- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- DShield Blocklist download failing
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
DShield Blocklist download failing
Anyone else having issues with their gateways downloading the DShield block list? Appears the SSL cert for the website was re-issued/renewed last week, which is most likely the culprit.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Have you, by chance, contacted the TAC about this?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have. This happens very frequently and there is an SK with the past issues documented. Majority of which are related to the DShield certificate. It usually takes a month or two for R&D to fix the problem. They first say no one has reported an issue, most likely because a lot of ppl do not forward their gateways syslog to a SIEM. The best way to really tell if the feed is failing is if you look at the systems OS logs.
We are planning on foregoing the Dshield IPS rule. Instead we will import the blocklist automatically with the checkpoint threat feed script that utilizes Sam rules. This will pull from a local server that pulls the Dshield list from the Dshield website.
Ryan St. Germain
- From Mobile
