<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Autonomous System Number Updatable Object? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Autonomous-System-Number-Updatable-Object/m-p/245007#M47705</link>
    <description>&lt;P&gt;Ah, very cool; will look into it.&amp;nbsp; I assume this traffic won't be visible in the Smart Console logs and is handled at a lower level?&lt;/P&gt;&lt;P&gt;I don't understand this section in the SK you linked to though.&amp;nbsp; Does this mean I can drop traffic, just not rate limit it?&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;SecureXL Rate Limiting rules for DoS Mitigation do not support these parameters (Known Limitation PMTR-87460):&lt;UL&gt;&lt;LI&gt;cc:&amp;lt;COUNTRY_CODE&amp;gt;&lt;/LI&gt;&lt;LI&gt;asn:&amp;lt;AUTONOMOUS_SYSTEM_NUMBER&amp;gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Thu, 27 Mar 2025 16:13:28 GMT</pubDate>
    <dc:creator>VikingsFan</dc:creator>
    <dc:date>2025-03-27T16:13:28Z</dc:date>
    <item>
      <title>Autonomous System Number Updatable Object?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Autonomous-System-Number-Updatable-Object/m-p/244975#M47691</link>
      <description>&lt;P&gt;Have a need come up where it would be useful to be able to import an AS Number that gets updated automatically.&amp;nbsp; A specific AS number is just sending us garbage constantly and we want to block all 200,000+ IPs from it.&amp;nbsp; Wasn't sure if there was anything that I missed for doing that?&lt;/P&gt;&lt;P&gt;For now, I'm scraping all the subnets from a place like&amp;nbsp;&lt;A href="https://www.ip2location.com/" target="_blank"&gt;https://www.ip2location.com/&lt;/A&gt;&amp;nbsp;and putting them in a network feed flat file.&amp;nbsp; It should work but it's not dynamic.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2025 11:54:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Autonomous-System-Number-Updatable-Object/m-p/244975#M47691</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2025-03-27T11:54:22Z</dc:date>
    </item>
    <item>
      <title>Re: Autonomous System Number Updatable Object?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Autonomous-System-Number-Updatable-Object/m-p/245004#M47703</link>
      <description>&lt;P&gt;You can refer to a specific AS with fwaccel dos and effectively block the traffic:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk112454" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk112454&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;Not sure there is an Updatable Object with this information, unfortunately.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2025 15:36:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Autonomous-System-Number-Updatable-Object/m-p/245004#M47703</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-03-27T15:36:14Z</dc:date>
    </item>
    <item>
      <title>Re: Autonomous System Number Updatable Object?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Autonomous-System-Number-Updatable-Object/m-p/245007#M47705</link>
      <description>&lt;P&gt;Ah, very cool; will look into it.&amp;nbsp; I assume this traffic won't be visible in the Smart Console logs and is handled at a lower level?&lt;/P&gt;&lt;P&gt;I don't understand this section in the SK you linked to though.&amp;nbsp; Does this mean I can drop traffic, just not rate limit it?&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;SecureXL Rate Limiting rules for DoS Mitigation do not support these parameters (Known Limitation PMTR-87460):&lt;UL&gt;&lt;LI&gt;cc:&amp;lt;COUNTRY_CODE&amp;gt;&lt;/LI&gt;&lt;LI&gt;asn:&amp;lt;AUTONOMOUS_SYSTEM_NUMBER&amp;gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 27 Mar 2025 16:13:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Autonomous-System-Number-Updatable-Object/m-p/245007#M47705</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2025-03-27T16:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: Autonomous System Number Updatable Object?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Autonomous-System-Number-Updatable-Object/m-p/245018#M47706</link>
      <description>&lt;P&gt;It's handled in SecureXL and I believe you can also have it generate logs in SmartConsole.&lt;BR /&gt;Believe the limitation only applies to actual rate limiting rules as opposed to drop ones.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2025 17:28:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Autonomous-System-Number-Updatable-Object/m-p/245018#M47706</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-03-27T17:28:43Z</dc:date>
    </item>
  </channel>
</rss>

