- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
Register HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Good morning, team.
We have a Cluster R81.10, in which, at the moment, we only have the "Firewall" blade working.
For a need of our customer, we need to block "malicious domains (URLs)" that are reporting to us.
Is it advisable and effective to be able to block malicious domains using a firewall rule with a DOMAIN object (FQDN)?
Our intention for the moment is to contain malicious traffic, for the moment the APPC+URLF blades are not yet being worked on due to an internal customer process.
I look forward to your kind comments.
Thank you.
Remember what I said yesterday bro? lol
You do NOT update these things yourself, they are auto-updated every 5 mins actually, so if anything gets added, you dont intervene at all
Andy
[Expert@QUANTUM-MANAGEMENT:0]# ioc_feeds show_interval
Feeds will be fetched every 300 seconds
[Expert@QUANTUM-MANAGEMENT:0]#
Ha, I understand.
It's new to me, this functionality.
I understand that I only need to have Internet access from my GW/Cluster to make this "work well", right?
Those Local* files (that are part of what the json brings) I understand that it is something customized by Checkpoint (I got to believe that you yourself had created it manually) hehehe.
Greetings.
Bro,
No offense, but someone would need to pay me LOT of money to create them myself LOL
Hahaha. 😅
Well, I really "thought" they were files created by you, that's why I had so many doubts.
It is clear to me, that only the output to the Internet from the GW is enough for us.
Now if we are inclined to use the method where the .csv format is used, that would require to enable the AV/ABOT blades, right?
Thanks for the help, friend. 🤓
You can use below to create custom indicators, as described
https://support.checkpoint.com/results/sk/sk132193
That needs av/ab enabled.
You are 100% right, I just verified that av and ab are needed, but ips is not.
Andy
As Phoneboy advised, thats your best bet...OR, you can create new domain based on below and follow steps from sk
Andy
https://support.checkpoint.com/results/sk/sk120633
i have a customer who is using fqdn objects to block bad domains in azure but MS defender is generating alerts that the firewall is trying to reach known bad domains - i believe because its trying to cache resolved IPs for the nefarious domains to apply in policy. Would network feeds and IOCs definitely be a better approach to this? Or DNS sinkhole?
I would say network feeds 100%. I had tested them in the lab and its fantastic. Though if I am not mistaken, you need R81.20 for that.
Andy
Network feeds in R81.20 is an alternate approach.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 9 | |
| 8 | |
| 6 | |
| 6 | |
| 6 | |
| 5 | |
| 5 | |
| 4 | |
| 3 |
Tue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleThu 25 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E10: READY OR NOT: Securing the AI Enterprise 2/5 - AI Red TeamingThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealTue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleThu 25 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E10: READY OR NOT: Securing the AI Enterprise 2/5 - AI Red TeamingTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY