<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom Threat Indicator Not Blocking Malicious IP in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/184610#M30756</link>
    <description>&lt;P&gt;Hello Blason, just a quick question&lt;/P&gt;
&lt;P&gt;Indicators by definition it helps AntiVirus and AntiBot blades, but like we know, list of ips are populated inside fwaccel dos deny lists.&lt;/P&gt;
&lt;P&gt;Well, these lists are enforced before Access Control and Threat Prevention policies.... if this is true, the statement about antivirus and antibot is not true...am i wrong? thanks&lt;/P&gt;
&lt;DIV id="gtx-trans" style="position: absolute; left: 604px; top: 102px;"&gt;
&lt;DIV class="gtx-trans-icon"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Fri, 23 Jun 2023 08:24:33 GMT</pubDate>
    <dc:creator>CheckPointerXL</dc:creator>
    <dc:date>2023-06-23T08:24:33Z</dc:date>
    <item>
      <title>Custom Threat Indicator Not Blocking Malicious IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182364#M30402</link>
      <description>&lt;P&gt;Hi Everyone.&lt;/P&gt;&lt;P&gt;I wanted to know if the custom threat indicators only apply to outgoing traffic and not incoming. I have a scenario where an IP listed in the custom indicator is not getting blocked.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do I need to run/install the IP Block Feature script to block the connections originating from malicious IP sources? The other way I could see is to configure a generic data center object and call the malicious IP database URL.&lt;/P&gt;&lt;P&gt;Checkpoint 5800&lt;/P&gt;&lt;P&gt;ClutserXL Active-Passive&lt;/P&gt;&lt;P&gt;R80.40&lt;/P&gt;&lt;P&gt;Perimeter Firewall&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;Digo.&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2023 05:31:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182364#M30402</guid>
      <dc:creator>Digo11</dc:creator>
      <dc:date>2023-05-29T05:31:14Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Threat Indicator Not Blocking Malicious IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182366#M30404</link>
      <description>&lt;P&gt;Hi Digo,&lt;/P&gt;
&lt;P&gt;If I recall inbound blocking is only available from R81 onwards - prior to that it was outbound only.&amp;nbsp; GDC should accomplish what you need, yes.&lt;/P&gt;
&lt;P&gt;-Ruan&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2023 05:49:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182366#M30404</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2023-05-29T05:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Threat Indicator Not Blocking Malicious IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182370#M30406</link>
      <description>&lt;P&gt;Hi Ruan,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any SK or document for this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Digo.&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2023 06:44:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182370#M30406</guid>
      <dc:creator>Digo11</dc:creator>
      <dc:date>2023-05-29T06:44:56Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Threat Indicator Not Blocking Malicious IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182371#M30407</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Please use fwaccel dos deny -a or -l feature and you should be able to block the desired IP addresses.&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2023 06:55:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182371#M30407</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2023-05-29T06:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Threat Indicator Not Blocking Malicious IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182372#M30408</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1551"&gt;@Blason_R&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your response. So, the custom indicator won't block incoming traffic? We get malicious IP lists from our partners and till now we assumed the indicator blocks both-way traffic. I couldn't find any relevant document or SK, where it is mentioned that the custom indicator only blocks only outgoing traffic apart from "Inbound traffic to a host behind the gateway,&amp;nbsp;does not get blocked, e.g: IP that is on the feed, sends ICMP Request to a host behind the gateway. This traffic does not&amp;nbsp;get&amp;nbsp;blocked" in SK 132193.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Digo.&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2023 07:08:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182372#M30408</guid>
      <dc:creator>Digo11</dc:creator>
      <dc:date>2023-05-29T07:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Threat Indicator Not Blocking Malicious IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182375#M30410</link>
      <description>&lt;P&gt;Well fwaccel dos deny will be able to block the traffic inbound however consider if the traffic is initiated outbound however if the return traffic arrives this is again an inbound and it will be cut on firewall. So eventually my observation is fwaccel dos deny is effective on blocking inbound and as well as outbound. Yes Inbound it will be knocked off on first SYN packets however outbound it will be killed on Ack packet.&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2023 08:11:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182375#M30410</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2023-05-29T08:11:29Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Threat Indicator Not Blocking Malicious IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182379#M30414</link>
      <description>&lt;P&gt;Hi Digo,&lt;/P&gt;
&lt;P&gt;It's listed in the "Known Limitations" in &lt;A href="https://support.checkpoint.com/results/sk/sk132193" target="_self"&gt;sk132193&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Edit: I see you did already come across this&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2023 08:36:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182379#M30414</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2023-05-29T08:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Threat Indicator Not Blocking Malicious IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182387#M30419</link>
      <description>&lt;P&gt;You can create generic data center objects as per SK indicated and use those to block most known bad IP addresses. I can send you the file I use for that if you like.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2023 12:19:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182387#M30419</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-29T12:19:33Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Threat Indicator Not Blocking Malicious IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182415#M30442</link>
      <description>&lt;P&gt;Custom Threat Indicators only block incoming traffic from R81.&lt;BR /&gt;However, if the traffic originates from outside, the reply traffic will be blocked by the Custom Threat Indicator.&lt;/P&gt;
&lt;P&gt;Note if you have a significant number of indicators, you should upgrade to R81.20 as it supports significantly more indicators than previous versions.&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2023 15:30:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182415#M30442</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-05-29T15:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Threat Indicator Not Blocking Malicious IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182416#M30443</link>
      <description>&lt;P&gt;Generic Datacenter objects are only available from R81 and the original poster is in R80.40.&lt;BR /&gt;Upgrading is highly recommended since R80.40 will be End of Life at the end of January 2024.&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2023 15:32:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182416#M30443</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-05-29T15:32:21Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Threat Indicator Not Blocking Malicious IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182469#M30458</link>
      <description>&lt;P&gt;Thanks,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1551"&gt;@Blason_R&lt;/a&gt;&amp;nbsp; I will try it.&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 05:09:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182469#M30458</guid>
      <dc:creator>Digo11</dc:creator>
      <dc:date>2023-05-30T05:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Threat Indicator Not Blocking Malicious IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182470#M30459</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the info. I can see one of the IPs listed in the custom indicator hits on port SMTP port 25 to one of our public mail IPs and the traffic is accepted. Somehow, the log shows as an alert but still accepts the connection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Digo.&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 05:15:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182470#M30459</guid>
      <dc:creator>Digo11</dc:creator>
      <dc:date>2023-05-30T05:15:01Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Threat Indicator Not Blocking Malicious IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182570#M30489</link>
      <description>&lt;P&gt;The question is: is there traffic flowing to it beyond that initial packet?&lt;BR /&gt;In any case, upgrading from R80.40 is highly recommended.&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 16:30:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/182570#M30489</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-05-30T16:30:26Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Threat Indicator Not Blocking Malicious IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/184610#M30756</link>
      <description>&lt;P&gt;Hello Blason, just a quick question&lt;/P&gt;
&lt;P&gt;Indicators by definition it helps AntiVirus and AntiBot blades, but like we know, list of ips are populated inside fwaccel dos deny lists.&lt;/P&gt;
&lt;P&gt;Well, these lists are enforced before Access Control and Threat Prevention policies.... if this is true, the statement about antivirus and antibot is not true...am i wrong? thanks&lt;/P&gt;
&lt;DIV id="gtx-trans" style="position: absolute; left: 604px; top: 102px;"&gt;
&lt;DIV class="gtx-trans-icon"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 23 Jun 2023 08:24:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/184610#M30756</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2023-06-23T08:24:33Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Threat Indicator Not Blocking Malicious IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/184643#M30759</link>
      <description>&lt;P&gt;fwaccel dos rules are enforced in SecureXL and occur even before Implied Rules are allowed &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;Indicator lists imported via ioc_feeds are enforced as part of Threat Prevention.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 15:09:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/184643#M30759</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-23T15:09:44Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Threat Indicator Not Blocking Malicious IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/184644#M30760</link>
      <description>&lt;P&gt;That's correct... but, if you add an Indicator you will see the the deny list value, obtained by the command &lt;EM&gt;fwaccel dos stats get&lt;/EM&gt;, that increases, curiosly the same number of IPs contained in the imported Indicator list....&lt;/P&gt;
&lt;DIV id="gtx-trans" style="position: absolute; left: 123px; top: 28px;"&gt;
&lt;DIV class="gtx-trans-icon"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 23 Jun 2023 15:27:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/184644#M30760</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2023-06-23T15:27:15Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Threat Indicator Not Blocking Malicious IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/184681#M30769</link>
      <description>&lt;P&gt;Which would also indicate that SecureXL is blocking the IPs imported via ioc_feeds.&lt;BR /&gt;Makes sense to do that from a performance perspective.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 18:54:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Custom-Threat-Indicator-Not-Blocking-Malicious-IP/m-p/184681#M30769</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-23T18:54:44Z</dc:date>
    </item>
  </channel>
</rss>

