- Products
- Learn
- Local User Groups
- Partners
- More
Secure Your AI Transformation
9 April @ 12pm SGT / 3pm CET / 2PM EDT
Check Point WAF TechTalk:
Introduction and New Features
AI Security Masters E6: When AI Goes Wrong -
Hallucinations, Jailbreaks, and the Curious Behavior of AI Agents
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
CheckMates Go:
CheckMates Fest
Hi all,
Does anyone know what the limit is for Custom Threat Feed entries? Just curious as I have been playing around with IP & MD5 feeds. Is it by file size or number of entries?
Thanks
Rahul
Hey bud,
Below link will help. Appears its 1024 per observable and 2 million observable limit.
Andy
Not quite accurate 😉
Prior to R81.20, we cannot provide an exact limit since it depends on the IOCs and other blades in use.
However, it is significantly lower than the 2 million IOCs we tested in R81.20, which had new infrastructure created to support a large number of IoCs. (Actual limit depends on available memory)
Hey bud,
Below link will help. Appears its 1024 per observable and 2 million observable limit.
Andy
Perfect thanks Andy!!
It goes without saying...FYFOC ; - )
Not quite accurate 😉
Prior to R81.20, we cannot provide an exact limit since it depends on the IOCs and other blades in use.
However, it is significantly lower than the 2 million IOCs we tested in R81.20, which had new infrastructure created to support a large number of IoCs. (Actual limit depends on available memory)
Fair enough :). I just quoted numbers from that post.
Andy
Thanks Phoneboy,
If this is memory dependent I assume you'd have to be at a high memory usage to start running into issues, just out of curiousity do we know if any sort of log is generated for failed feed updates?
Edit: Looks like the notes for Custom Threat Intelligence show:
Thanks,
Rahul
Appears as per below:
https://support.checkpoint.com/results/sk/sk132193
Observables of IP addresses and IP Ranges can hold IPv4 values only. In R81 and higher versions IPV6 is supported as well.
MD5, SHA1, SHA256 observables cannot be enforced by Anti-Bot Blade. If user does not enable Anti-Virus blade, there will be no enforcement.
For R80.20SP, a Jumbo Hotfix Accumulator installation is required.
Inbound traffic to a host behind the gateway does not get blocked, e.g: IP that is on the feed, sends ICMP Request to a host behind the gateway. This traffic does not get blocked.
In R81 and higher versions, this traffic is blocked.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 40 | |
| 26 | |
| 14 | |
| 13 | |
| 11 | |
| 11 | |
| 10 | |
| 9 | |
| 8 |
Tue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Tue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Tue 14 Apr 2026 @ 03:00 PM (PDT)
Renton, WA: Securing The AI Transformation and Exposure ManagementThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY