<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Domain blocking by FQDN rule in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187717#M31431</link>
    <description>&lt;P&gt;Hi, Buddy&lt;/P&gt;
&lt;P&gt;I have managed to replicate your recommendation so far.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MA1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21899iE112D035F4D4E607/image-size/large?v=v2&amp;amp;px=999" role="button" title="MA1.png" alt="MA1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I have not enabled AV/ABOT in the Firewall.&lt;BR /&gt;Anyway, you tell me that it is not necessary to do so, right?&lt;/P&gt;
&lt;P&gt;I only have one doubt; how does the Firewall "feed" the new malicious IPs that exist?&lt;/P&gt;
&lt;P&gt;I understand that the intention is to work this way, is it to be automatic and transparent to us as users, or is it going to be necessary that we still "mess" with the configuration?&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
    <pubDate>Wed, 26 Jul 2023 15:49:29 GMT</pubDate>
    <dc:creator>Matlu</dc:creator>
    <dc:date>2023-07-26T15:49:29Z</dc:date>
    <item>
      <title>Domain blocking by FQDN rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187355#M31342</link>
      <description>&lt;P&gt;Good morning, team.&lt;/P&gt;
&lt;P&gt;We have a Cluster R81.10, in which, at the moment, we only have the "Firewall" blade working.&lt;/P&gt;
&lt;P&gt;For a need of our customer, we need to block "malicious domains (URLs)" that are reporting to us.&lt;/P&gt;
&lt;P&gt;Is it advisable and effective to be able to block malicious domains using a firewall rule with a DOMAIN object (FQDN)?&lt;/P&gt;
&lt;P&gt;Our intention for the moment is to contain malicious traffic, for the moment the APPC+URLF blades are not yet being worked on due to an internal customer process.&lt;/P&gt;
&lt;P&gt;I look forward to your kind comments.&lt;BR /&gt;&lt;BR /&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 13:36:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187355#M31342</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-24T13:36:17Z</dc:date>
    </item>
    <item>
      <title>Re: Domain blocking by FQDN rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187359#M31343</link>
      <description>&lt;P&gt;Note that an FQDN object will only block the specific FQDN (e.g. example.com) and not a wildcard (I.e. *.example.com).&lt;BR /&gt;To block the latter with just firewall, upgrade to R81.20 and use the Network Feeds option.&lt;BR /&gt;Or you can do it R81.10 using ioc_feeds and Anti-Virus/Anti-Bot enabled.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 13:46:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187359#M31343</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-24T13:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: Domain blocking by FQDN rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187361#M31344</link>
      <description>&lt;P&gt;As Phoneboy advised, thats your best bet...OR, you can create new domain based on below and follow steps from sk&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk120633" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk120633&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21860iFA9A10FCD60A200E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 13:53:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187361#M31344</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-24T13:53:20Z</dc:date>
    </item>
    <item>
      <title>Re: Domain blocking by FQDN rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187363#M31345</link>
      <description>&lt;P&gt;One inquiry,&lt;/P&gt;
&lt;P&gt;If I "uncheck" the checkbox, the Firewall is not able to "block" what is "before the first dot"?&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BL1.png" style="width: 626px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21861iE1B05B530B1204C4/image-size/large?v=v2&amp;amp;px=999" role="button" title="BL1.png" alt="BL1.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 13:54:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187363#M31345</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-24T13:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: Domain blocking by FQDN rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187364#M31346</link>
      <description>&lt;P&gt;Its all explained in the sk my friend : - )&lt;/P&gt;
&lt;P&gt;In layman's terms, if you uncheck it, then it should look up 10 sub-domains as well.Otherwise, it will check ONLY fully qualified domain name.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 13:56:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187364#M31346</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-24T13:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: Domain blocking by FQDN rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187365#M31347</link>
      <description>&lt;P&gt;&lt;SPAN&gt;N&lt;/SPAN&gt;&lt;SPAN&gt;etwork feeds in R81.20 is an alternate approach.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 14:00:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187365#M31347</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-07-24T14:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: Domain blocking by FQDN rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187366#M31348</link>
      <description>&lt;P&gt;Thanks for the clarification, my friend.&lt;/P&gt;
&lt;P&gt;PhoneBoy also mentioned another alternative, which is using the "ioc_feeds".&lt;/P&gt;
&lt;P&gt;How feasible is it to do this in version R81.10?&lt;/P&gt;
&lt;P&gt;Does it require extensive configuration in the Firewall?&lt;/P&gt;
&lt;P&gt;Cheers.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 14:16:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187366#M31348</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-24T14:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: Domain blocking by FQDN rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187367#M31349</link>
      <description>&lt;P&gt;No extra config needed mate &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 14:18:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187367#M31349</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-24T14:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: Domain blocking by FQDN rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187368#M31350</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;&lt;BR /&gt;I don't understand, but I am reading the official Checkpoint documentation.&lt;/P&gt;
&lt;P&gt;The ioc_feeds is part of the Threat Prevention, as I understand, but is it "mandatory" to activate any of the TP blades?&lt;BR /&gt;&lt;BR /&gt;Thanks. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 14:26:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187368#M31350</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-24T14:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: Domain blocking by FQDN rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187370#M31352</link>
      <description>&lt;P&gt;ioc_feeds needs TP blades yes (refer: sk132193).&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 14:34:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187370#M31352</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-07-24T14:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: Domain blocking by FQDN rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187371#M31353</link>
      <description>&lt;P&gt;But is it necessary to activate the 3 known TP blades, such as "AV, Anti-Bot, and IPS"?&lt;/P&gt;
&lt;P&gt;Or is it enough to enable 1/3 of these blades?&lt;/P&gt;
&lt;P&gt;Cheers.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 14:35:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187371#M31353</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-24T14:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: Domain blocking by FQDN rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187372#M31354</link>
      <description>&lt;P&gt;Im almost positive you need AV enabled, not sure if other 2 are a must.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 14:37:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187372#M31354</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-24T14:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: Domain blocking by FQDN rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187396#M31358</link>
      <description>&lt;P&gt;AV and Anti-Bot are required to use ioc_feeds.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 20:40:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187396#M31358</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-24T20:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: Domain blocking by FQDN rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187405#M31361</link>
      <description>&lt;P&gt;I could have sworn I only enabled AV in the lab to use ioc feeds, but will double check tomorrow.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 00:23:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187405#M31361</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-25T00:23:41Z</dc:date>
    </item>
    <item>
      <title>Re: Domain blocking by FQDN rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187496#M31372</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Do you have available a "step by step" guide to work with the IOC_FEEDS?&lt;/P&gt;
&lt;P&gt;Do the AV and AntiBot blades need to work with any particular profile?&lt;/P&gt;
&lt;P&gt;Or is it irrelevant the profile they work with?&lt;/P&gt;
&lt;P&gt;Thanks for your support&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 12:34:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187496#M31372</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-25T12:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: Domain blocking by FQDN rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187497#M31373</link>
      <description>&lt;P&gt;You are 100% right, I just verified that av and ab are needed, but ips is not.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 12:35:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187497#M31373</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-25T12:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: Domain blocking by FQDN rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187499#M31374</link>
      <description>&lt;P&gt;Ola bro,&lt;/P&gt;
&lt;P&gt;Profile does not matter, because in my TP profile, I do NOT have anything but IPS enabled, but I have av and ab blades on in the object properties. If you need screenshots, I can "slap" them together and send. Let me know.&lt;/P&gt;
&lt;P&gt;Cheers amigo.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 12:36:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187499#M31374</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-25T12:36:35Z</dc:date>
    </item>
    <item>
      <title>Re: Domain blocking by FQDN rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187514#M31377</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Hi, Andy.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Do you have a "csv" format to help me, to know how to "customize" my file, if we want to block malicious URLs.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;We want to block both Malicious IPs (In a .txt file) and Malicious URLs, with the IOCs.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;I understand that to block the IPs, I would only need connectivity between my GW and the PC that will "host" the .txt file, right?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Thanks for any helpful comments.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 13:31:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187514#M31377</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-25T13:31:23Z</dc:date>
    </item>
    <item>
      <title>Re: Domain blocking by FQDN rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187519#M31378</link>
      <description>&lt;P&gt;To make this simple, you can even use generic data center object and put a file anywhere on the mgmt server, once done, right click, import and then use those objects in the policy. I attached the file, as well as doc with screenshots.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 13:36:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187519#M31378</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-25T13:36:34Z</dc:date>
    </item>
    <item>
      <title>Re: Domain blocking by FQDN rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187520#M31379</link>
      <description>&lt;P&gt;To also add, to use generic data center objects, you do NOT need av/ab blades.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 13:37:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-blocking-by-FQDN-rule/m-p/187520#M31379</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-25T13:37:24Z</dc:date>
    </item>
  </channel>
</rss>

