- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: Problem with fetching Malicious IP feeds using...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Problem with fetching Malicious IP feeds using sk103154
Hi,
Trying to block incoming traffic from Malicious IPs using: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
This is Section [3] How to block traffic from custom IP feeds (managed from Management Server)
It seems to work ok for: https://secureupdates.checkpoint.com/IP-list/TOR.txt as I can see the following output on the Gateway:
operation=add uid=<5f85babb,000005d7,f102020a,0000132f> target=all timeout=3575 action=drop log=log comment=threatcloud_ip_block service=any source=range:199.249.230.165 pkt-rate=0 req_type=quota
operation=add uid=<5f85babb,000005d9,f102020a,0000132f> target=all timeout=3575 action=drop log=log comment=threatcloud_ip_block service=any source=range:199.249.230.167 pkt-rate=0 req_type=quota
operation=add uid=<5f85babb,000005da,f102020a,0000132f> target=all timeout=3575 action=drop log=log comment=threatcloud_ip_block service=any source=range:158.69.63.54 pkt-rate=0 req_type=quota
when issuing: fw samp get | grep threatcloud_ip_block
Subsequently I have tried adding other feeds in there, but I don't see any new rules created as above. Examples:
http://www.talosintelligence.com/documents/ip-blacklist
https://api.blocklist.de/getlast.php?time=600
Any idea on how to troubleshoot this?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Are you using ioc_feeds or something else?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I am using the method described in sk103154 Section 3. Not using ioc_feeds commands but scripts.
