<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does 61000 support custom Threat indicators in any version in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-61000-support-custom-Threat-indicators-in-any-version/m-p/3886#M59413</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;SNORT rules would be tricky and not optimal for such requirement.&lt;/P&gt;&lt;P&gt;Meanwhile you can use fast packet drop feature - note that the configuration is on the gateway and not on the management.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check Fast Packet Drop feature in 61k Admin Guide&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="http://dl3.checkpoint.com/paid/71/71ae92768b018816ab82d91d3b361345/CP_R76SP.30_Security_System_AdministrationGuide.pdf?HashKey=1499113431_bb90c391e1e45ddd1ac3c4c590fcabee&amp;amp;xtn=.pdf" title="http://dl3.checkpoint.com/paid/71/71ae92768b018816ab82d91d3b361345/CP_R76SP.30_Security_System_AdministrationGuide.pdf?HashKey=1499113431_bb90c391e1e45ddd1ac3c4c590fcabee&amp;amp;xtn=.pdf"&gt;http://dl3.checkpoint.com/paid/71/71ae92768b018816ab82d91d3b361345/CP_R76SP.30_Security_System_AdministrationGuide.pdf?H…&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In any case, please engage your Check Point SE.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 03 Jul 2017 18:27:08 GMT</pubDate>
    <dc:creator>Gera_Dorfman</dc:creator>
    <dc:date>2017-07-03T18:27:08Z</dc:date>
    <item>
      <title>Does 61000 support custom Threat indicators in any version</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-61000-support-custom-Threat-indicators-in-any-version/m-p/3880#M59407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Threat Prevention has a option to add custom indicators from R77.20 and above. However, 61000 versions are R76SP.X. Does 61000 support the deployment of custom indicators in any version. We are running 61000 in R76SP.40 in VSX mode.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 02 Jul 2017 05:28:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-61000-support-custom-Threat-indicators-in-any-version/m-p/3880#M59407</guid>
      <dc:creator>Varun_Arora</dc:creator>
      <dc:date>2017-07-02T05:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: Does 61000 support custom Threat indicators in any version</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-61000-support-custom-Threat-indicators-in-any-version/m-p/3881#M59408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The next major release for the Scalable Platforms is expected to be based on R80 and thus should support this functionality.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Meanwhile, I would engage with your Check Point SE to discuss your specific requirements to see what can be done in the meantime.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jul 2017 05:09:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-61000-support-custom-Threat-indicators-in-any-version/m-p/3881#M59408</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-07-03T05:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: Does 61000 support custom Threat indicators in any version</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-61000-support-custom-Threat-indicators-in-any-version/m-p/3882#M59409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class=""&gt;&lt;A _jive_internal="true" class="jive-link-profile-small jive_macro jive_macro_user" href="https://community.checkpoint.com/people/gerad5da845f9-9584-48cf-9a5f-e26b6b227890"&gt;Gera Dorfman&amp;nbsp;&lt;/A&gt;, can't it be done maybe with a custom sig (snort ?) ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jul 2017 05:11:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-61000-support-custom-Threat-indicators-in-any-version/m-p/3882#M59409</guid>
      <dc:creator>Moti</dc:creator>
      <dc:date>2017-07-03T05:11:51Z</dc:date>
    </item>
    <item>
      <title>Re: Does 61000 support custom Threat indicators in any version</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-61000-support-custom-Threat-indicators-in-any-version/m-p/3883#M59410</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As Dameon mentioned, we plan to align features set of Scalable Platform with R80.X.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding the specific requirement, we need to understand which exact indicators are planned and see if meanwhile it can be achieved with SNORT.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jul 2017 08:29:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-61000-support-custom-Threat-indicators-in-any-version/m-p/3883#M59410</guid>
      <dc:creator>Gera_Dorfman</dc:creator>
      <dc:date>2017-07-03T08:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: Does 61000 support custom Threat indicators in any version</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-61000-support-custom-Threat-indicators-in-any-version/m-p/3884#M59411</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gera, we are looking for simple IOC blocking with Md5 or IP Address for the prevention using Threat Indicators. Sample is shown below:&lt;/P&gt;&lt;TABLE style="border-collapse: collapse; width: 338pt;" width="451"&gt;&lt;TBODY&gt;&lt;TR style="height: 15.0pt;"&gt;&lt;TD height="20" style="width: 98pt; height: 15.0pt;" width="131"&gt;#UNIQ-NAME&lt;/TD&gt;&lt;TD style="width: 48pt;" width="64"&gt;VALUE&lt;/TD&gt;&lt;TD style="width: 48pt;" width="64"&gt;TYPE&lt;/TD&gt;&lt;TD style="width: 48pt;" width="64"&gt;CONFIDENCE&lt;/TD&gt;&lt;TD style="width: 48pt;" width="64"&gt;SEVERITY&lt;/TD&gt;&lt;TD style="width: 48pt;" width="64"&gt;PRODUCT&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 15.0pt;"&gt;&lt;TD height="20" style="height: 15.0pt;"&gt;HOST107.181.174.34&lt;/TD&gt;&lt;TD&gt;107.181.174.34&lt;/TD&gt;&lt;TD&gt;IP&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;High&lt;/TD&gt;&lt;TD&gt;AB&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 15.0pt;"&gt;&lt;TD height="20" style="height: 15.0pt;"&gt;HOST10.10.10.20&lt;/TD&gt;&lt;TD&gt;10.10.10.20&lt;/TD&gt;&lt;TD&gt;IP&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;High&lt;/TD&gt;&lt;TD&gt;AV&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 15.0pt;"&gt;&lt;TD height="20" style="height: 15.0pt;"&gt;file1&lt;/TD&gt;&lt;TD&gt;23680e480e13981a4d96f7ed72f35c7f&lt;/TD&gt;&lt;TD&gt;MD5&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;Low&lt;/TD&gt;&lt;TD&gt;AV&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jul 2017 09:00:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-61000-support-custom-Threat-indicators-in-any-version/m-p/3884#M59411</guid>
      <dc:creator>Varun_Arora</dc:creator>
      <dc:date>2017-07-03T09:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: Does 61000 support custom Threat indicators in any version</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-61000-support-custom-Threat-indicators-in-any-version/m-p/3885#M59412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You may able to leverage Private ThreatCloud to do the file hashes today, not 100% sure on IPs.&lt;/P&gt;&lt;P&gt;Either way, I recommend engaging your Check Point SE.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jul 2017 17:21:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-61000-support-custom-Threat-indicators-in-any-version/m-p/3885#M59412</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-07-03T17:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: Does 61000 support custom Threat indicators in any version</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-61000-support-custom-Threat-indicators-in-any-version/m-p/3886#M59413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;SNORT rules would be tricky and not optimal for such requirement.&lt;/P&gt;&lt;P&gt;Meanwhile you can use fast packet drop feature - note that the configuration is on the gateway and not on the management.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check Fast Packet Drop feature in 61k Admin Guide&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="http://dl3.checkpoint.com/paid/71/71ae92768b018816ab82d91d3b361345/CP_R76SP.30_Security_System_AdministrationGuide.pdf?HashKey=1499113431_bb90c391e1e45ddd1ac3c4c590fcabee&amp;amp;xtn=.pdf" title="http://dl3.checkpoint.com/paid/71/71ae92768b018816ab82d91d3b361345/CP_R76SP.30_Security_System_AdministrationGuide.pdf?HashKey=1499113431_bb90c391e1e45ddd1ac3c4c590fcabee&amp;amp;xtn=.pdf"&gt;http://dl3.checkpoint.com/paid/71/71ae92768b018816ab82d91d3b361345/CP_R76SP.30_Security_System_AdministrationGuide.pdf?H…&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In any case, please engage your Check Point SE.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jul 2017 18:27:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-61000-support-custom-Threat-indicators-in-any-version/m-p/3886#M59413</guid>
      <dc:creator>Gera_Dorfman</dc:creator>
      <dc:date>2017-07-03T18:27:08Z</dc:date>
    </item>
  </channel>
</rss>

