I have. This happens very frequently and there is an SK with the past issues documented. Majority of which are related to the DShield certificate. It usually takes a month or two for R&D to fix the problem. They first say no one has reported an issue, most likely because a lot of ppl do not forward their gateways syslog to a SIEM. The best way to really tell if the feed is failing is if you look at the systems OS logs.
We are planning on foregoing the Dshield IPS rule. Instead we will import the blocklist automatically with the checkpoint threat feed script that utilizes Sam rules. This will pull from a local server that pulls the Dshield list from the Dshield website.
Ryan St. Germain
- From Mobile