Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Ven
Participant

Custom Intelligence Feeds Vs Network feeds

Hello Mates, 

I`ve a customer who is blocking thousands of Block listed ip`s by manually creating objects on the sms. I see that in R81.20 we have Custom Intelligence feeds and Network Feeds. 

Which out of these 2 methods is scalable and more quick to enable and enforce on gateways ?

Also what is the primary difference btw these 2 features in terms of understanding, implementing.  

 

 

0 Kudos
4 Replies
the_rock
Legend
Legend

They both work well, but network feeds dont require av or ab blade enabled.

Im in Faroe Islands now, so no access to my laptop as Im on vacation, but have a look at post I made, hope it helps. Personally, I would say both are scalable.

Best,

Andy

 

https://community.checkpoint.com/t5/Security-Gateways/Network-feed/m-p/212407

 

Also, they get auto updated, which is fantastic.

Hope that helps.

the_rock
Legend
Legend

@Ven I would say try it, I gave network feeds idea to one customer, smaller hospital, all those 9 feeds in the post, in 2 days, they had 3 mil hits, pretty good, I would say.

Best,

Andy

0 Kudos
Bob_Zimmerman
Authority
Authority

Network feeds are normal objects which you can use in rules. They can be used to allow stuff.

Custom intelligence feeds can only be used to drop stuff.

0 Kudos
PhoneBoy
Admin
Admin

Actually, in R81.20, they're both fairly scalable since the infrastructure was updated.

Custom Intelligence Feeds can only be used with Threat Prevention blades and, as @Bob_Zimmerman said, they are used to block stuff.
Custom Intelligence Feeds have existed since R77.30.

Network Feeds can be used in the Access Policy and can be used both in the Access/NAT Policy and the Threat Prevention policy.
They can be used for both allowing and blocking stuff.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events