<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom IOC Feeds CIDR/IP Ranges logging issues in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Custom-IOC-Feeds-CIDR-IP-Ranges-logging-issues/m-p/251289#M53745</link>
    <description>&lt;P&gt;Keep us posted.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Sun, 15 Jun 2025 22:20:57 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-06-15T22:20:57Z</dc:date>
    <item>
      <title>Custom IOC Feeds CIDR/IP Ranges logging issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Custom-IOC-Feeds-CIDR-IP-Ranges-logging-issues/m-p/250996#M53739</link>
      <description>&lt;P&gt;Hi, I'm trying to add a custom IOC feed using CIDR or IP Ranges and have been able to get them to block traffic successfully, however the logging seems to be a bit more tricky&lt;/P&gt;&lt;P&gt;This is on R81.20 Take 103 and the same issue is also seen if adding the IOC feed from the GUI&lt;/P&gt;&lt;P&gt;if I add a feed via ioc_feeds add&amp;nbsp;--feed_name Test_Block_CDIR --format [value:#1,type:IP Range] --transport https --resource "&lt;A href="https://url.example.com/test_block_range.txt" target="_blank"&gt;https://url.example.com/test_block_range.txt&lt;/A&gt;" --comment [#] --delimiter ","&lt;/P&gt;&lt;P&gt;Where the test_block_range.txt looks like&lt;/P&gt;&lt;P&gt;10.1.1.0-10.1.1.255&lt;/P&gt;&lt;P&gt;10.2.2.0-10.2.2.255&lt;/P&gt;&lt;P&gt;It blocks the ranges successfully however in the logs it only shows the full details of the IOC feed doing the blocking for 10.1.1.0 or 10.2.2.0 addresses&lt;/P&gt;&lt;P&gt;For any other addresses in the ranges, it only reports the Protection Type being "IP Reputation" with no Protection Name, Indicator Name, Observable Name, which makes it hard to search on when there are multiple IOC feeds&lt;/P&gt;&lt;P&gt;Although CIDR is explicitly mentioned in&amp;nbsp;&lt;SPAN&gt;sk132193 it seems to block just fine using the IP type but again only logs the first IP of each subnet defined&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I can make it work using individual IP addresses, but this seems a bit over the top when looking at several thousand IP's&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Does anyone have experience with IOC feeds and logging who can point me in the right direction please&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Hamish Fleming&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 00:30:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Custom-IOC-Feeds-CIDR-IP-Ranges-logging-issues/m-p/250996#M53739</guid>
      <dc:creator>flemingh</dc:creator>
      <dc:date>2025-06-11T00:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: Custom IOC Feeds CIDR/IP Ranges logging issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Custom-IOC-Feeds-CIDR-IP-Ranges-logging-issues/m-p/250997#M53740</link>
      <description>&lt;P&gt;I will test this in R81.20 and R82 labs tomorrow, since I have IOCs in both.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 00:50:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Custom-IOC-Feeds-CIDR-IP-Ranges-logging-issues/m-p/250997#M53740</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-11T00:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: Custom IOC Feeds CIDR/IP Ranges logging issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Custom-IOC-Feeds-CIDR-IP-Ranges-logging-issues/m-p/251115#M53741</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/35400"&gt;@flemingh&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry for the delay, was busy with studying and then writting CCTE exam, totally forgot about updating you, apologies.&lt;/P&gt;
&lt;P&gt;I tested this in R82 jumbo 19. more less, was exact same issue.&lt;/P&gt;
&lt;P&gt;Not sure if its expected or not...maube someone from CP can comment.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2025 02:23:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Custom-IOC-Feeds-CIDR-IP-Ranges-logging-issues/m-p/251115#M53741</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-12T02:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: Custom IOC Feeds CIDR/IP Ranges logging issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Custom-IOC-Feeds-CIDR-IP-Ranges-logging-issues/m-p/251150#M53742</link>
      <description>&lt;P&gt;Just to clarify, the issue isn't that the traffic is not being blocked, it's that it's not being logged correctly, right?&lt;BR /&gt;And by correct, meaning "not as IP Reputation"&lt;/P&gt;
&lt;P&gt;A TAC case is probably needed here.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2025 12:31:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Custom-IOC-Feeds-CIDR-IP-Ranges-logging-issues/m-p/251150#M53742</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-06-12T12:31:26Z</dc:date>
    </item>
    <item>
      <title>Re: Custom IOC Feeds CIDR/IP Ranges logging issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Custom-IOC-Feeds-CIDR-IP-Ranges-logging-issues/m-p/251287#M53743</link>
      <description>&lt;P&gt;Yes the traffic is blocked as it is defined in the IOC feed but when you look through the logs it doesn't have the reason/IOC feed that blocks the traffic except for the first entry of the subnet/range listed&lt;/P&gt;&lt;P&gt;If I have 10.1.1.0/24 defined it doesn't block 10.1.1.0 but it blocks 10.1.1.1 and shows the correct log info, however10.1.1.2 - 10.1.1.254 it blocks but just has "IP Reputation" in the logs&lt;BR /&gt;Equally if I define 10.1.1.0-10.1.1.255 then 10.1.1.0 blocks and shows in the logs with the correct IOC info but 10.1.1.1 - 10.1.1.255 only block and only have "IP Reputation" in the logs&lt;/P&gt;&lt;P&gt;CIDR isn't specified in the doco that I could find but seems to work other than for the network address and the broadcast address but I also get the same logging issue with the IP Range definition (inclusive of the network and broadcast addresses not that a range is defining these per se) which is supported in the doco&lt;/P&gt;&lt;P&gt;I can define the 139K IP addresses individually that I want to block and this works correctly with the full logging info but I wanted to check I wasn't missing something as defining a dozen or so ranges is less overhead that maintaining a 139K entry file&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Jun 2025 22:10:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Custom-IOC-Feeds-CIDR-IP-Ranges-logging-issues/m-p/251287#M53743</guid>
      <dc:creator>flemingh</dc:creator>
      <dc:date>2025-06-15T22:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: Custom IOC Feeds CIDR/IP Ranges logging issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Custom-IOC-Feeds-CIDR-IP-Ranges-logging-issues/m-p/251288#M53744</link>
      <description>&lt;P&gt;Thanks for verifying, I appreciate you taking the time&lt;/P&gt;&lt;P&gt;I'll open a TAC case, not that it's a major issue that doesn't have a workaround but it's always nice to get things like this tidied up if possible... or be informed that it's a feature not a bug &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Jun 2025 22:17:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Custom-IOC-Feeds-CIDR-IP-Ranges-logging-issues/m-p/251288#M53744</guid>
      <dc:creator>flemingh</dc:creator>
      <dc:date>2025-06-15T22:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: Custom IOC Feeds CIDR/IP Ranges logging issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Custom-IOC-Feeds-CIDR-IP-Ranges-logging-issues/m-p/251289#M53745</link>
      <description>&lt;P&gt;Keep us posted.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 15 Jun 2025 22:20:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Custom-IOC-Feeds-CIDR-IP-Ranges-logging-issues/m-p/251289#M53745</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-15T22:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: Custom IOC Feeds CIDR/IP Ranges logging issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Custom-IOC-Feeds-CIDR-IP-Ranges-logging-issues/m-p/251355#M53746</link>
      <description>&lt;P&gt;I thought CIDRs were explicitly documented as supported?&lt;BR /&gt;In any case, the logging issue is probably independent of this.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2025 14:59:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Custom-IOC-Feeds-CIDR-IP-Ranges-logging-issues/m-p/251355#M53746</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-06-16T14:59:06Z</dc:date>
    </item>
  </channel>
</rss>

