- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Got the request to block Tor nodes on a R81.10 environment.
First thought was the Updatable Objects, which felt to me like a logical place. Unfortunately Tor is not there.
Found SK 103154 - https://support.checkpoint.com/results/sk/sk103154 which suggests using the Generic Data Center object, it also gives a Check Point maintained online list https://secureupdates.checkpoint.com/IP-list/TOR.txt so this felt like the solution.
But that Check Point list is a plain text list and Generic Data Center object requires JSON format.
Apparently I wasn't the first with this problem as I found this script which glues everything together: https://github.com/HGrigorov/checkpoint/blob/main/tor2json
Which is a solution but at two points I feel Check Point is missing a chance to make this so much more user friendly.
1 - Why is that Tor list not in the Updatable Objects? Seen that asked before in 2020 also.
2 - Why is that Tor list not available as a JSON file for a Generic Data Center object (specially as it is mentioned in that SK as a solution for this sitation)?
I block TOR nodes using the external IOC feeds in R81.10.
The only way to use this file currently is with the Custom Intelligence Feeds options (ioc_feeds).
It cannot be used in either Generic Datacenter Objects or Network Feeds without some modification.
The sk has been updated accordingly.
We are also looking at adding it as an Updatable Object.
Upgrade to R81.20 and use Network Feeds, which should be able to read/use this file as-is.
I block TOR nodes using the external IOC feeds in R81.10.
Same here.
Andy
Thanks for the quick replies all.
I dont fully agree that upgrading is easy, the external IOC feed seems interesting although in another module. might be good to add to the SK which lists all the options.
And of course Check Point could just add it to updatable objects 😉
I have json file you can use to create generic data object, which can be then used in policy to block known bad IPs and it gets updated every 300 seconds (5 mins)
Andy
The only way to use this file currently is with the Custom Intelligence Feeds options (ioc_feeds).
It cannot be used in either Generic Datacenter Objects or Network Feeds without some modification.
The sk has been updated accordingly.
We are also looking at adding it as an Updatable Object.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 15 | |
| 11 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY