<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall Script Example: Automatically Block IPs in Events</title>
    <link>https://community.checkpoint.com/t5/Events/Firewall-Script-Example-Automatically-Block-IPs/m-p/253840#M74</link>
    <description>&lt;P&gt;Will try in the morning...cheers. Thank you!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 24 Jul 2025 04:05:40 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-07-24T04:05:40Z</dc:date>
    <item>
      <title>Firewall Script Example: Automatically Block IPs</title>
      <link>https://community.checkpoint.com/t5/Events/Firewall-Script-Example-Automatically-Block-IPs/m-p/253722#M68</link>
      <description>&lt;DIV id="tinyMceEditorxp_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;1）Purpose：&lt;/P&gt;
&lt;P&gt;Utilize SmartEvent's Automatic Reaction feature to automatically execute a response script when specific attack events (such as Nikto scans) are detected, enhancing automation and real-time threat response.&lt;/P&gt;
&lt;P&gt;2）Use Case：&lt;/P&gt;
&lt;P&gt;A.Security administrators want to automatically block source IPs upon detecting intrusion behaviors like Nikto Security Scanner scans.&lt;/P&gt;
&lt;P&gt;B.Integrates SmartEvent’s event detection with custom scripts to enable fast and automated response without manual intervention.&lt;/P&gt;
&lt;P&gt;C.Ideal for test or production environments requiring immediate mitigation of known attack patterns, along with response logging.&lt;/P&gt;
&lt;P&gt;3）Requirements：&lt;/P&gt;
&lt;P&gt;&lt;STRONG data-start="971" data-end="992"&gt;SmartEvent Server&lt;/STRONG&gt; and &lt;STRONG data-start="997" data-end="1028"&gt;SmartEvent Correlation Unit&lt;/STRONG&gt; must be deployed and enabled.&lt;/P&gt;
&lt;P&gt;The relevant attack event (e.g., Nikto scan) must be identifiable in the logs and captured by the Correlation Unit.&lt;/P&gt;
&lt;P&gt;An Automatic Reaction rule must be configured and linked to a script (the script should be placed in &lt;CODE data-start="1394" data-end="1420"&gt;$RTDIR/bin/ext_commands/&lt;/CODE&gt; on the SmartEvent Server and granted executable permissions).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 06:00:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Firewall-Script-Example-Automatically-Block-IPs/m-p/253722#M68</guid>
      <dc:creator>xp</dc:creator>
      <dc:date>2025-07-24T06:00:17Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Script Example: Automatically Block IPs</title>
      <link>https://community.checkpoint.com/t5/Events/Firewall-Script-Example-Automatically-Block-IPs/m-p/253830#M69</link>
      <description>&lt;P&gt;Will test it in the lab. Does it create a feed with bad IP addresses?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 23:12:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Firewall-Script-Example-Automatically-Block-IPs/m-p/253830#M69</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-23T23:12:17Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Script Example: Automatically Block IPs</title>
      <link>https://community.checkpoint.com/t5/Events/Firewall-Script-Example-Automatically-Block-IPs/m-p/253836#M70</link>
      <description>&lt;P&gt;Yes, it is recommended to create a drop policy in advance, using a predefined address group as the source. This group will be used to store IP addresses from the malicious IP feed.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 03:16:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Firewall-Script-Example-Automatically-Block-IPs/m-p/253836#M70</guid>
      <dc:creator>xp</dc:creator>
      <dc:date>2025-07-24T03:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Script Example: Automatically Block IPs</title>
      <link>https://community.checkpoint.com/t5/Events/Firewall-Script-Example-Automatically-Block-IPs/m-p/253837#M71</link>
      <description>&lt;P&gt;I assume its run on mgmt server?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 03:29:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Firewall-Script-Example-Automatically-Block-IPs/m-p/253837#M71</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-24T03:29:19Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Script Example: Automatically Block IPs</title>
      <link>https://community.checkpoint.com/t5/Events/Firewall-Script-Example-Automatically-Block-IPs/m-p/253839#M73</link>
      <description>&lt;P&gt;Yes, it runs on the management server. Upload the script to &lt;CODE data-start="356" data-end="382"&gt;$RTDIR/bin/ext_commands/&lt;/CODE&gt; and make it executable. Please refer to the "&lt;EM data-start="427" data-end="475"&gt;R82 Logging and Monitoring Administrator Guide"&lt;/EM&gt; or the attachment for details.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 03:49:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Firewall-Script-Example-Automatically-Block-IPs/m-p/253839#M73</guid>
      <dc:creator>xp</dc:creator>
      <dc:date>2025-07-24T03:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Script Example: Automatically Block IPs</title>
      <link>https://community.checkpoint.com/t5/Events/Firewall-Script-Example-Automatically-Block-IPs/m-p/253840#M74</link>
      <description>&lt;P&gt;Will try in the morning...cheers. Thank you!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 04:05:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Firewall-Script-Example-Automatically-Block-IPs/m-p/253840#M74</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-24T04:05:40Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Script Example: Automatically Block IPs</title>
      <link>https://community.checkpoint.com/t5/Events/Firewall-Script-Example-Automatically-Block-IPs/m-p/253841#M75</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/107538"&gt;@xp&lt;/a&gt;&amp;nbsp;, please add some description: use case, purpose, requirements, etc&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 04:59:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Firewall-Script-Example-Automatically-Block-IPs/m-p/253841#M75</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-07-24T04:59:46Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Script Example: Automatically Block IPs</title>
      <link>https://community.checkpoint.com/t5/Events/Firewall-Script-Example-Automatically-Block-IPs/m-p/253878#M76</link>
      <description>&lt;P&gt;Just ran it in my R82 mgmt lab and when I invoke the script, it never finishes, not sure why. I followed exact steps you outlined.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 12:11:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Firewall-Script-Example-Automatically-Block-IPs/m-p/253878#M76</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-24T12:11:21Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Script Example: Automatically Block IPs</title>
      <link>https://community.checkpoint.com/t5/Events/Firewall-Script-Example-Automatically-Block-IPs/m-p/253898#M77</link>
      <description>&lt;P&gt;Here are a few things you can check:&lt;/P&gt;
&lt;P&gt;1. you can run cat /home/admin/ext_script.txt on the management server to view the full execution log of the script and identify where it might be hanging.&lt;/P&gt;
&lt;P&gt;2. If there's no log output at all,please double-check that User Defined Event Policy is properly configured and deployed.The event may not be triggering the Automatic Reaction as expected.&lt;/P&gt;
&lt;P&gt;3. Also,verify that the IPS logs are indeed being generated and that the "attack information" field contains the keyword "xxx(Nikto Security Scanner)",as this is required for the script trigger condition.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 15:23:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Firewall-Script-Example-Automatically-Block-IPs/m-p/253898#M77</guid>
      <dc:creator>xp</dc:creator>
      <dc:date>2025-07-24T15:23:23Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Script Example: Automatically Block IPs</title>
      <link>https://community.checkpoint.com/t5/Events/Firewall-Script-Example-Automatically-Block-IPs/m-p/253899#M78</link>
      <description>&lt;P&gt;I get below.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;[Expert@CP-MANAGEMENT:0]# cat /home/admin/ext_script.txt&lt;BR /&gt;2025-07-24 08:08:11 - ===== 新事件触发 =====&lt;BR /&gt;[Expert@CP-MANAGEMENT:0]#&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 15:40:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Firewall-Script-Example-Automatically-Block-IPs/m-p/253899#M78</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-24T15:40:32Z</dc:date>
    </item>
  </channel>
</rss>

