- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Re: Checkpoint r80.10 block ip feed and send logs ...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Checkpoint r80.10 block ip feed and send logs to rsyslog server
Hello! Could you help me please? i'm testing checkpoint security gateway with gaia 80.10. I have ip feed which is updating every few hours and want to block ips from this feed.
I already configured checkpoint with nat, created host behind nat with local ip and tried to make what i need with this article:
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
but i cant download scripts cause i dont have valid subscriptions, just want to test
i've done scripts like TOR blocking script but with my own ip feed and url.
samp policy adds my ip feed but checkpoint not blocking those ips and no logs about deny or allow traffic in smartview and smartconsole.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
But if you're generating your own IOC feed, you should be using the Custom Intelligence Feeds option: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you, seems that it is what i need, but when i trying to install hotfix with ioc_feeds i got
Reason of failure: The package is not compatible to install - A fix conflict was detected during pre-install validation.
To prevent system instability, installation will not continue.
Please contact Check Point support with the following information:
Package: Check_Point_R80.10_JHF_T121_Hotfix_sk132193_FULL.tgz
conflicts with the following hotfixes:
R80.10 Jumbo Hotfix Accumulator General Availability (Take 189)
R80_10_New_Image
For more information - see log files:
/opt/CPInstLog/CRSValidator_fw1_wrapper_R80_10_JHF_T121_564.log
