- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi Everyone
How to upload bulk updates of IOC URL file in checkpoint firewall instead of manual update one by one url
In Palo-alto firewall EDL option for Bulk update 10,000 IP Address
In checkpoint gateway is there any option similar like EDL if avail, guide the process
Regards,
Chiranjeevi
That works if the feed is published by some web server. If it's a file on a local machine and you don't have it on a web server the firewalls can access, the management API will still work.
Hello mate,
Review that post about IOCs: https://community.checkpoint.com/t5/Security-Gateways/IOC-feeds/m-p/212021#M40210
BR.
Always funny to see my own post lol. Anyway, I think thats best method I found so far, but if anyone has better one, be free to share.
Andy
That works if the feed is published by some web server. If it's a file on a local machine and you don't have it on a web server the firewalls can access, the management API will still work.
I would probably use the management API to make a series of Application/Site objects (Ideally around 200 domains per object) which you then stick in an Application/Site Group object or an Application/Site Category. You can use an existing category like "Critical Risk". This can only filter HTTP-like traffic, so if you need to filter SSH, it won't work. It requires either HTTPS Inspection or the "Categorize HTTPS sites" setting to be enabled. Depending on how the objects are made, they may match more traffic than intended (for example, blocking *.ar could block a file named 32x32.left.arrow.png). I did some match expression testing last year, which can help create specific matching expressions.
If R81.20, you can use Network Feeds, which can be used in both Access Control and Threat Prevention policies.
See: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuid...
For earlier releases, you're probably looking at using ioc_feeds.
However, if you are importing a lot of IoCs, you should really upgrade to R81.20 as the infrastructure for this has improved dramatically.
We've tested ~2 million IoCs and had no issues.
The limit in R81.10 and earlier is...much lower.
Im "throwing" another post of mine then lol
https://community.checkpoint.com/t5/Security-Gateways/Network-feed/m-p/212407#M40317
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 20 | |
| 8 | |
| 7 | |
| 7 | |
| 4 | |
| 4 | |
| 3 | |
| 2 | |
| 2 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY