<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Automated IP Blocking in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247392#M48320</link>
    <description>&lt;P&gt;And is it possible that even using this method, if it is necessary to add some IPs that report as “Malicious” to our monitoring area, we can somehow add them to the referral “sources”?&lt;/P&gt;
&lt;P&gt;For example, you get 3 super strange “Malicious” IPs reported to you.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;48.190.1.5&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;35.120.2.2&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;191.2.2.4&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;(&lt;STRONG&gt;Just to give you an example&lt;/STRONG&gt;), and you are already using the Network Feeds.&lt;BR /&gt;Can these IPs be “tied” to this “Network Feeds” operation? Or would you have to manually create explicit rules to block these particular IPs?&lt;/P&gt;</description>
    <pubDate>Sat, 26 Apr 2025 00:22:21 GMT</pubDate>
    <dc:creator>Matlu</dc:creator>
    <dc:date>2025-04-26T00:22:21Z</dc:date>
    <item>
      <title>Automated IP Blocking</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247386#M48315</link>
      <description>&lt;P&gt;Hello, Mates.&lt;/P&gt;
&lt;P&gt;I have an environment of several VSX Clusters, which are managed from an MDS.&lt;/P&gt;
&lt;P&gt;We currently have many Perimeter FWs, and when we have certain IPs reported as “Malicious”, we have the need to block them in explicit rules that we already have created in each of the FWs.&lt;BR /&gt;The problem with doing it manually, is that this task “takes a lot of time”, and we want to use some automated way to be able to execute this task.&lt;/P&gt;
&lt;P&gt;Is there any way in the Check Point solutions, that allows us to have a more “automated” environment for this type of tasks?&lt;/P&gt;
&lt;P&gt;Thanks for your comments.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2025 23:32:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247386#M48315</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-04-25T23:32:20Z</dc:date>
    </item>
    <item>
      <title>Re: Automated IP Blocking</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247387#M48316</link>
      <description>&lt;P&gt;Ola bro,&lt;/P&gt;
&lt;P&gt;How are you? Have a look at my post from last year, hope it can help you. Network feeds do NOT require av or ab blades enabled. I would say to begin with, do NOT use stamparm1 and emerg feeds, others are fine, stamparm 2-8.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Network-feed/m-p/212407#M40317" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Security-Gateways/Network-feed/m-p/212407#M40317&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2025 23:51:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247387#M48316</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-25T23:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: Automated IP Blocking</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247388#M48317</link>
      <description>&lt;P&gt;Hello, my friend.&lt;/P&gt;
&lt;P&gt;Some of my Perimeter FWs do have the AV and AB blades enabled, &lt;STRONG&gt;but others do NOT&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;Would this way of working with the “Network Feed” work as well in the FWs that have these blades enabled?&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Apr 2025 00:02:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247388#M48317</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-04-26T00:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: Automated IP Blocking</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247390#M48318</link>
      <description>&lt;P&gt;Yes sir, 100%. Regardless whether you have those blades enabled or not, network feeds work fine. I would make sure you have R81.20 installed, as it lets you test the feeds beforehand. Just for the context, I work often with a smaller hospital (I mean, for comparison, its not the size of Ankara city hospital in Turkey, nothing like that lol), but they were doing the same method for a long time like what you described, adding IPs manually.&lt;/P&gt;
&lt;P&gt;I showed them the same post, they added ALL the feeds, in 3 days, they had more than 10 million hits, while before implementing net feeds, there was about 25k hits in 1 year.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 26 Apr 2025 00:09:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247390#M48318</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-26T00:09:18Z</dc:date>
    </item>
    <item>
      <title>Re: Automated IP Blocking</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247391#M48319</link>
      <description>&lt;P&gt;reference&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Network_Feed.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Network_Feed.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 26 Apr 2025 00:18:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247391#M48319</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-26T00:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: Automated IP Blocking</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247392#M48320</link>
      <description>&lt;P&gt;And is it possible that even using this method, if it is necessary to add some IPs that report as “Malicious” to our monitoring area, we can somehow add them to the referral “sources”?&lt;/P&gt;
