<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blocking IP using custom IOC feeds in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/74640#M57462</link>
    <description>Is the feed source using self-signed certificate? We're having the same exact issue. The feed is retrieved without problems when added, but fails on the next scheduled IOC pull with memory allocation error.&lt;BR /&gt;&lt;BR /&gt;We've had a SR opened until november, did some debugs and now waiting for CP to investigate the issue. I'll update this thread if we come to the solution.</description>
    <pubDate>Mon, 10 Feb 2020 09:30:08 GMT</pubDate>
    <dc:creator>Borut</dc:creator>
    <dc:date>2020-02-10T09:30:08Z</dc:date>
    <item>
      <title>Blocking IP using custom IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/60604#M57448</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I am trying to automatically Block IPs from IOC feeds coming from ServiceNow-Secops. I can see, check point is able to fetch IOCs from Secops however, it is not blocking those IPs.&lt;/P&gt;&lt;P&gt;I am using R80.30 (gateway and management are behind proxy and it is standalone). I check&amp;nbsp;&lt;SPAN&gt;sk103154 and it asks me to install script "&lt;EM&gt;ip_block_sk103154.tar" . Unfortunately, with my access i am unable to download this script.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;EM&gt;Please let me know, if there is any work-around for this issue.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 09:25:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/60604#M57448</guid>
      <dc:creator>Kumar_Sambhav</dc:creator>
      <dc:date>2019-08-19T09:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IP using custom IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/60656#M57449</link>
      <description>What steps did you follow to achieve this?&lt;BR /&gt;I'll check on the script to see if we can fix the access permissions.</description>
      <pubDate>Mon, 19 Aug 2019 18:23:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/60656#M57449</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-08-19T18:23:46Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IP using custom IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/60698#M57450</link>
      <description>&lt;P&gt;Thank you PhoneBoy for replying.&lt;/P&gt;&lt;P&gt;I followed :&amp;nbsp;&lt;SPAN&gt;sk132193.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Below steps we did for configuration:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To add external feed: ioc_feeds add --feed_name blocklist --transport https --resource &lt;A href="https://xxx.com" target="_blank"&gt;https://xxx.com&lt;/A&gt; --user_name admin_account&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;EM&gt;ioc_feeds show : Gives message that feed is active&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;EM&gt;file :&amp;nbsp;&lt;STRONG&gt;$FWDIR/external_ioc/feed_name_folder/blocklist_https&amp;nbsp; : Shows the IP address fetched from external feed in format:&amp;nbsp;#UNIQ-NAME,VALUE,TYPE,CONFIDENCE,SEVERITY,PRODUCT,COMMENT&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;While checking sk103154, it says it is known issue with firewalls behind&amp;nbsp; proxy.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;PS: Firewall is standalone and behind proxy. Fw version is :&amp;nbsp; R80.30 - Build 484&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2019 07:51:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/60698#M57450</guid>
      <dc:creator>Kumar_Sambhav</dc:creator>
      <dc:date>2019-08-20T07:51:51Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IP using custom IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/60912#M57451</link>
      <description>The permission issue with the file in sk103154 should be fixed now.&lt;BR /&gt;ioc_feeds should support use with a proxy, see: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk132193" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk132193&lt;/A&gt;</description>
      <pubDate>Thu, 22 Aug 2019 05:01:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/60912#M57451</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-08-22T05:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IP using custom IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/60941#M57452</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was able to run script as per sk103154. However, still IP is not getting blocked.&lt;/P&gt;&lt;P&gt;I am trying to block a Private IP (as it is Lab environment). I am still able to ping, ssh firewall from that pvt. IP. Any insight?&lt;/P&gt;&lt;P&gt;PS: There is no error logs in :&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;$FWDIR/log/ioc_feeder.elg&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;$FWDIR/log/ext_ioc_push.elg&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2019 10:46:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/60941#M57452</guid>
      <dc:creator>Kumar_Sambhav</dc:creator>
      <dc:date>2019-08-22T10:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IP using custom IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/60956#M57453</link>
      <description>&lt;P&gt;Small Update:&lt;/P&gt;&lt;P&gt;I tried Blocking it from Smart Console also, by uploading the .csv file as Indicators and still IP is not getting blocked.&lt;/P&gt;&lt;P&gt;Is there any limitation like Private IP cannot be blocked (though it is coming from External interface)? I have created a rule on firewall to allow SSH, Ping and 443 from the Same IP (which i am looking to block through Anti-Bot blade)&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2019 13:27:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/60956#M57453</guid>
      <dc:creator>Kumar_Sambhav</dc:creator>
      <dc:date>2019-08-22T13:27:41Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IP using custom IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/60975#M57454</link>
      <description>The mechanism that ioc_feeds uses is Anti-Bot and Anti-Virus.&lt;BR /&gt;This works for blocking outbound traffic to the specified IPs from internal networks.&lt;BR /&gt;It won't block traffic coming FROM those IPs, however.&lt;BR /&gt;For that, you can use the scripts in sk103154.</description>
      <pubDate>Thu, 22 Aug 2019 17:52:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/60975#M57454</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-08-22T17:52:12Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IP using custom IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/65867#M57455</link>
      <description>&lt;P&gt;Hi Phoneboy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for that info, because I had no idea IOC only worked for outbound traffic. Now I just tested it I realise you are right.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As we have IOC setup with both a IP and domain list, is there a way to use&amp;nbsp;sk103154 with domains aswell? I would prefer not to have two separate systems for IP and domain, I want to block incoming and outgoing traffic to my IP list, and all outgoing traffic to my domain list. (R80.20)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2019 05:45:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/65867#M57455</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2019-10-25T05:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IP using custom IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/65935#M57456</link>
      <description>No, the scripts in sk103154 only work at the IP level.&lt;BR /&gt;With domains, we can really only block if we see the initial DNS query from the client and rewrite it with a non-malicious IP.&lt;BR /&gt;That is a function Antibot/Antivirus can provide.</description>
      <pubDate>Fri, 25 Oct 2019 16:41:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/65935#M57456</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-10-25T16:41:05Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IP using custom IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/65953#M57457</link>
      <description>&lt;P&gt;okay thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The domain blocking function of IOC waas working well for us but now its stopped blocking the domains and IPs with this error in $FWDIR/log/ioc_feeder.elg:&lt;/P&gt;&lt;P&gt;Feed status ip_list :: engine memory allocation error&lt;BR /&gt;Feed status domain_list :: engine memory allocation error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interesting I see the same error on two different clusters that use the same list, I cleared the list out to a single entry in each txt file and still same issue, however if I run "ioc_feeds push" it works successfully and that single entry starts blocking.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also they should really make that clear on&amp;nbsp;&lt;SPAN&gt;sk132193 thats its only outgoing traffic!&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2019 21:45:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/65953#M57457</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2019-10-25T21:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IP using custom IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/65957#M57458</link>
      <description>Recommend opening a TAC case on the memory errors you're seeing.</description>
      <pubDate>Fri, 25 Oct 2019 23:09:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/65957#M57458</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-10-25T23:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IP using custom IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/72487#M57459</link>
      <description>&lt;P&gt;Ryan, I'm working on IOCs nowadays as well and I am experiencing the&amp;nbsp;engine memory allocation error that you had in the past. Wondering if you discovered a fix for it?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am opening a TAC case tomorrow to tackle this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2020 04:10:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/72487#M57459</guid>
      <dc:creator>Tim_McColgan</dc:creator>
      <dc:date>2020-01-17T04:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IP using custom IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/72489#M57460</link>
      <description>&lt;P&gt;Hi, I think this should fix the memory allocation error:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fw ctl set int g_ci_av_sft_classification_buffer_size 16000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2020 04:26:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/72489#M57460</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2020-01-17T04:26:23Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IP using custom IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/72557#M57461</link>
      <description>&lt;P&gt;Thanks Ryan, I checked and we are already at 16000 as this looks to be the default for R80.30. Opening a TAC now.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2020 15:23:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/72557#M57461</guid>
      <dc:creator>Tim_McColgan</dc:creator>
      <dc:date>2020-01-17T15:23:42Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IP using custom IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/74640#M57462</link>
      <description>Is the feed source using self-signed certificate? We're having the same exact issue. The feed is retrieved without problems when added, but fails on the next scheduled IOC pull with memory allocation error.&lt;BR /&gt;&lt;BR /&gt;We've had a SR opened until november, did some debugs and now waiting for CP to investigate the issue. I'll update this thread if we come to the solution.</description>
      <pubDate>Mon, 10 Feb 2020 09:30:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/74640#M57462</guid>
      <dc:creator>Borut</dc:creator>
      <dc:date>2020-02-10T09:30:08Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IP using custom IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/77438#M57463</link>
      <description>&lt;P&gt;As promised. Support figured out what the problem was.&lt;/P&gt;&lt;P&gt;The feed resides on an internal server with a certificate from our internal CA, which is not trusted by default. They added all the certificates in the certificate path to ca_bundle.pem. After that it started working without errors.&lt;/P&gt;&lt;P&gt;You can see if you have cert errors by running&amp;nbsp;$FWDIR/bin/ioc_feeder -d -f and checking&amp;nbsp;$FWDIR/log/ioc_feeder.elg. We had certificate errors like this&amp;nbsp;[ERROR] curl_easy_perform() failed: Peer certificate cannot be authenticated with given CA certificates.&lt;/P&gt;&lt;P&gt;We also tried adding the certificates via https policy to Trusted CA's but found out, that the policy install does not add them to ca_bundle.pem. R&amp;amp;D is still investigationg that.&lt;/P&gt;&lt;P&gt;I can go into more detail on how to add the certificates if anyone needs.&lt;/P&gt;&lt;P&gt;I would expect that the process of adding the server public keys to the bundle would be automatic. Maybe in future versions &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 11:39:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/77438#M57463</guid>
      <dc:creator>Borut</dc:creator>
      <dc:date>2020-03-06T11:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IP using custom IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/77476#M57464</link>
      <description>The certificate store used for HTTPS Inspection and the ioc_feeds CLI could also be different &lt;span class="lia-unicode-emoji" title=":thinking_face:"&gt;🤔&lt;/span&gt;</description>
      <pubDate>Fri, 06 Mar 2020 15:51:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/77476#M57464</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-06T15:51:13Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IP using custom IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/77601#M57465</link>
      <description>It actually is a different certificate store</description>
      <pubDate>Sun, 08 Mar 2020 09:30:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/77601#M57465</guid>
      <dc:creator>TP_Master</dc:creator>
      <dc:date>2020-03-08T09:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IP using custom IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/81631#M57466</link>
      <description>&lt;P&gt;Same thing happened in my lab:&lt;/P&gt;&lt;P&gt;[17736 4126325536]@cpfw[12 Apr 12:09:48] #############################################&lt;BR /&gt;[17736 4126325536]@cpfw[12 Apr 12:09:48] Feed status blacklist-ssl :: engine memory allocation error&lt;BR /&gt;[17736 4126325536]@cpfw[12 Apr 12:09:48] #############################################&lt;BR /&gt;[17736 4126325536]@cpfw[12 Apr 12:09:48] Feed log External IOC - External Indicators processing failed&lt;BR /&gt;blacklist-ssl: Failed to fetch feed. Resource: &lt;A href="https://x.x.x.x/black_list/ip.txt" target="_blank"&gt;https://x.x.x.x/black_list/ip.txt&lt;/A&gt;, Reason: Peer certificate cannot be authenticated with given CA certificates&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But http works well.&lt;/P&gt;</description>
      <pubDate>Sun, 12 Apr 2020 04:13:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/81631#M57466</guid>
      <dc:creator>Neville_Kuo</dc:creator>
      <dc:date>2020-04-12T04:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking IP using custom IOC feeds</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/81677#M57467</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;For those are using Custom Intelligence Feeds function with self-signed https server, you should use the following command:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;export EXT_IOC_NO_SSL_VALIDATION=1&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Then start your https ioc feeds, I just fixed this problem, according to sk132193:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Feed's resource can be:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;URL - HTTP/HTTPS (&lt;EM&gt;--transport http --resource "&lt;A href="http://10.0.0.1/my_feeds/stix_feed.xml" target="_blank" rel="noopener"&gt;http://10.0.0.1/my_feeds/stix_feed.xml&lt;/A&gt;"&lt;/EM&gt;)&lt;BR /&gt;*Self-signed certificate HTTPS resource will propmt for user agreement to update the bundle. It is possible to skip the certificate verification by running "export EXT_IOC_NO_SSL_VALIDATION=1" on the gateway.&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 13 Apr 2020 13:00:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-IP-using-custom-IOC-feeds/m-p/81677#M57467</guid>
      <dc:creator>Neville_Kuo</dc:creator>
      <dc:date>2020-04-13T13:00:48Z</dc:date>
    </item>
  </channel>
</rss>

