- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Good morning, team.
We have a Cluster R81.10, in which, at the moment, we only have the "Firewall" blade working.
For a need of our customer, we need to block "malicious domains (URLs)" that are reporting to us.
Is it advisable and effective to be able to block malicious domains using a firewall rule with a DOMAIN object (FQDN)?
Our intention for the moment is to contain malicious traffic, for the moment the APPC+URLF blades are not yet being worked on due to an internal customer process.
I look forward to your kind comments.
Thank you.
Remember what I said yesterday bro? lol
You do NOT update these things yourself, they are auto-updated every 5 mins actually, so if anything gets added, you dont intervene at all
Andy
[Expert@QUANTUM-MANAGEMENT:0]# ioc_feeds show_interval
Feeds will be fetched every 300 seconds
[Expert@QUANTUM-MANAGEMENT:0]#
Ha, I understand.
It's new to me, this functionality.
I understand that I only need to have Internet access from my GW/Cluster to make this "work well", right?
Those Local* files (that are part of what the json brings) I understand that it is something customized by Checkpoint (I got to believe that you yourself had created it manually) hehehe.
Greetings.
Bro,
No offense, but someone would need to pay me LOT of money to create them myself LOL
Hahaha. 😅
Well, I really "thought" they were files created by you, that's why I had so many doubts.
It is clear to me, that only the output to the Internet from the GW is enough for us.
Now if we are inclined to use the method where the .csv format is used, that would require to enable the AV/ABOT blades, right?
Thanks for the help, friend. 🤓
You can use below to create custom indicators, as described
https://support.checkpoint.com/results/sk/sk132193
That needs av/ab enabled.
You are 100% right, I just verified that av and ab are needed, but ips is not.
Andy
As Phoneboy advised, thats your best bet...OR, you can create new domain based on below and follow steps from sk
Andy
https://support.checkpoint.com/results/sk/sk120633
i have a customer who is using fqdn objects to block bad domains in azure but MS defender is generating alerts that the firewall is trying to reach known bad domains - i believe because its trying to cache resolved IPs for the nefarious domains to apply in policy. Would network feeds and IOCs definitely be a better approach to this? Or DNS sinkhole?
I would say network feeds 100%. I had tested them in the lab and its fantastic. Though if I am not mistaken, you need R81.20 for that.
Andy
Network feeds in R81.20 is an alternate approach.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 36 | |
| 16 | |
| 8 | |
| 7 | |
| 7 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY