<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blocking TOR Exit nodes with scripting in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-TOR-Exit-nodes-with-scripting/m-p/55214#M9934</link>
    <description>&lt;P&gt;Does it require anything else specific, except modification of script?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've configured and can see rules in samp, but it's not enforce, nothing get block from source IP's.&lt;/P&gt;&lt;P&gt;TAC case opened, just in case..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;operation=add uid=&amp;lt;5cf8fc48,000003b0,65c5c30a,000068d2&amp;gt; target=all timeout=458 action=drop log=log comment=threatcloud_TOR_block service=any source=range:199.249.230.78 pkt-rate=0 req_type=quota&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 06 Jun 2019 13:41:08 GMT</pubDate>
    <dc:creator>Martin_Valenta</dc:creator>
    <dc:date>2019-06-06T13:41:08Z</dc:date>
    <item>
      <title>Blocking TOR Exit nodes with scripting</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-TOR-Exit-nodes-with-scripting/m-p/4160#M9932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello guys!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm planning to block all of TOR exit nodes using Checkpoint scripts created for that purpose, see link below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103154" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103154"&gt;How to block traffic coming from known malicious IP addresses&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is this..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will these exit nodes be append to the SAM Rule, or when it updates the SAM Rule will it clean all my SAM Rules already created and in place?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much for your support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Luis Borralho&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jul 2017 11:34:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-TOR-Exit-nodes-with-scripting/m-p/4160#M9932</guid>
      <dc:creator>Luis_Borralho1</dc:creator>
      <dc:date>2017-07-14T11:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking TOR Exit nodes with scripting</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-TOR-Exit-nodes-with-scripting/m-p/4161#M9933</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That SK uses the fw samp mechanism, which is completely different from SAM rules.&lt;/P&gt;&lt;P&gt;Note fw samp is SecureXL friendly and is more efficient than using SAM rules.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jul 2017 15:33:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-TOR-Exit-nodes-with-scripting/m-p/4161#M9933</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-07-14T15:33:28Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking TOR Exit nodes with scripting</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-TOR-Exit-nodes-with-scripting/m-p/55214#M9934</link>
      <description>&lt;P&gt;Does it require anything else specific, except modification of script?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've configured and can see rules in samp, but it's not enforce, nothing get block from source IP's.&lt;/P&gt;&lt;P&gt;TAC case opened, just in case..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;operation=add uid=&amp;lt;5cf8fc48,000003b0,65c5c30a,000068d2&amp;gt; target=all timeout=458 action=drop log=log comment=threatcloud_TOR_block service=any source=range:199.249.230.78 pkt-rate=0 req_type=quota&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 13:41:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-TOR-Exit-nodes-with-scripting/m-p/55214#M9934</guid>
      <dc:creator>Martin_Valenta</dc:creator>
      <dc:date>2019-06-06T13:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking TOR Exit nodes with scripting</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-TOR-Exit-nodes-with-scripting/m-p/72165#M9935</link>
      <description>&lt;P&gt;Curious why this route and not simply blocking the TOR app in policy?&amp;nbsp; Do you not have app control?&amp;nbsp; I looked at the script but it would have to be redone after upgrade/lifecycle.&amp;nbsp; Simply blocking app makes it part of the policy.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2020 20:38:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-TOR-Exit-nodes-with-scripting/m-p/72165#M9935</guid>
      <dc:creator>Timothy_Weid</dc:creator>
      <dc:date>2020-01-13T20:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking TOR Exit nodes with scripting</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-TOR-Exit-nodes-with-scripting/m-p/106588#M9936</link>
      <description>&lt;P&gt;Greetings, &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7423"&gt;@Martin_Valenta&lt;/a&gt;.&lt;/P&gt;&lt;P&gt;I too am having the same problem: I configured the script following step 3 from the link mentioned above, I can see rules in SAMP, but apparently nothing is blocked as I see allowed connections in SmartView Tracker.&lt;/P&gt;&lt;P&gt;We are running R77.30 and do not have Application Control blade enabled (not licensed).&lt;/P&gt;&lt;P&gt;Did you manage to get it working? Is App Control a prerequisite to use the script?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Dec 2020 21:45:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-TOR-Exit-nodes-with-scripting/m-p/106588#M9936</guid>
