Cyber_Serge&lt;/a&gt;&amp;nbsp;. Will try that ASAP. Will post my results&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 19:45:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137477#M25573</guid>
      <dc:creator>DDiaz</dc:creator>
      <dc:date>2021-12-30T19:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to block traffic coming from known malicious IP addresses R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137603#M25574</link>
      <description>&lt;P&gt;TOR exit node IPs are relevant for both ingress and egress blocking, See&amp;nbsp;&lt;A href="https://www.cisa.gov/uscert/ncas/alerts/aa20-183a" target="_blank"&gt;https://www.cisa.gov/uscert/ncas/alerts/aa20-183a &lt;/A&gt;for an analysis.&lt;/P&gt;
&lt;P&gt;An operationally viable approach for ingesting IOC feeds into Check Point enforcement points is provided by Infinity NDR. The feeds are managed centrally, and the individual IOCs can be seen and managed in the NDR application. They can then be selectively delivered via NDR "data sets", which are compatible with sk&lt;SPAN&gt;132193.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;: inbound blocking (as well as IPv6 indicators) are supported starting from R81.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;User guide: &lt;A href="https://community.checkpoint.com/t5/CloudGuard-NDR/Infinity-NDR-Intel-User-Guide/m-p/131434" target="_blank"&gt;https://community.checkpoint.com/t5/CloudGuard-NDR/Infinity-NDR-Intel-User-Guide/m-p/131434&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jan 2022 19:55:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137603#M25574</guid>
      <dc:creator>Nir_Naaman</dc:creator>
      <dc:date>2022-01-03T19:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to block traffic coming from known malicious IP addresses R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137752#M25575</link>
      <description>&lt;P&gt;Guys&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the output of this command in your environment?&amp;nbsp;&lt;/P&gt;&lt;P&gt;cat $FWDIR/conf/ioc_feeder.conf&lt;BR /&gt;{&lt;BR /&gt;"external_ioc": "on",&lt;BR /&gt;"interval": "300",&lt;BR /&gt;"ioc_bundle": "/database/ca_bundle.pem",&lt;BR /&gt;"feeds": {&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;[Expert@FW-MGMT-UY:0]#&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The interval does not change even if you modify it from:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To change the fetching interval, go to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Manage &amp;amp; Settings&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Blades&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Threat Prevention&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Advanced Settings&lt;/SPAN&gt;&lt;SPAN&gt;, go to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;External Feed&lt;/SPAN&gt;&lt;SPAN&gt;, and select the applicable interval.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jan 2022 15:41:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137752#M25575</guid>
      <dc:creator>Mstay</dc:creator>
      <dc:date>2022-01-05T15:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to block traffic coming from known malicious IP addresses R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137789#M25576</link>
      <description>&lt;P&gt;For what it's worth, you will also need to be on at least R81 to drop incoming traffic.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jan 2022 08:03:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/137789#M25576</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2022-01-06T08:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to block traffic coming from known malicious IP addresses R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/138116#M25577</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am running R81.10 in the SMS.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14833iA7111D99753714FB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14831i9299A0FA7EB655A2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14832i90BA031BE455604B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;URLS used for feed (or https). &lt;A href="http://secureupdates.checkpoint.com/IP-list/TOR.txt" target="_blank"&gt;http://secureupdates.checkpoint.com/IP-list/TOR.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Custom feed settings&lt;/P&gt;&lt;P&gt;Value 1 and type IP Address&lt;/P&gt;&lt;P&gt;Enabled Blades: Full Threat Prevention&lt;/P&gt;&lt;P&gt;curl_cli -v &lt;A href="http://secureupdates.checkpoint.com/IP-list/TOR.txt" target="_blank"&gt;http://secureupdates.checkpoint.com/IP-list/TOR.txt&lt;/A&gt; for SMS, GW Successfully&lt;/P&gt;&lt;P&gt;I am able to download properly the txt from the PC running Smart Console&lt;/P&gt;&lt;P&gt;I am not able to see the state of the Fetches by filtering the logs through the Anti-Bot and Anti-Virus blades.&lt;BR /&gt;blade:(Anti-Bot OR Anti-Virus).&lt;/P&gt;&lt;P&gt;Do i missing something?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 14:35:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/138116#M25577</guid>
      <dc:creator>Mstay</dc:creator>
      <dc:date>2022-01-11T14:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to block traffic coming from known malicious IP addresses R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/138126#M25578</link>
      <description>&lt;P&gt;Disclaimer that I'm still on R81 but here I can see the difference between something configured locally and something from the GUI...&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-01-11_16-12-23.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14834i66345D3694536617/image-size/large?v=v2&amp;amp;px=999" role="button" title="2022-01-11_16-12-23.png" alt="2022-01-11_16-12-23.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 15:15:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/138126#M25578</guid>
      <dc:creator>Mikael</dc:creator>
      <dc:date>2022-01-11T15:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to block traffic coming from known malicious IP addresses R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/138128#M25579</link>
      <description>&lt;P&gt;Which command was used&amp;nbsp;&lt;EM&gt;[Expert@HostName:0]# ioc_feeds show ?&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;I just have output using CLI IOC feeds. If smart console method is used nothing show&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;There is a lot off different things regarding this issue. SK must be updated, is very confusing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 15:27:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/138128#M25579</guid>
      <dc:creator>Mstay</dc:creator>
      <dc:date>2022-01-11T15:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to block traffic coming from known malicious IP addresses R81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/138130#M25580</link>
      <description>&lt;P&gt;Yes, thats from ioc_feeds show...&lt;/P&gt;&lt;P&gt;I have 7 feeds configured so there was too much to blur out to get it all in one screenshot&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 15:40:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-block-traffic-coming-from-known-malicious-IP-addresses/m-p/138130#M25580</guid>
      <dc:creator>Mikael</dc:creator>
      <dc:date>2022-01-11T15:40:21Z</dc:date>
    </item>
  </channel>
</rss>

