<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to get IoC working in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195295#M32744</link>
    <description>&lt;P&gt;Any time mate, pleasure to help the best I can. Please let us know what you find.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Mon, 16 Oct 2023 16:37:19 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-10-16T16:37:19Z</dc:date>
    <item>
      <title>Unable to get IoC working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195189#M32713</link>
      <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm trying to play around with External IoC Feeds from .csv file uploaded to the Standalone device (lab setup).&lt;/P&gt;
&lt;P&gt;I've successfully uploaded the IoC file which is of Check Point Format .csv&lt;/P&gt;
&lt;TABLE width="562"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="85"&gt;#Uniq-Name&lt;/TD&gt;
&lt;TD width="106"&gt;#Value&lt;/TD&gt;
&lt;TD width="64"&gt;#Type&lt;/TD&gt;
&lt;TD width="85"&gt;#Confidence&lt;/TD&gt;
&lt;TD width="64"&gt;#Severity&lt;/TD&gt;
&lt;TD width="64"&gt;#Product&lt;/TD&gt;
&lt;TD width="94"&gt;#Comment&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;observ1&lt;/TD&gt;
&lt;TD&gt;*.facebook.com&lt;/TD&gt;
&lt;TD&gt;URL&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;high&lt;/TD&gt;
&lt;TD&gt;AV&lt;/TD&gt;
&lt;TD&gt;"Malicious IP"&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once the file was uploaded, I've even tried to push policy as well. However I'm still able to ping &lt;A href="http://www.facebook.com" target="_blank"&gt;www.facebook.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I've checked the free disk is more than 40% and memory utilization is around 40%. - Since it was written in the known limitations.&amp;nbsp;&lt;/P&gt;
&lt;DIV id="tinyMceEditor_khard_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;Is there something which I'm missing ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Oct 2023 16:54:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195189#M32713</guid>
      <dc:creator>_khard</dc:creator>
      <dc:date>2023-10-15T16:54:36Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get IoC working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195193#M32714</link>
      <description>&lt;P&gt;Send the csv file you used, I will test it in the lab.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 15 Oct 2023 17:03:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195193#M32714</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-15T17:03:21Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get IoC working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195197#M32715</link>
      <description>&lt;P&gt;Here's the .csv file.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Oct 2023 17:39:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195197#M32715</guid>
      <dc:creator>_khard</dc:creator>
      <dc:date>2023-10-15T17:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get IoC working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195200#M32716</link>
      <description>&lt;P&gt;Might do it tomorrow and let you know. Btw, you can easily tell yourself why it fails...just check the logs, route, capture...etc.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 15 Oct 2023 18:34:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195200#M32716</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-15T18:34:47Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get IoC working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195215#M32719</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/70943"&gt;@_khard&lt;/a&gt;&amp;nbsp;Suggest you take this internally for resolution please.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These spaces are intended for customers / partners to ask questions.&lt;/P&gt;</description>
      <pubDate>Sun, 15 Oct 2023 22:19:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195215#M32719</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-10-15T22:19:55Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get IoC working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195218#M32720</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;Sorry about the delay, my colleagues were doing lots of changes to our lab, so took bit longer than expected. I just tested this, and works fine for me. I have real good R81.20 lab, happy to show you what I did.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 15 Oct 2023 23:21:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195218#M32720</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-15T23:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get IoC working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195219#M32721</link>
      <description>&lt;P&gt;I see what you are saying Chris, but in my opinion, we are all here to help one another. As far as Im concerned, I never care whether its a CP employee or anyone else posting a question, makes no difference to me.&lt;/P&gt;
&lt;P&gt;I will always do my best to help, thats all.&lt;/P&gt;
&lt;P&gt;Cheers mate.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 15 Oct 2023 23:22:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195219#M32721</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-15T23:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get IoC working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195222#M32722</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So you're saying that with the file I provided your internal network machines were not able to ping/telnet *.facebook.com ?&lt;/P&gt;
&lt;P&gt;Yes, if you could show me that would be great. Let me know how you want to connect.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 03:15:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195222#M32722</guid>
      <dc:creator>_khard</dc:creator>
      <dc:date>2023-10-16T03:15:04Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get IoC working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195223#M32723</link>
      <description>&lt;P&gt;No...what Im saying is I was going to facebook fine from machine behind the lab cluster. I will see if I can get it working right tomorrow.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Good night.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 03:20:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195223#M32723</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-16T03:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get IoC working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195265#M32736</link>
      <description>&lt;P&gt;I got access to the lab, so will try work on this today when I have time. I see that access to facebook is allowed based on layered rules, so I have a feeling there is something else "missing" in order to make IoC feed work properly.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 12:41:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195265#M32736</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-16T12:41:40Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get IoC working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195292#M32742</link>
      <description>&lt;P&gt;K, just did some more testing, but no luck. Im occupied with important Fortinet stuff today, but here are my thoughts and I could be mistaken when I say this, but maybe someone else can confirm. I dont believe its enough to just put website/category in there via CSV file for indicator and enable say AV blade and that will auto block those sites. When I test facebook, works fine, though yes, I do have https inspection enabled, but category for FB is NOT blocked, so thats why it works.&lt;/P&gt;
&lt;P&gt;Personally, I do NOT think trying to do this via IoC would suffice, since its related to either AV or AB blades, but as far as blocking sites, thats strictly regarding URLF blade.&lt;/P&gt;
&lt;P&gt;Again, I could be totally way off here, but thats my logical approach...&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 16:11:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195292#M32742</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-16T16:11:40Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get IoC working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195294#M32743</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;for putting so much effort.&lt;/P&gt;
&lt;P&gt;Appreciate your help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 16:36:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195294#M32743</guid>
      <dc:creator>_khard</dc:creator>
      <dc:date>2023-10-16T16:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get IoC working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195295#M32744</link>
      <description>&lt;P&gt;Any time mate, pleasure to help the best I can. Please let us know what you find.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 16:37:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195295#M32744</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-16T16:37:19Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get IoC working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195335#M32749</link>
      <description>&lt;P&gt;IoC feeds are enforced by the AntiBot/AntiVirus blades, which I don't think block ICMP.&lt;BR /&gt;Best to use Network Feeds in R81.20, which can be directly used in the Access Policy.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 22:09:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195335#M32749</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-16T22:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get IoC working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195338#M32750</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;Can IoC indicator be used to block specific URL?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 22:22:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195338#M32750</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-16T22:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get IoC working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195345#M32753</link>
      <description>&lt;P&gt;Yes, the example in &lt;A href="https://support.checkpoint.com/results/sk/sk132193" target="_self"&gt;sk132193&lt;/A&gt; even includes one (subject to HTTPS Inspection configuration).&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 23:12:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195345#M32753</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-16T23:12:14Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get IoC working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195346#M32754</link>
      <description>&lt;P&gt;No idea what Im missing then...&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 23:17:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195346#M32754</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-16T23:17:48Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get IoC working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195457#M32772</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/70943"&gt;@_khard&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Got it working with help of my good colleague. So, we checked the config and he said to me "Hey, is it possible wildcard is not allowed in ioc file?" and I was thinking, hm, he has a point and BAM, as soon as we replaced *.facebook.com with &lt;A href="http://www.facebook.com," target="_blank"&gt;www.facebook.com,&lt;/A&gt;&amp;nbsp;deleted the ioc feed and reimported the file, all worked like a charm.&lt;/P&gt;
&lt;P&gt;I attached the file with screenshots.&lt;/P&gt;
&lt;P&gt;You may want to submit RFE for this, since you work for CP, so it would probably mean more coming from you than me LOL&lt;/P&gt;
&lt;P&gt;Anyway, file attached and if you have any more questions, happy to show you my lab, it has most things configured in it.&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 18:36:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195457#M32772</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-17T18:36:17Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get IoC working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195477#M32784</link>
      <description>&lt;P&gt;Also, forgot to say, though Im sure you know this, you can customize block page with different logos and messages (its under user check objects in object explorer and it can be set as per TP profile policy).&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 23:32:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195477#M32784</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-17T23:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get IoC working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195498#M32786</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;, Thanks for pointing this one out. I went through the documentation again and saw it doesn't support non-fqdns like network feeds does.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you again for your support.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 06:03:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Unable-to-get-IoC-working/m-p/195498#M32786</guid>
      <dc:creator>_khard</dc:creator>
      <dc:date>2023-10-18T06:03:32Z</dc:date>
    </item>
  </channel>
</rss>

