- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
When the Agents Attack
A Live Look at Agentic Exposure Validation
Bridge the CAASM Gap
with Exposure Management
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Got the request to block Tor nodes on a R81.10 environment.
First thought was the Updatable Objects, which felt to me like a logical place. Unfortunately Tor is not there.
Found SK 103154 - https://support.checkpoint.com/results/sk/sk103154 which suggests using the Generic Data Center object, it also gives a Check Point maintained online list https://secureupdates.checkpoint.com/IP-list/TOR.txt so this felt like the solution.
But that Check Point list is a plain text list and Generic Data Center object requires JSON format.
Apparently I wasn't the first with this problem as I found this script which glues everything together: https://github.com/HGrigorov/checkpoint/blob/main/tor2json
Which is a solution but at two points I feel Check Point is missing a chance to make this so much more user friendly.
1 - Why is that Tor list not in the Updatable Objects? Seen that asked before in 2020 also.
2 - Why is that Tor list not available as a JSON file for a Generic Data Center object (specially as it is mentioned in that SK as a solution for this sitation)?
I block TOR nodes using the external IOC feeds in R81.10.
The only way to use this file currently is with the Custom Intelligence Feeds options (ioc_feeds).
It cannot be used in either Generic Datacenter Objects or Network Feeds without some modification.
The sk has been updated accordingly.
We are also looking at adding it as an Updatable Object.
Upgrade to R81.20 and use Network Feeds, which should be able to read/use this file as-is.
Agree with @PhoneBoy ,R81.20 is your answer.
Andy
I block TOR nodes using the external IOC feeds in R81.10.
Same here.
Andy
Thanks for the quick replies all.
I dont fully agree that upgrading is easy, the external IOC feed seems interesting although in another module. might be good to add to the SK which lists all the options.
And of course Check Point could just add it to updatable objects 😉
I have json file you can use to create generic data object, which can be then used in policy to block known bad IPs and it gets updated every 300 seconds (5 mins)
Andy
The only way to use this file currently is with the Custom Intelligence Feeds options (ioc_feeds).
It cannot be used in either Generic Datacenter Objects or Network Feeds without some modification.
The sk has been updated accordingly.
We are also looking at adding it as an Updatable Object.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 28 | |
| 12 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 3 |
Tue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningThu 18 Jun 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point WAF - The Next Generation of AI powered protectionTue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleTue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningThu 18 Jun 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point WAF - The Next Generation of AI powered protectionTue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleThu 25 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E10: READY OR NOT: Securing the AI Enterprise 2/5 - AI Red TeamingAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY