Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
the_rock
Legend
Legend

Network feed

Hey boys and girls,

Happy Friday! Figured would share this, as its super useful, specially for anyone who is not running AV or AB blades on the firewall to block known bad IPs out there. All you do is create new network feed (can only be tested if running R81.20) and then those can be used to block the traffic from those feeds. There are 8 of them and all you do is replace number 1-8 in the link below:

Github link -> https://github.com/stamparm/ipsum

feed example -> https://raw.githubusercontent.com/stamparm/ipsum/master/levels/1.txt

You can create 8 separate network feeds, simply keep replacing numbers sequentially, 1 to 8.

Thanks @delToro1 for sharing this in my other IOC post.

I set it up in my Azure lab and so far, got 140K hits in less than 1 day, that is super impressive even though its Azure, but I got no hosts behind the fw in that lab at all.

Example:

Screenshot_1.png

Thanks a bunch as well to Miroslav Stampar for creating this.

https://github.com/stamparm

 

Best,

 

Andy

(1)
9 Replies
PhoneBoy
Admin
Admin

Nice one!

the_rock
Legend
Legend

Thank you 🙂

0 Kudos
the_rock
Legend
Legend

Btw, just added all 8 feeds to see how many IP addresses were there, showed 234,909 all together, not bad 🙂

Andy

0 Kudos
delToro1
Contributor

So cool!! 😉

the_rock
Legend
Legend

Absolutely!

0 Kudos
the_rock
Legend
Legend

Just to add, I also found below, which probably has millions of bad IP addresses, as it contains LOTS of /16 subnets. I did a search and saw there was 131 entries for /16, so right there thats 8.5 million, plus remaining /21,/22,/23,/17 etc...would not be surprised its close to 15 M all together.

https://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt

Best,

Andy

0 Kudos
Scottc98
Advisor

@the_rock    What is the result if the feed in question on your block rule contains no entries at all (i.e. the feed source becomes empty and the previous cached files on the GW is cleared)?    Does it result in no matches and therefore nothing will hit it?      More fearful of some situation where it starts blocking more than it should be 🙂  

 

 

0 Kudos
the_rock
Legend
Legend

I noticed one in my lab with no entries, but had not seen any such issues as of yet, what you described.

Andy

0 Kudos
the_rock
Legend
Legend

One thing I will say though, as a word of caution, though those feeds block BUNCH of bad IPs, but it could happen that something is blocked inadvertently where people may need access to the cloud portal. In my experience, its not often, but there is a chance for it.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events