Have you considered using sk132193 Custom Intelligence Feeds? Instead of pushing policy from your management, you can configure your gateways to pull indicators from a feed. When the feed contents change, the gateway automatically stops blocking the old values and starts blocking the new. And, if you're looking for a managed facility, you could automate the input feed on Infinity NDR, and configure your gateways to pull from there.
Note that an R80.40 gateway will not match IP IOCs to source IP, only destination IP. R81 and higher block in both directions. This is true regardless of whether you're pushing policy or pulling from the gateway.