Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
eliadcourt
Participant
Jump to solution

Blocking TOR dynamically on Maestro + VSX

Hi everyone.

 

I wish to block TOR using the list published by CP.

AFAIU, my options are:
1. Network feeds.
2. IOC feeds.
3. Dynamic object.

Network feeds isn't supported on VSX - sk79700.

As for IOC feeds, I had a hard time figuring out if it's supported.
I tried using it, but I couldn't do "Test Feed", as it didn't recognize any FW object.
I've added the object anyway, and installed policy.
Under the new object I don't see any observables.
In CLI, ioc_feeds doesn't show anything.

If I try adding through ioc_feeds, it says it's missing the AV-AB blades, even though they are installed.
We had some weird issue I can't remember right now, that these blades didn't work properly because it needed them to be active on the VS 0 as well.

Last is dynamic object, but building some mechanism is a bit to time consuming right now.

 

Any thoughts?

0 Kudos
2 Solutions

Accepted Solutions
Wolfgang
Authority
Authority

@eliadcourt  following sk79700, IOC feeds are supported with VSX, only network feeds not.

View solution in original post

PhoneBoy
Admin
Admin

And specifically, it's the "test" functionality that doesn't work.
If you have a non-VSX gateway to validate the feed on, it should work on VSX. 

View solution in original post

4 Replies
Tal_Paz-Fridman
Employee
Employee

According to the SK for IOC the following is supported:

  • Only these versions for Scalable Platforms (Maestro and Chassis) support IoC feeds:

 

https://support.checkpoint.com/results/sk/sk132193

 

0 Kudos
eliadcourt
Participant

Yeah, sorry, forgot to mention.
We have 81.20 jhf 84 on th SGMs., and jhf 65 on the MGMT.

0 Kudos
Wolfgang
Authority
Authority

@eliadcourt  following sk79700, IOC feeds are supported with VSX, only network feeds not.

PhoneBoy
Admin
Admin

And specifically, it's the "test" functionality that doesn't work.
If you have a non-VSX gateway to validate the feed on, it should work on VSX.