Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Simon_Macpherso
Advisor
Jump to solution

R81.20 TechTalk webinar - Network Feed Objects

Hello,

This is related Network Feeds object mentioned in the What's New in R81.20 TechTalk webinar this week.  

I have a few questions re the Network Feeds object. 

What file type is the file the Network Feeds object?

If there is no strict formatting;

  • How can you trust the data input is valid data?
  • Is there a built-in validation process to ensure the data is valid?
  • Also is there a constraints mechanism i.e. restrict what values can will be accepted ion the file e.g. a specific IP range?

We just started using generic data center objects block malicious IPs from verified threat intelligence feeds. As you stated, the generic data center object references a JSON file with strict formatting requirements. However, there is still no built-in protection for data validation. 

To mitigate input errors i.e. input data that doesn't conform to the strict formatting, we validate the JSON against a schema before copying the file to a web or the management server.  

In terms of scalability,  the JSON should be able to handle a lot of IPs. Can you explain the advantage of the new object in further detail here?  

I would be interested to look at any additional information you're able to provide on the Network Feeds object.  

@Tomer_Noy are you able to shed some more light on these objects?

Regards,

Simon    

0 Kudos
2 Solutions

Accepted Solutions
PhoneBoy
Admin
Admin

In addition to being JSON, for which you can specify a 'jq' query to pull out the precise fields you're interested in, a "flat file" type is supported.
You specify the precise formatting when you define the object:

image.png

The Data Type of the feed can be:

  • IP Address
  • Domain Name
  • IP Address or Domain Name

As for the benefit of this new method, there are a few:

  • Generic Datacenter objects use the CloudGuard Connector backend, which relies on the management server being active to feed the gateways. Network Feeds are fetched from the gateways directly.
  • Generic Datacenter objects only support IPs, Network Feeds also support domains.
  • Network Feeds should be significantly faster and more scalable than either Generic Datacenter objects or IOC Feeds in terms of how quickly they are read in and enforced on the gateway.

Hopefully I got everything that's pertinent 🙂

Edit: See also the official documentation on this feature
https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuid... 

View solution in original post

This widget could not be displayed.
23 Replies

All of @PhoneBoy's comments are accurate.

In addition, to answer your remaining questions:

An invalid entry will not break the entire feed and will simply be skipped. I just tried it to verify 😀
(take a look at the attached pictures)

Also, if the feed is completely broken or inaccessible, the gateway will continue to use cached contents from the last successful fetch.

You can of course add your custom validations to some CI/CD pipeline before updating the feed files (whether JSON or flat files).

View solution in original post

All of @PhoneBoy's comments are accurate.

In addition, to answer your remaining questions:

An invalid entry will not break the entire feed and will simply be skipped. I just tried it to verify 😀
(take a look at the attached pictures)

Also, if the feed is completely broken or inaccessible, the gateway will continue to use cached contents from the last successful fetch.

You can of course add your custom validations to some CI/CD pipeline before updating the feed files (whether JSON or flat files).

View solution in original post

All of @PhoneBoy's comments are accurate.

In addition, to answer your remaining questions:

An invalid entry will not break the entire feed and will simply be skipped. I just tried it to verify 😀
(take a look at the attached pictures)

Also, if the feed is completely broken or inaccessible, the gateway will continue to use cached contents from the last successful fetch.

You can of course add your custom validations to some CI/CD pipeline before updating the feed files (whether JSON or flat files).

View solution in original post

Simon_Macpherso
Advisor
Simon_Macpherso
Advisor

@PhoneBoy 

Thanks for the information. 

If flat file format is selected, do you know if any validation is done on the IP or domain values to ensure they are valid inputs? If not, and an invalid entry is added, does this break the entire network feed object?  

With JSON selection, if there is no built-in validation, we can perform our own validation against a JSON schema which we currently do.  

Regards,

Simon

@PhoneBoy 

Thanks for the information. 

If flat file format is selected, do you know if any validation is done on the IP or domain values to ensure they are valid inputs? If not, and an invalid entry is added, does this break the entire network feed object?  

With JSON selection, if there is no built-in validation, we can perform our own validation against a JSON schema which we currently do.  

Regards,

Simon

0 Kudos
0 Kudos
This widget could not be displayed.
This widget could not be displayed.
This widget could not be displayed.
This widget could not be displayed.
This widget could not be displayed.
This widget could not be displayed.
This widget could not be displayed.
This widget could not be displayed.
This widget could not be displayed.
This widget could not be displayed.
This widget could not be displayed.
This widget could not be displayed.
This widget could not be displayed.
This widget could not be displayed.
This widget could not be displayed.
This widget could not be displayed.
This widget could not be displayed.
This widget could not be displayed.
This widget could not be displayed.
This widget could not be displayed.
This widget could not be displayed.