<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom Intelligence Feeds in CIDR format via SmartConsole in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Custom-Intelligence-Feeds-in-CIDR-format-via-SmartConsole/m-p/171281#M28612</link>
    <description>&lt;P&gt;Custom Intelligence Feeds files have a very specific format that is required.&lt;BR /&gt;It’s documented here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk132193" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk132193&lt;/A&gt;&lt;BR /&gt;If the file is not in that format, it won’t work.&lt;/P&gt;
&lt;P&gt;Network Feed objects (available in R81.20) should solve both issues.&lt;/P&gt;</description>
    <pubDate>Mon, 13 Feb 2023 17:27:58 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-02-13T17:27:58Z</dc:date>
    <item>
      <title>Custom Intelligence Feeds in CIDR format via SmartConsole</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Intelligence-Feeds-in-CIDR-format-via-SmartConsole/m-p/171199#M28600</link>
      <description>&lt;P&gt;Dear Mates,&lt;/P&gt;&lt;P&gt;R81.10 Take 87&lt;/P&gt;&lt;P&gt;1. Since Custom Intelligence Feeds via SmartConsole allows only "IP Address" or&amp;nbsp; "IP Range" types, is it possible to apply Spamhaus DROP list which is in CIDR format? In ioc_feeder.elg I get: "Feed format problem. Feed format not supported" - for both IP types.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Spamhaus.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19577i15CFCFD9FED0AB7A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Spamhaus.jpg" alt="Spamhaus.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. TOR_Exit_Nodes (&lt;A href="https://secureupdates.checkpoint.com/IP-list/TOR.txt" target="_blank"&gt;https://secureupdates.checkpoint.com/IP-list/TOR.txt)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;When I "Test Connectivity" it is OK, but in ioc_feeder.elg I get: "Feed format problem. Empty feed file".&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Tor.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19579iB41550209FA5CECD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Tor.jpg" alt="Tor.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;M.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2023 08:16:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Intelligence-Feeds-in-CIDR-format-via-SmartConsole/m-p/171199#M28600</guid>
      <dc:creator>CheckMate-R77</dc:creator>
      <dc:date>2023-02-13T08:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Intelligence Feeds in CIDR format via SmartConsole</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Intelligence-Feeds-in-CIDR-format-via-SmartConsole/m-p/171281#M28612</link>
      <description>&lt;P&gt;Custom Intelligence Feeds files have a very specific format that is required.&lt;BR /&gt;It’s documented here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk132193" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk132193&lt;/A&gt;&lt;BR /&gt;If the file is not in that format, it won’t work.&lt;/P&gt;
&lt;P&gt;Network Feed objects (available in R81.20) should solve both issues.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2023 17:27:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Intelligence-Feeds-in-CIDR-format-via-SmartConsole/m-p/171281#M28612</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-13T17:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Intelligence Feeds in CIDR format via SmartConsole</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Intelligence-Feeds-in-CIDR-format-via-SmartConsole/m-p/171358#M28624</link>
      <description>&lt;P&gt;Thank You PhoneBoy.&lt;/P&gt;&lt;P&gt;1. In sk132193 there is following CLI example for Spamhaus and CIDR format:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Original CSV structure is a list of IP addresses in CIDR format and comment lines are marked as ';'&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;ioc_feeds add --feed_name ip_cidr_list_with_delimiter --transport https --resource "&lt;A href="https://www.spamhaus.org/drop/edrop.txt" target="_blank" rel="noopener"&gt;https://www.spamhaus.org/drop/edrop.txt&lt;/A&gt;" --format [value:1,type:ip] --delimiter ";" --comment ";"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Mirosaw_Zimny_0-1676359881741.jpeg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19602i9472ADF644E49D83/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Mirosaw_Zimny_0-1676359881741.jpeg" alt="Mirosaw_Zimny_0-1676359881741.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When I test it in gateway CLI (I added only "--test true" option to original example) I get following error:&lt;/P&gt;&lt;P&gt;[Expert@gw1:0]# &lt;EM&gt;export EXT_IOC_NO_SSL_VALIDATION=1&lt;/EM&gt;&lt;BR /&gt;[Expert@gw1:0]# &lt;EM&gt;ioc_feeds add --feed_name ip_cidr_list_with_delimiter --transport https --resource "&lt;A href="https://www.spamhaus.org/drop/edrop.txt" target="_blank" rel="noopener"&gt;https://www.spamhaus.org/drop/edrop.txt&lt;/A&gt;" --format [value:1,type:ip] --delimiter ";" --comment ";" --test true&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Modifying feed ip_cidr_list_with_delimiter&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;start add&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Feed ip_cidr_list_with_delimiter will add on&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Feed Name: ip_cidr_list_with_delimiter&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Feed is Active&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;File will be fetched via HTTPS&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Resource: &lt;A href="https://www.spamhaus.org/drop/edrop.txt" target="_blank" rel="noopener"&gt;https://www.spamhaus.org/drop/edrop.txt&lt;/A&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Action: Prevent&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Feed is cli managed&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Feed type: custom_csv&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Fetching active feeds&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Something went wrong&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Something went wrong&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Signatures load failed&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The same error when I try to test it with http transport and even in case of local file downloaded by curl_cli - still doesn't work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. There is last point in Known Limitations section of sk132193: "Before 81.20, there is limit of number of observables , See sk171988."&lt;/P&gt;&lt;P&gt;Maybe I have exceeded the limit, but where can I find sk171988? I wonder if there is any mechanism to check and eliminate duplicated IOCs (IPs for example) by few external (and maybe overlapping) feeds?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. I have also noticed differences in notation in sk132193&lt;/P&gt;&lt;P&gt;--format [value:#1 orvalue:1&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;--comment [#] or --comment "#"&lt;/P&gt;&lt;P&gt;It seems both forms are equal?&lt;/P&gt;&lt;P&gt;sk132193 was last modified on &lt;SPAN class=""&gt;2023-02-07 and seems ...&amp;nbsp; not so actual?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 08:35:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Intelligence-Feeds-in-CIDR-format-via-SmartConsole/m-p/171358#M28624</guid>
      <dc:creator>CheckMate-R77</dc:creator>
      <dc:date>2023-02-14T08:35:05Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Intelligence Feeds in CIDR format via SmartConsole</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Intelligence-Feeds-in-CIDR-format-via-SmartConsole/m-p/171440#M28642</link>
      <description>&lt;P&gt;Hm...if it's an explicitly listed example that doesn't work, might be worth a TAC case.&lt;BR /&gt;&lt;SPAN&gt;Regardless, you might see if there are other messages in&amp;nbsp;$FWDIR/log/load_sigs.elg that explain what's happening.&lt;BR /&gt;Don't know that there's a way to deduplicate things.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The SK mentioned is internal, but&amp;nbsp;&amp;nbsp;it provides some details on the limits that exist prior to R81.20.&lt;BR /&gt;R81.20 has new infrastructure for IOC Feeds and Network Feeds that supports ~2 million observables.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 15:14:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Intelligence-Feeds-in-CIDR-format-via-SmartConsole/m-p/171440#M28642</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-14T15:14:23Z</dc:date>
    </item>
  </channel>
</rss>

