- Products
- Learn
- Local User Groups
- Partners
- More
CheckMates Fifth Birthday
Celebrate with Us!
days
hours
minutes
seconds
Join the CHECKMATES Everywhere Competition
Submit your picture to win!
Check Point Proactive support
Free trial available for 90 Days!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
The 2022 MITRE Engenuity ATT&CK®
Evaluations Results Are In!
Now Available: SmartAwareness Security Training
Training Built to Educate and Engage
MITRE ATT&CK
Inside Check Point products!
CheckFlix!
All Videos In One Space
Hello
I want to block a list of ip with the indicator function. For this I go to Theart Prevention -> Indicators -> Import file and the file is imported.
Every day I have to push a new file and delete the old one. So I would like to use checkpoint APIs to do this.
I manage to delete the file but I can't find how to import the file.
Can you help me ?
Thanks
Why don't you run it on schedule and fetch the file automatically? Either local to the GW or remote.
I get a list of IPs to block every day. I already have a script in python that converts this list of ip to checkpoint format to import. The goal is to have a single script that will create the file, delete the old one and add the new one. And using the checkpoint APIs seems consistent to me.
I'm new to checkpoint so I don't know the features yet, but thanks for the feedback, I'll take a look.
Look forward to the finished results.
Hello ChruNDC,
Could you provide the CSV file or the format?
I am trying to import a CSV through smart console but i keep getting the error "Indicator in row 1 has less fields than expected".
Already tried to use an example of checkpoint but still no success.
Thanks
Have you considered using sk132193 Custom Intelligence Feeds? Instead of pushing policy from your management, you can configure your gateways to pull indicators from a feed. When the feed contents change, the gateway automatically stops blocking the old values and starts blocking the new. And, if you're looking for a managed facility, you could automate the input feed on Infinity NDR, and configure your gateways to pull from there.
Note that an R80.40 gateway will not match IP IOCs to source IP, only destination IP. R81 and higher block in both directions. This is true regardless of whether you're pushing policy or pulling from the gateway.
Hello nir_Naaman,
Yes i already consider but the customer what to be managed by the MGMT and Centralized.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY