- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: How to Block TOR NODE is Checkpoint Firewall R...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to Block TOR NODE is Checkpoint Firewall R80.30 Version
Dear @PhoneBoy
Please help me to Block the TOR node in checkpoint firewall which is running on R80.30 version.
We want to follow step:4 from the link below. But i could not find same configuration in the file IP-blacklist.sh and ip_block.sh in R80.30 version firewall.
we want to block all the IP's in the below
https://secureupdates.checkpoint.com/IP-list/TOR.txt
Thank you for you kind co-operation
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Have you actually tried them and what were the precise results?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
like suggested on step:4 of below link
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
on the step:3 on the link below there is a scrip to download and that script has not mention the OS version of r80.30
I have attached the screenshot herewith
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Try the scripts.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dear @PhoneBoy
Actually, it the requirement of the customer and i have tried this even in the customer environment, but when i go through the script in r80.30. The given SK doesn't match at all. The script are different in R80.30 then what is said in the SK.
So Maybe, the SK need to be updated or there should be different SK for Newer Version so that we can't be confuse. It will help us understand easier and help us to configure in simple way.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please clarify this point.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So, If i dont modify the script as suggested by the SK and just run the default script which is already there in r80.30 version
Does it block the same IP's from the below link
https://secureupdates.checkpoint.com/IP-list/TOR.txt
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The downloaded script should run as is.
However, you have to follow the instructions in the Step 3 of sk103154 to ensure that it's going to use the TOR list we maintain.
The modifications mentioned in Step 4 of the SK do not need to be done, and in fact, look wrong or maybe even inappropriate, at least in R80.40.
@Ronen_Zel can you have someone look at this?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We did look into sk103154 and consulted R&D about this. Their reply was:
These are not steps, these are separate independent sections and as it says in the beginning of section [4]:
Important Notes:
- It is recommended to use the solution from section "(3) How to block traffic from custom IP feeds (managed from Management Server)" with the Check Point's feed database https://secureupdates.checkpoint.com/IP-list/TOR.txt.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks @PhoneBoy Thanks @Ronen_Zel
I will try with step:3 only and update you about this. Thanks for your support.
