<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Network feed in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/219726#M42012</link>
    <description>&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk132193" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk132193&lt;/A&gt;&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;IP Allow List (Exception List)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The IP whitelist provides a convenient way to allow certain IP addresses to bypass the enforcement actions, that have been defined by threat intelligence feeds.&lt;/P&gt;&lt;P&gt;This document provides instructions for managing IP addresses within the IP white list, also known as the IP exception list.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;Edit the File&lt;/STRONG&gt;:&lt;/LI&gt;&lt;/OL&gt;&lt;P class="lia-indent-padding-left-60px"&gt;&lt;STRONG&gt;vi $FWDIR/conf/ip_whitelist.eng&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;Append IP Addresses&lt;/STRONG&gt;:&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Add the desired IP addresses, one per line.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;Save Changes&lt;/STRONG&gt;:&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Ensure you save the file after adding the IP addresses.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Exemption from Enforcement&lt;/STRONG&gt;: IP addresses listed in the&amp;nbsp;&lt;STRONG&gt;$FWDIR/conf/ip_whitelist.eng&lt;/STRONG&gt;&amp;nbsp;file will not be subject to enforcement actions even if they appear in any of the threat intelligence feeds.&lt;/P&gt;&lt;P&gt;…&lt;/P&gt;&lt;P&gt;“&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Question:&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Is this file located on the Management Server or GW ?&lt;UL&gt;&lt;LI&gt;If on the Management Server, how do we update it on MaaS ?&amp;nbsp; The same way as we do with &lt;SPAN&gt;$FWDIR/lib/table.def&amp;nbsp;&lt;/SPAN&gt;?&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;What is the syntax ?&amp;nbsp; One IP per line or IP/mask to allow a network ?&lt;/LI&gt;&lt;LI&gt;Can it be Dynamically updated from a Datacenter object from AWS / Azure / GCP ... ?&lt;/LI&gt;&lt;LI&gt;How often it is read ?&amp;nbsp; On a policy push operation ?&amp;nbsp; I mean, if we include and/or exclude something, when it will start to be enforced with the recent changes ?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Besides that, IMHO information about "IP Allow list" could be included on the Admin Guide, like here (or close) for instance:&amp;nbsp;&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ThreatPrevention_AdminGuide/Content/Topics-TPG/Uploading-Threat-Indicator-Files-through-SmartConsole_Custom.htm?tocpath=Custom%20Threat%20Prevention%7CConfiguring%20Advanced%20Threat%20Prevention%20Settings%7CConfiguring%20Threat%20Indicators%7C_____2" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ThreatPrevention_AdminGuide/Content/Topics-TPG/Uploading-Threat-Indicator-Files-through-SmartConsole_Custom.htm?tocpath=Custom%20Threat%20Prevention%7CConfiguring%20Advanced%20Threat%20Prevention%20Settings%7CConfiguring%20Threat%20Indicators%7C_____2&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H3&gt;&lt;span class="lia-unicode-emoji" title=":vulcan_salute:"&gt;🖖&lt;/span&gt;&lt;/H3&gt;&lt;P&gt;Best regards,&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Jul 2024 15:57:26 GMT</pubDate>
    <dc:creator>rrbranco</dc:creator>
    <dc:date>2024-07-04T15:57:26Z</dc:date>
    <item>
      <title>Network feed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/212407#M40317</link>
      <description>&lt;P&gt;Hey boys and girls,&lt;/P&gt;
&lt;P&gt;Happy Friday! Figured would share this, as its super useful, specially for anyone who is not running AV or AB blades on the firewall to block known bad IPs out there. All you do is create new network feed (can only be tested if running R81.20) and then those can be used to block the traffic from those feeds. There are 8 of them and all you do is replace number 1-8 in the link below:&lt;/P&gt;
&lt;P&gt;Github link -&amp;gt;&amp;nbsp;&lt;A href="https://github.com/stamparm/ipsum" target="_blank" rel="noopener"&gt;https://github.com/stamparm/ipsum&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;feed example -&amp;gt;&amp;nbsp;&lt;A href="https://raw.githubusercontent.com/stamparm/ipsum/master/levels/1.txt" target="_blank" rel="noopener"&gt;https://raw.githubusercontent.com/stamparm/ipsum/master/levels/1.txt&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You can create 8 separate network feeds, simply keep replacing numbers sequentially, 1 to 8.&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/75094"&gt;@delToro1&lt;/a&gt;&amp;nbsp;for sharing this in my other IOC post.&lt;/P&gt;
&lt;P&gt;I set it up in my Azure lab and so far, got 140K hits in less than 1 day, that is super impressive even though its Azure, but I got no hosts behind the fw in that lab at all.&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25417iCDD247C4F709EAA4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;Thanks a bunch as well to&amp;nbsp;&lt;SPAN&gt;Miroslav Stampar for creating this.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://github.com/stamparm" target="_blank" rel="noopener"&gt;https://github.com/stamparm&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt" target="_blank" rel="noopener nofollow noreferrer"&gt;https://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;IMPORTANT NOTE:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;PLEASE DONT USE EMERG AND SAMPARM FEED 1 TO BEGIN WITH, since I had few customers having issues with those feeds. Samparm 2-8 are fine, no issues.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Best,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2025 01:59:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/212407#M40317</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-12T01:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: Network feed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/212431#M40323</link>
      <description>&lt;P&gt;Nice one!&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 17:58:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/212431#M40323</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-04-26T17:58:15Z</dc:date>
    </item>
    <item>
      <title>Re: Network feed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/212432#M40324</link>
      <description>&lt;P&gt;Thank you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 17:59:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/212432#M40324</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-26T17:59:07Z</dc:date>
    </item>
    <item>
      <title>Re: Network feed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/212434#M40326</link>
      <description>&lt;P&gt;Btw, just added all 8 feeds to see how many IP addresses were there, showed 234,909 all together, not bad &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 18:26:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/212434#M40326</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-26T18:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: Network feed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/212514#M40358</link>
      <description>&lt;P&gt;So cool!! &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 07:57:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/212514#M40358</guid>
      <dc:creator>delToro1</dc:creator>
      <dc:date>2024-04-29T07:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: Network feed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/212522#M40360</link>
      <description>&lt;P&gt;Absolutely!&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 10:54:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/212522#M40360</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-29T10:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: Network feed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/212700#M40415</link>
      <description>&lt;P&gt;Just to add, I also found below, which probably has millions of bad IP addresses, as it contains LOTS of /16 subnets. I did a search and saw there was 131 entries for /16, so right there thats 8.5 million, plus remaining /21,/22,/23,/17 etc...would not be surprised its close to 15 M all together.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt" target="_blank" rel="noopener"&gt;https://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 11:58:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/212700#M40415</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-30T11:58:01Z</dc:date>
    </item>
    <item>
      <title>Re: Network feed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/212856#M40461</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp; &amp;nbsp; What is the result if the feed in question on your block rule contains no entries at all (i.e. the feed source becomes empty and the previous cached files on the GW is cleared)?&amp;nbsp; &amp;nbsp; Does it result in no matches and therefore nothing will hit it?&amp;nbsp; &amp;nbsp; &amp;nbsp; More fearful of some situation where it starts blocking more than it should be &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2024 16:57:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/212856#M40461</guid>
      <dc:creator>Scottc98</dc:creator>
      <dc:date>2024-05-01T16:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: Network feed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/212858#M40463</link>
      <description>&lt;P&gt;I noticed one in my lab with no entries, but had not seen any such issues as of yet, what you described.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2024 02:06:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/212858#M40463</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-17T02:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: Network feed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/212859#M40464</link>
      <description>&lt;P&gt;One thing I will say though, as a word of caution, though those feeds block BUNCH of bad IPs, but it could happen that something is blocked inadvertently where people may need access to the cloud portal. In my experience, its not often, but there is a chance for it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2024 18:45:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/212859#M40464</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-01T18:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: Network feed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/219726#M42012</link>
      <description>&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk132193" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk132193&lt;/A&gt;&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;IP Allow List (Exception List)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The IP whitelist provides a convenient way to allow certain IP addresses to bypass the enforcement actions, that have been defined by threat intelligence feeds.&lt;/P&gt;&lt;P&gt;This document provides instructions for managing IP addresses within the IP white list, also known as the IP exception list.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;Edit the File&lt;/STRONG&gt;:&lt;/LI&gt;&lt;/OL&gt;&lt;P class="lia-indent-padding-left-60px"&gt;&lt;STRONG&gt;vi $FWDIR/conf/ip_whitelist.eng&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;Append IP Addresses&lt;/STRONG&gt;:&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Add the desired IP addresses, one per line.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;Save Changes&lt;/STRONG&gt;:&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Ensure you save the file after adding the IP addresses.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Exemption from Enforcement&lt;/STRONG&gt;: IP addresses listed in the&amp;nbsp;&lt;STRONG&gt;$FWDIR/conf/ip_whitelist.eng&lt;/STRONG&gt;&amp;nbsp;file will not be subject to enforcement actions even if they appear in any of the threat intelligence feeds.&lt;/P&gt;&lt;P&gt;…&lt;/P&gt;&lt;P&gt;“&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Question:&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Is this file located on the Management Server or GW ?&lt;UL&gt;&lt;LI&gt;If on the Management Server, how do we update it on MaaS ?&amp;nbsp; The same way as we do with &lt;SPAN&gt;$FWDIR/lib/table.def&amp;nbsp;&lt;/SPAN&gt;?&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;What is the syntax ?&amp;nbsp; One IP per line or IP/mask to allow a network ?&lt;/LI&gt;&lt;LI&gt;Can it be Dynamically updated from a Datacenter object from AWS / Azure / GCP ... ?&lt;/LI&gt;&lt;LI&gt;How often it is read ?&amp;nbsp; On a policy push operation ?&amp;nbsp; I mean, if we include and/or exclude something, when it will start to be enforced with the recent changes ?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Besides that, IMHO information about "IP Allow list" could be included on the Admin Guide, like here (or close) for instance:&amp;nbsp;&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ThreatPrevention_AdminGuide/Content/Topics-TPG/Uploading-Threat-Indicator-Files-through-SmartConsole_Custom.htm?tocpath=Custom%20Threat%20Prevention%7CConfiguring%20Advanced%20Threat%20Prevention%20Settings%7CConfiguring%20Threat%20Indicators%7C_____2" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ThreatPrevention_AdminGuide/Content/Topics-TPG/Uploading-Threat-Indicator-Files-through-SmartConsole_Custom.htm?tocpath=Custom%20Threat%20Prevention%7CConfiguring%20Advanced%20Threat%20Prevention%20Settings%7CConfiguring%20Threat%20Indicators%7C_____2&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H3&gt;&lt;span class="lia-unicode-emoji" title=":vulcan_salute:"&gt;🖖&lt;/span&gt;&lt;/H3&gt;&lt;P&gt;Best regards,&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 15:57:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/219726#M42012</guid>
      <dc:creator>rrbranco</dc:creator>
      <dc:date>2024-07-04T15:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: Network feed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/219728#M42013</link>
      <description>&lt;P&gt;The file is 100% on the mgmt server. Does it get auto updated? Im not so sure about that as per sk. Syntax is simply one IP per line, as mask will always be /32 anyway.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 16:02:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/219728#M42013</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-04T16:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: Network feed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/226791#M43590</link>
      <description>&lt;P&gt;Hey Andy,&lt;/P&gt;
&lt;P&gt;Did you create the Network Feed objects as globals or strictly local (Generic DC Obj do that)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2024 13:30:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/226791#M43590</guid>
      <dc:creator>George_Ellis</dc:creator>
      <dc:date>2024-09-16T13:30:03Z</dc:date>
    </item>
    <item>
      <title>Re: Network feed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/242671#M47148</link>
      <description>&lt;P&gt;Hey everyone,&lt;/P&gt;
&lt;P&gt;I know this post is almost year old, but I feel its important to highlight something. I had customer tell me recently they used emerg feed below and it caused issues on their network, so just a word of caution, maybe do NOT use it in the beginning, since it has about 15.5 M IP addresses, so can definitely cause problems. Safe to use other 8.&lt;/P&gt;
&lt;P&gt;To be precise, number of IPs is&amp;nbsp;&lt;SPAN data-olk-copy-source="MessageBody"&gt;15,455,886&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt" target="_blank" rel="noopener"&gt;https://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 14:28:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/242671#M47148</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-28T14:28:05Z</dc:date>
    </item>
    <item>
      <title>Re: Network feed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/242714#M47157</link>
      <description>&lt;P&gt;15 million IPs is a bit beyond what we tested for Network Feeds (2 million).&lt;BR /&gt;Possible that has something to do with it.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 17:13:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/242714#M47157</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-28T17:13:41Z</dc:date>
    </item>
    <item>
      <title>Re: Network feed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/242715#M47158</link>
      <description>&lt;P&gt;I think so too.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 17:15:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/242715#M47158</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-28T17:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: Network feed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/242727#M47170</link>
      <description>&lt;P&gt;Latest update. Below link also contains some great stuff for IOC.&lt;/P&gt;
&lt;P&gt;Nice weekend everyone &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P lang="x-none"&gt;&lt;A href="https://github.com/Bert-JanP/Open-Source-Threat-Intel-Feeds?tab=readme-ov-file" target="_blank"&gt;https://github.com/Bert-JanP/Open-Source-Threat-Intel-Feeds?tab=readme-ov-file&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 22:04:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/242727#M47170</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-28T22:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: Network feed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/243300#M47264</link>
      <description>&lt;P&gt;I got this running in my lab and shot up my CPU to 90% - had to get rid of it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 22:03:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/243300#M47264</guid>
      <dc:creator>DeltaUnit</dc:creator>
      <dc:date>2025-03-07T22:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: Network feed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/243311#M47266</link>
      <description>&lt;P&gt;Just remove emerg one and samparm 1, others are fine.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 23:57:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/243311#M47266</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-07T23:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: Network feed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/243327#M47268</link>
      <description>&lt;P&gt;This is super useful info too, since&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;mentioned 2 million entries is the limit currently, and emerg net feed has more less, about 15 M entries, so definitely way more than officially supported. Not sure why stamparm 1 feed is causing issues for people, since its less than 200K entried, but we had one customer use stamparm 2-8 feeds and in 4-5 days, they had almost 10M hits, so definitely working well. For the context, I had a customer do this while ago, they are smaller hospital, and they told me in a week, there was almost 100M hits, compated to few thousands with manual IPs they were adding before doing net feeds.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 08 Mar 2025 18:07:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-feed/m-p/243327#M47268</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-08T18:07:16Z</dc:date>
    </item>
  </channel>
</rss>

