- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: Custom Intelligence Feeds Vs Network feeds
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Custom Intelligence Feeds Vs Network feeds
Hello Mates,
I`ve a customer who is blocking thousands of Block listed ip`s by manually creating objects on the sms. I see that in R81.20 we have Custom Intelligence feeds and Network Feeds.
Which out of these 2 methods is scalable and more quick to enable and enforce on gateways ?
Also what is the primary difference btw these 2 features in terms of understanding, implementing.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
They both work well, but network feeds dont require av or ab blade enabled.
Im in Faroe Islands now, so no access to my laptop as Im on vacation, but have a look at post I made, hope it helps. Personally, I would say both are scalable.
Best,
Andy
https://community.checkpoint.com/t5/Security-Gateways/Network-feed/m-p/212407
Also, they get auto updated, which is fantastic.
Hope that helps.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@Ven I would say try it, I gave network feeds idea to one customer, smaller hospital, all those 9 feeds in the post, in 2 days, they had 3 mil hits, pretty good, I would say.
Best,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Network feeds are normal objects which you can use in rules. They can be used to allow stuff.
Custom intelligence feeds can only be used to drop stuff.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Actually, in R81.20, they're both fairly scalable since the infrastructure was updated.
Custom Intelligence Feeds can only be used with Threat Prevention blades and, as @Bob_Zimmerman said, they are used to block stuff.
Custom Intelligence Feeds have existed since R77.30.
Network Feeds can be used in the Access Policy and can be used both in the Access/NAT Policy and the Threat Prevention policy.
They can be used for both allowing and blocking stuff.