      <dc:creator>Samuel_AL</dc:creator>
      <dc:date>2020-12-29T21:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking TOR Exit nodes with scripting</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-TOR-Exit-nodes-with-scripting/m-p/106611#M9937</link>
      <description>&lt;P&gt;Blocking TOR app in policy only achieves blocking outgoing traffic from your network. With this route you achieve, that your publicly accessible services (DMZ...) cannot be accessed from TOR exit nodes.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 05:54:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-TOR-Exit-nodes-with-scripting/m-p/106611#M9937</guid>
      <dc:creator>Borut</dc:creator>
      <dc:date>2020-12-30T05:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking TOR Exit nodes with scripting</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-TOR-Exit-nodes-with-scripting/m-p/106612#M9938</link>
      <description>&lt;P&gt;App control is not a prerequisite. We are using the script on gateways without it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are some known limitations.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Supported on Security Gateway running Gaia OS only.&lt;/LI&gt;&lt;LI&gt;Not supported on VSX Gateway and on Scalable Platforms.&lt;/LI&gt;&lt;LI&gt;Security Gateway behind a proxy is supported only with the modified scripts from&lt;BR /&gt;section "&lt;SPAN class="checkpoint_navigate"&gt;(3) How to block traffic from custom IP feeds (managed from Management Server)&lt;/SPAN&gt;".&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Did not test it on R77.30 however, we're using it on versions from R80.10 - R80.40.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 06:04:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-TOR-Exit-nodes-with-scripting/m-p/106612#M9938</guid>
      <dc:creator>Borut</dc:creator>
      <dc:date>2020-12-30T06:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking TOR Exit nodes with scripting</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-TOR-Exit-nodes-with-scripting/m-p/106626#M9940</link>
      <description>&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Our SG is running Gaia OS.&lt;/LI&gt;&lt;LI&gt;Not a VSX GW.&lt;/LI&gt;&lt;LI&gt;Not behind a proxy.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The allowed connections that I see in SmartView Tracker are accepted by a rule in the firewall policy that is allowing from the Internet to a specific server in DMZ network through specific services.&lt;/P&gt;&lt;P&gt;Shouldn't this traffic be dropped by SAMP before it reaches the firewall policy?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 09:21:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-TOR-Exit-nodes-with-scripting/m-p/106626#M9940</guid>
      <dc:creator>Samuel_AL</dc:creator>
      <dc:date>2020-12-30T09:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking TOR Exit nodes with scripting</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-TOR-Exit-nodes-with-scripting/m-p/106701#M14258</link>
      <description>&lt;P&gt;Yes, it should. Not sure why it isn't working for you. Is this a cluster enviroment? Are rules applied on all gateways in a cluster?&lt;/P&gt;&lt;P&gt;On R80.40 we get "&lt;EM&gt;The packet violated the DOS module's rate limiting rule base (SecureXL device 0) (policy: 2045) (total rules: 3&lt;/EM&gt;)" logs in SmartLog. No policy matches for this IP's.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;: Any Ideas why we can search for this logs only by IP address and not by message contents? I have tried every string from the SK and some of my own, with no&amp;nbsp; success.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Dec 2020 06:38:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-TOR-Exit-nodes-with-scripting/m-p/106701#M14258</guid>
      <dc:creator>Borut</dc:creator>
      <dc:date>2020-12-31T06:38:27Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking TOR Exit nodes with scripting</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-TOR-Exit-nodes-with-scripting/m-p/106771#M14271</link>
      <description>&lt;P&gt;Depends on what field this message appears in.&lt;BR /&gt;Not every log field is indexed (and thus not searchable).&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jan 2021 00:37:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-TOR-Exit-nodes-with-scripting/m-p/106771#M14271</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-01T00:37:20Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking TOR Exit nodes with scripting</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-TOR-Exit-nodes-with-scripting/m-p/106892#M14302</link>
      <description>&lt;P&gt;Can't say i ever liked this solution.&amp;nbsp; More and more thinking ill wait for R81 and do an importable list and just update that off an api&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 13:45:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blocking-TOR-Exit-nodes-with-scripting/m-p/106892#M14302</guid>
      <dc:creator>Timothy_Weid</dc:creator>
      <dc:date>2021-01-04T13:45:45Z</dc:date>
    </item>
  </channel>
</rss>