&lt;P&gt;For example, you get 3 super strange “Malicious” IPs reported to you.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;48.190.1.5&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;35.120.2.2&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;191.2.2.4&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;(&lt;STRONG&gt;Just to give you an example&lt;/STRONG&gt;), and you are already using the Network Feeds.&lt;BR /&gt;Can these IPs be “tied” to this “Network Feeds” operation? Or would you have to manually create explicit rules to block these particular IPs?&lt;/P&gt;</description>
      <pubDate>Sat, 26 Apr 2025 00:22:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247392#M48320</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-04-26T00:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: Automated IP Blocking</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247393#M48321</link>
      <description>&lt;P&gt;Thats right...though, you can search for any given IP when opening the links I posted, same way you can do ctrl+F to search for anything in text file of web page. Keep in mind, any net feed is updated automatically, so you dont have to do anything yourself.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 26 Apr 2025 00:25:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247393#M48321</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-26T00:25:30Z</dc:date>
    </item>
    <item>
      <title>Re: Automated IP Blocking</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247394#M48322</link>
      <description>&lt;P&gt;Btw, even if you have any gateways on R80.xx, those can also do net feeds, but I definitely suggest they be on R81.20, if possible, to utilize all the available options.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 26 Apr 2025 00:46:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247394#M48322</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-26T00:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: Automated IP Blocking</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247427#M48325</link>
      <description>&lt;P&gt;Btw, figured would update you on this post as well...tested R82 vsx for network feeds, no issues.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 26 Apr 2025 19:05:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247427#M48325</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-26T19:05:03Z</dc:date>
    </item>
    <item>
      <title>Re: Automated IP Blocking</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247442#M48327</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/82839"&gt;@Matlu&lt;/a&gt;&amp;nbsp;If you need me to test anything else in the lab, please let me know.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 27 Apr 2025 13:56:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247442#M48327</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-27T13:56:18Z</dc:date>
    </item>
    <item>
      <title>Re: Automated IP Blocking</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247475#M48337</link>
      <description>&lt;P&gt;Just a word of caution though...maybe dont add all of net feeds I provided at once, start with 2 or 3 and then give it couple of days and see how many hits you get, just to make sure there are not inadvertent effects.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 01:42:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247475#M48337</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-28T01:42:52Z</dc:date>
    </item>
    <item>
      <title>Re: Automated IP Blocking</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247479#M48338</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1000071876.jpg" style="width: 719px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30337i30AEF85F2B5A42CC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="1000071876.jpg" alt="1000071876.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;From the list of .txt file options, which option do you recommend to use in my ‘Network Feeds’?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 03:12:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247479#M48338</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-04-28T03:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: Automated IP Blocking</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247482#M48341</link>
      <description>&lt;P&gt;Hey bro,&lt;/P&gt;
&lt;P&gt;Here is the thing. My best suggestion is if you are unsure, always test any IP you are concerned about in below link, its very accurate. We always use it to check those things. Besides, only way to really know is to apply the feed, block it in policy, and then observe and see.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.abuseipdb.com/" target="_blank"&gt;https://www.abuseipdb.com/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 03:23:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247482#M48341</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-28T03:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: Automated IP Blocking</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247565#M48357</link>
      <description>&lt;P&gt;Another helpful link I found.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/Bert-JanP/Open-Source-Threat-Intel-Feeds?tab=readme-ov-file" target="_blank"&gt;https://github.com/Bert-JanP/Open-Source-Threat-Intel-Feeds?tab=readme-ov-file&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 00:54:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Automated-IP-Blocking/m-p/247565#M48357</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-29T00:54:25Z</dc:date>
    </item>
  </channel>
</rss>

