Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
mahesh
Explorer

406-Not acceptable error while testing external IOC feed in VSX environment

Getting 406-Not acceptable error while testing external IOC feed in VSX environment. Screenshot attached.

Usually 406 errors means server is unable to accept client's request. Does this mean it is an issue with the server where the feed is hosted ?

We are able to get the ip's when we try the same url in browser and curl connectivity also works fine.

We are using the same feed in Palo Alto firewall and it works fine over there.

Also, I got to know from below sk that vsx gateways are not supported but there is a confusion whether it indicates TOR list or IOC feed.

https://support.checkpoint.com/results/sk/sk103154

Tried custom csv file and able to block the ip's successfully.

Can someone assist here ?

Thanks in advance.

 

0 Kudos
4 Replies
PhoneBoy
Admin
Admin

Version/JHF of gateway and management?
Note that the mechanism used in sk103154 is different from either of the following:

It's not clear from your description which method you're using here.
I do know that testing a Network Feed from a VSX VS will not work, see: https://community.checkpoint.com/t5/General-Topics/Network-Feeds-and-VSX/m-p/212877/highlight/true#M... 
Not sure this applies to Threat Intelligence Feeds or not.

Both should work on VSX, though (absent the "testing" function).

0 Kudos
mahesh
Explorer

Hello @PhoneBoy,

Thanks for the reply.

We are using R81.10 take 139 Vsx gateway and adding external IOC feed.

As per the community article shared by you, testing the IOC feed in vsx gateways is not supported but we can test the feed in normal gateway and use it in VSX gateways to block the ip's.

I have tested the feed in normal Quantum security gateway which was successful  and added the same feed in VSX gateway but unable to block the ip's present in the feed. No logs observed either when we try to ping the ip's.

Instead the ip's are getting blocked by the access rule configured and not using IOC feed.

Hope the requirement is clear.

Thanks.

0 Kudos
PhoneBoy
Admin
Admin

Best to consult with TAC here: https://help.checkpoint.com 

0 Kudos
the_rock
Legend
Legend

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events