Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
the_rock
MVP Gold
MVP Gold

Network feed

Hey boys and girls,

Happy Friday! Figured would share this, as its super useful, specially for anyone who is not running AV or AB blades on the firewall to block known bad IPs out there. All you do is create new network feed (can only be tested if running R81.20) and then those can be used to block the traffic from those feeds. There are 8 of them and all you do is replace number 1-8 in the link below:

Github link -> https://github.com/stamparm/ipsum

feed example -> https://raw.githubusercontent.com/stamparm/ipsum/master/levels/1.txt

You can create 8 separate network feeds, simply keep replacing numbers sequentially, 1 to 8.

Thanks @delToro1 for sharing this in my other IOC post.

I set it up in my Azure lab and so far, got 140K hits in less than 1 day, that is super impressive even though its Azure, but I got no hosts behind the fw in that lab at all.

Example:

Screenshot_1.png

Thanks a bunch as well to Miroslav Stampar for creating this.

https://github.com/stamparm

https://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt

 

IMPORTANT NOTE:

PLEASE DONT USE EMERG AND SAMPARM FEED 1 TO BEGIN WITH, since I had few customers having issues with those feeds. Samparm 2-8 are fine, no issues.

 

Best,

 

Andy

(1)
41 Replies
the_rock
MVP Gold
MVP Gold

You got it, thats right.

Andy

0 Kudos
the_rock
MVP Gold
MVP Gold

Latest update with lots of links available for net feeds.

Andy

https://github.com/Bert-JanP/Open-Source-Threat-Intel-Feeds?tab=readme-ov-file

0 Kudos
the_rock
MVP Gold
MVP Gold

Hey guys,

I know post is more than a year old, but found another feed that has probably around 15 mil entried, same as emerg threat one, so be careful if you do decide to use it.

Andy

https://www.spamhaus.org/drop/drop.txt

reference:

http://iplists.firehol.org/

0 Kudos
Matlu
MVP Silver
MVP Silver

Bro,

Have you used an internal server as a “source” to block IPs that “escape” from public Internet sources?

Is it possible to do this?

I have several IPs that I can't find in any of the public sources, and I want to know if we can integrate a Windows/Linux-type server to add the new IPs we need there.

Cheers

0 Kudos
the_rock
MVP Gold
MVP Gold

O yea, worked in my lab just fine.

Andy

0 Kudos
Matlu
MVP Silver
MVP Silver

Can you share an image of how you have configured your server in SmartConsole to achieve this goal, please?

Are you using Windows/Linux?

Do you need a license for this?

Cheers

0 Kudos
the_rock
MVP Gold
MVP Gold

I dont have that server online any more, but literally rule would be that server as source, net feeds as dst, block and then same rule, just other way around, You got my email, be free to message me offline, we can connect that way.

Andy

0 Kudos
the_rock
MVP Gold
MVP Gold

Bro, what exactly was failing for this? Do you have any relevant logs, captures?

Andy

0 Kudos
Matlu
MVP Silver
MVP Silver

Hey
Not exactly.

We want to implement it for the first time because we need to generate massive blocks of IPs and domains with a bad reputation.

In many public sources, our IPs and domains reported by our Monitoring area do not appear, so we want to “optimize” this block.

We want to know if we need a “special” license to use Network Feed, and if we can use a Windows Server, where we can include the txt files (one for IPs and another for domains).

0 Kudos
the_rock
MVP Gold
MVP Gold

Nope, you do NOT need any special license to use it. I have eval in my labs and I have used net feeds for some time, no problems.

Andy

0 Kudos
the_rock
MVP Gold
MVP Gold

Bro, I messaged you offline about this.

Andy

0 Kudos
PhoneBoy
Admin
Admin

Network Feed is considered a basic firewall feature and does not require a specific license.
Refer to the documentation for more details: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuid... 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events