- Products
- Learn
- Local User Groups
- Partners
- More
The State of Ransomware Q1 2026
Key Trends and Their Impact
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hello,
I am trying to enhance the CheckPoint policy security level.
And I am looking for a dynamic list from a great Security Vendor that can be applied to a Firewall policy to protect users from malicious IP addresses.
I find that PaloAlto is using an object named External Dynamic Lists, and it also provides
"Palo Alto Networks Known Malicious IP Addresses"
"Palo Alto Networks High-Risk IP Addresses"
as objects to allow IT admin to apply them to a Firewall policy for blocking/blacklist purposes.
I wonder if CheckPoint also provides the same great objects there.
Thank you!
Not sure if checkpoint provides it's own list, but what you can configure are intelligence feeds through the threat prevention feature Threat Indicators
Hello, you can import IOCs list from SmartConsole or CLI. I found a whitepaper in this community and maybe may be util for you.
Under application control just use categories as Critical and High risk, Spam, Spyware & Malicious and you don't need to deal with IP blacklist.
Much more, but in a different way: IP addresses are usually evaluated by TP in ThreatCloud (much better than a list); Dynamic / Updateable Objects can use customer-created IP lists, see Can we create custom updatable objects in R80.20
R81.20 - currently in EA - might have what you're asking for:
https://community.checkpoint.com/t5/Product-Announcements/R81-20-EA-Program-Production/ba-p/135926
Enhancing the gold standard in Security Management: Quantum R81.20 lets you leverage the new Management API to integrate security from the ground up and efficiently manage access policies with support for dynamic policy objects taken from external sources.
Yes. External Network Feeds. https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuid...
You got it! Best part is, no need to have AV or AB blades enabled to use network feeds.
I made post about it.
Andy
https://community.checkpoint.com/t5/Security-Gateways/Network-feed/m-p/212407#M40317
R81+ now includes a "Generic Data Center" that you populate with a JSON file of IPs/networks. You can update this object via management API and Ansible.
https://support.checkpoint.com/results/sk/sk167210
Management API: https://sc1.checkpoint.com/documents/latest/APIs/#cli/add-data-center-object~v1.7%20
Ansible: cp_mgmt_add_data_center_object module
Great suggestion.
Your screenshot does not seem to be related to this discussion. Reach out to me directly via a PM, please
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 34 | |
| 10 | |
| 10 | |
| 10 | |
| 10 | |
| 8 | |
| 7 | |
| 6 | |
| 6 | |
| 6 |
Tue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceWed 13 May 2026 @ 11:00 AM (EDT)
TechTalk: The State of Ransomware Q1 2026: Key Trends and Their ImpactThu 14 May 2026 @ 07:00 PM (EEST)
Under the Hood: Presentando Check Point Cloud Firewall como ServicioTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY