<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anti-Bot IP Reputation in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/157285#M55257</link>
    <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face="inherit"&gt;We have a lots of "Reputation IPs"&amp;nbsp; for Anti-Bot &lt;/FONT&gt;Protection&lt;FONT face="inherit"&gt;&amp;nbsp;show as below, but never see "IP reputation" type on log.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-09-15_175141.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17787i64E9885FF60EC3AD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2022-09-15_175141.png" alt="2022-09-15_175141.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is it possible to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;generate "IPs&amp;nbsp;reputation logs" without using indicator files/ external IOC feed?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 15 Sep 2022 10:00:08 GMT</pubDate>
    <dc:creator>Jarvis_Lin</dc:creator>
    <dc:date>2022-09-15T10:00:08Z</dc:date>
    <item>
      <title>Anti-Bot IP Reputation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/155143#M55250</link>
      <description>&lt;P&gt;Hi Everybody,&lt;/P&gt;&lt;P&gt;Anti-bot Protection&amp;nbsp;contains IP, URLs, Domain reputation list.&lt;/P&gt;&lt;DIV class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-08-17_224009.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17450iC116AB4F51C849FE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2022-08-17_224009.png" alt="2022-08-17_224009.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;I can generate URLs and DNS reputation logs easily, but cannot generate IPs reputation logs without using indicator files/external IOC feed.&lt;/P&gt;&lt;P&gt;How can I&amp;nbsp;generate IPs&amp;nbsp;reputation logs without using indicator files/ external IOC feed. Is it possible to do ?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 14:53:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/155143#M55250</guid>
      <dc:creator>Jarvis_Lin</dc:creator>
      <dc:date>2022-08-17T14:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-Bot IP Reputation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/155146#M55251</link>
      <description>&lt;P&gt;For background what are you trying to achieve, are you trying to confirm a protection works as expected or do you need the log record as a template?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 14:57:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/155146#M55251</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-08-17T14:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-Bot IP Reputation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/155150#M55252</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;I access "http(s)://131.188.40.189" ,&amp;nbsp; the traffic can be block by Anti-bot (URL Reputation). but ping&amp;nbsp;131.188.40.189 or telnet&amp;nbsp;131.188.40.189 25, the traffic goes through.&lt;/P&gt;&lt;P&gt;Can I&amp;nbsp;generate IPs&amp;nbsp;reputation logs on production? I try several times but not luck.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What kind of tests can trigger IPs reputation logs?&lt;BR /&gt;Is it possible to create IPs reputation&amp;nbsp;log record via Threatwiki page for demo?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 15:31:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/155150#M55252</guid>
      <dc:creator>Jarvis_Lin</dc:creator>
      <dc:date>2022-08-17T15:31:43Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-Bot IP Reputation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/155152#M55253</link>
      <description>&lt;P&gt;HI Chris&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in this example. according to "&lt;A href="https://urlcat.checkpoint.com/urlcat/main.htm&amp;quot;" target="_blank"&gt;https://urlcat.checkpoint.com/urlcat/main.htm"&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;if i enter the ip "&lt;SPAN&gt;131.188.40.189&lt;/SPAN&gt;", it will be shown&amp;nbsp;&lt;SPAN&gt;URL Reputation not&amp;nbsp;IP Reputation.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-08-17_23-24-37.png" style="width: 726px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17451iDE7A7B30C8280A65/image-dimensions/726x316?v=v2" width="726" height="316" role="button" title="2022-08-17_23-24-37.png" alt="2022-08-17_23-24-37.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The&amp;nbsp;&lt;SPAN&gt;Anti-bot Protection&lt;/SPAN&gt;&amp;nbsp;name (R&lt;SPAN&gt;eputation&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;IP/Reputation URLs / Reputation Domain&lt;/SPAN&gt;) confuses me.&lt;/P&gt;&lt;P&gt;As far as I know&lt;/P&gt;&lt;P&gt;1.&amp;nbsp;R&lt;SPAN&gt;eputation&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;IP =&amp;gt; xxx.xxx.xxx.xxx&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;&lt;SPAN&gt;Reputation URLs =&amp;gt; &lt;A href="http://www.bot.com/xxx.exe" target="_blank"&gt;www.bot.com/xxx.exe&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;3.&amp;nbsp;&lt;SPAN&gt;Reputation Domain =&amp;gt; &lt;A href="http://www.bot.com" target="_blank"&gt;www.bot.com&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For this case, if we want to show log of&amp;nbsp;"R&lt;SPAN&gt;eputation&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;IP" in the&amp;nbsp;Logs and Monitoring, would it be possible?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 15:46:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/155152#M55253</guid>
      <dc:creator>ClonyShen</dc:creator>
      <dc:date>2022-08-17T15:46:42Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-Bot IP Reputation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/155204#M55254</link>
      <description>&lt;P&gt;For context:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Reputation IPs.png" style="width: 660px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17459i9C2509DF43962613/image-size/large?v=v2&amp;amp;px=999" role="button" title="Reputation IPs.png" alt="Reputation IPs.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;What confidence level is the profile/blade set to enforce?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Profile.png" style="width: 379px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17460i4F25D23F98F42392/image-size/large?v=v2&amp;amp;px=999" role="button" title="Profile.png" alt="Profile.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Also are the protections correctly reporting up to date in the necessary areas/domain per&amp;nbsp;&lt;SPAN&gt;sk171644.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Jan 2023 23:24:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/155204#M55254</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-01-28T23:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-Bot IP Reputation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/155212#M55255</link>
      <description>&lt;P&gt;My setting as below&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-08-18_212221.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17461i21F2B6E9CCCAEB54/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2022-08-18_212221.png" alt="2022-08-18_212221.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-08-18_212238.png" style="width: 337px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17462i52F1E24310D3CC79/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2022-08-18_212238.png" alt="2022-08-18_212238.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Aug 2022 13:24:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/155212#M55255</guid>
      <dc:creator>Jarvis_Lin</dc:creator>
      <dc:date>2022-08-18T13:24:51Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-Bot IP Reputation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/155240#M55256</link>
      <description>&lt;P&gt;Are you trying to find a known IP that will trigger the Reputation IP protection?&lt;BR /&gt;In any case, the focus of Anti-Bot is DNS, SMTP, and HTTP(S), as noted here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92264" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92264&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Best practice is to limit outbound Internet connectivity to the precise services needed.&lt;BR /&gt;Meanwhile you might try a DNS lookup to the IP (assuming the lookup goes through the gateway) or initiate an SMTP connection to it.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Aug 2022 20:33:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/155240#M55256</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-08-18T20:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-Bot IP Reputation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/157285#M55257</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face="inherit"&gt;We have a lots of "Reputation IPs"&amp;nbsp; for Anti-Bot &lt;/FONT&gt;Protection&lt;FONT face="inherit"&gt;&amp;nbsp;show as below, but never see "IP reputation" type on log.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-09-15_175141.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17787i64E9885FF60EC3AD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2022-09-15_175141.png" alt="2022-09-15_175141.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is it possible to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;generate "IPs&amp;nbsp;reputation logs" without using indicator files/ external IOC feed?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2022 10:00:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/157285#M55257</guid>
      <dc:creator>Jarvis_Lin</dc:creator>
      <dc:date>2022-09-15T10:00:08Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-Bot IP Reputation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/157337#M55258</link>
      <description>&lt;P&gt;Not as far as I know because of how the decision to block is made (IP Reputation being just one factor).&lt;/P&gt;
&lt;P&gt;When you use an external indicator feed and block based purely on that, we can make the clear statement in the logs that it's an "IP Reputation" reason.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2022 15:45:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/157337#M55258</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-09-15T15:45:40Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-Bot IP Reputation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/169497#M55259</link>
      <description>&lt;P&gt;Was this screenshot from demo mode or elsewhere the protections look out of date by 6-months at the time of posting (refer:&amp;nbsp;&lt;SPAN&gt;sk171644)?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Jan 2023 23:26:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/169497#M55259</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-01-28T23:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-Bot IP Reputation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/195618#M55260</link>
      <description>&lt;P&gt;same issue:&lt;/P&gt;&lt;P&gt;&lt;A href="https://youtu.be/djhQncknDH0" target="_blank"&gt;https://youtu.be/djhQncknDH0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 11:31:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/195618#M55260</guid>
      <dc:creator>yanivatia</dc:creator>
      <dc:date>2023-10-19T11:31:52Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-Bot IP Reputation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/195626#M55261</link>
      <description>&lt;P&gt;This thread is about Gateway protections&lt;/P&gt;
&lt;P&gt;Whereas your video is Endpoint or must I keep watching to a particular timestamp?&lt;/P&gt;
&lt;P&gt;If for Endpoint I suggest starting a new thread.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 12:53:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/195626#M55261</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-10-19T12:53:59Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-Bot IP Reputation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/195634#M55262</link>
      <description>&lt;P&gt;you rught mine for endpoint&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 13:20:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-Bot-IP-Reputation/m-p/195634#M55262</guid>
      <dc:creator>yanivatia</dc:creator>
      <dc:date>2023-10-19T13:20:45Z</dc:date>
    </item>
  </channel>
</rss>

