- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Got the request to block Tor nodes on a R81.10 environment.
First thought was the Updatable Objects, which felt to me like a logical place. Unfortunately Tor is not there.
Found SK 103154 - https://support.checkpoint.com/results/sk/sk103154 which suggests using the Generic Data Center object, it also gives a Check Point maintained online list https://secureupdates.checkpoint.com/IP-list/TOR.txt so this felt like the solution.
But that Check Point list is a plain text list and Generic Data Center object requires JSON format.
Apparently I wasn't the first with this problem as I found this script which glues everything together: https://github.com/HGrigorov/checkpoint/blob/main/tor2json
Which is a solution but at two points I feel Check Point is missing a chance to make this so much more user friendly.
1 - Why is that Tor list not in the Updatable Objects? Seen that asked before in 2020 also.
2 - Why is that Tor list not available as a JSON file for a Generic Data Center object (specially as it is mentioned in that SK as a solution for this sitation)?
I block TOR nodes using the external IOC feeds in R81.10.
The only way to use this file currently is with the Custom Intelligence Feeds options (ioc_feeds).
It cannot be used in either Generic Datacenter Objects or Network Feeds without some modification.
The sk has been updated accordingly.
We are also looking at adding it as an Updatable Object.
Upgrade to R81.20 and use Network Feeds, which should be able to read/use this file as-is.
I block TOR nodes using the external IOC feeds in R81.10.
Same here.
Andy
Thanks for the quick replies all.
I dont fully agree that upgrading is easy, the external IOC feed seems interesting although in another module. might be good to add to the SK which lists all the options.
And of course Check Point could just add it to updatable objects 😉
I have json file you can use to create generic data object, which can be then used in policy to block known bad IPs and it gets updated every 300 seconds (5 mins)
Andy
The only way to use this file currently is with the Custom Intelligence Feeds options (ioc_feeds).
It cannot be used in either Generic Datacenter Objects or Network Feeds without some modification.
The sk has been updated accordingly.
We are also looking at adding it as an Updatable Object.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 15 | |
| 9 | |
| 8 | |
| 8 | |
| 8 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 3 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY