- Products
- Learn
- Local User Groups
- Partners
- More
Stop Babysitting Rules.
Go Agentic
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hi Everybody,
Anti-bot Protection contains IP, URLs, Domain reputation list.
I can generate URLs and DNS reputation logs easily, but cannot generate IPs reputation logs without using indicator files/external IOC feed.
How can I generate IPs reputation logs without using indicator files/ external IOC feed. Is it possible to do ?
For background what are you trying to achieve, are you trying to confirm a protection works as expected or do you need the log record as a template?
Hi Chris,
I access "http(s)://131.188.40.189" , the traffic can be block by Anti-bot (URL Reputation). but ping 131.188.40.189 or telnet 131.188.40.189 25, the traffic goes through.
Can I generate IPs reputation logs on production? I try several times but not luck.
What kind of tests can trigger IPs reputation logs?
Is it possible to create IPs reputation log record via Threatwiki page for demo?
HI Chris
in this example. according to "https://urlcat.checkpoint.com/urlcat/main.htm".
if i enter the ip "131.188.40.189", it will be shown URL Reputation not IP Reputation.
The Anti-bot Protection name (Reputation IP/Reputation URLs / Reputation Domain) confuses me.
As far as I know
1. Reputation IP => xxx.xxx.xxx.xxx
2. Reputation URLs => www.bot.com/xxx.exe
3. Reputation Domain => www.bot.com
For this case, if we want to show log of "Reputation IP" in the Logs and Monitoring, would it be possible?
For context:
What confidence level is the profile/blade set to enforce?
Also are the protections correctly reporting up to date in the necessary areas/domain per sk171644.
My setting as below
This thread is about Gateway protections
Whereas your video is Endpoint or must I keep watching to a particular timestamp?
If for Endpoint I suggest starting a new thread.
you rught mine for endpoint
Are you trying to find a known IP that will trigger the Reputation IP protection?
In any case, the focus of Anti-Bot is DNS, SMTP, and HTTP(S), as noted here: https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&eve...
Best practice is to limit outbound Internet connectivity to the precise services needed.
Meanwhile you might try a DNS lookup to the IP (assuming the lookup goes through the gateway) or initiate an SMTP connection to it.
Hi PhoneBoy,
We have a lots of "Reputation IPs" for Anti-Bot Protection show as below, but never see "IP reputation" type on log.
Is it possible to generate "IPs reputation logs" without using indicator files/ external IOC feed?
Not as far as I know because of how the decision to block is made (IP Reputation being just one factor).
When you use an external indicator feed and block based purely on that, we can make the clear statement in the logs that it's an "IP Reputation" reason.
Was this screenshot from demo mode or elsewhere the protections look out of date by 6-months at the time of posting (refer: sk171644)?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 9 | |
| 9 | |
| 8 | |
| 7 | |
| 6 | |
| 6 | |
| 4 | |
| 4 |
Fri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceTue 02 Jun 2026 @ 10:00 AM (AEST)
The Cloud Architect Series: Check Point WAF. The next generation of AI-Powered Protection - APACTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesTue 02 Jun 2026 @ 10:00 AM (AEST)
The Cloud Architect Series: Check Point WAF. The next generation of AI-Powered Protection - APACTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY