- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Introducing Check Point Quantum Spark 2500:
Smarter Security, Faster Connectivity, and Simpler MSP Management!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Dear All,
We have Check Point R81.10 security gateways, and we want to automate the blocking of malicious IPs and URLs gathered by the SOC team. We want the SOC team to add the malicious IPs and URLs to a separate server in a text file, and then we will link these files to our gateways using the IOC. Is there any documentation available that can help me achieve this?
Thanks
Just to update, I did remote session with @Ihenock1011 and his colleague and I showed them exactly what I have configured in the lab, as well as good reference below:
https://support.checkpoint.com/results/sk/sk132193
Once again, as we discussed, please try upgrade to R81.20, as its recommended anyway and also, below are all the links I sent before, including new one we tested today.
Andy
ioc indicators links:
http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt
https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt
https://github.com/firehol/blocklist-ipsets
https://www.misp-project.org/feeds/
K, sounds good. I sort of figured that was the case, just wanted to clarify.
Thank you as always 🙂
Andy
This is covered in the Threat Prevention Admin Guide for the version. e.g.
Is there a particular issue that you're facing here or a unique requirement?
If you have a significant number of IoCs, I highly recommend upgrading to R81.20.
You also have Network Feed objects in R81.20, which allow for more flexible reporting and Network Feed objects can be directly used in the Access Policy.
This is also a good reference SK: sk132193
What I didn't get from the SK is
How do I make the gateways refer to the CSV file?
Where should I put the CSV file, either on a file server or any server?
Lastly, can you share with me a sample CSV file that contains both optional and mandatory fields?
I can send you one tomorrow, as well as example of some fqdn's you can use, and best thing about is that they are dynamically updated. And yes, I agree with Phoneboy, R81.20 is the way to go if you plan to use this feature.
Best,
Andy
Hey mate,
As promised, here it is. Attached the screenshot, as well as the file.
Let me know if you are not clear and happy to do remote and show you my lab. Remember, you need EITHER av OR ab blade enabled for this to work.
Andy
http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt
https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt
https://github.com/firehol/blocklist-ipsets
@the_rock Thanks a lot!
Hope that was useful info? If not, let me know, we can do remote and I can show you more in my lab.
Best,
Andy
@the_rockThat was helpful! If we could do a remote session, it would be much better for me. I could then clear up a lot of things.
Sure, what time zone you in?
Andy
GMT+3 EAT 8:00AM-12:00PM or 2:00PMto 5:00PM will be best.
So its 2.35 pm now for you?
Yes
K, messaged you offline
Just to update, I did remote session with @Ihenock1011 and his colleague and I showed them exactly what I have configured in the lab, as well as good reference below:
https://support.checkpoint.com/results/sk/sk132193
Once again, as we discussed, please try upgrade to R81.20, as its recommended anyway and also, below are all the links I sent before, including new one we tested today.
Andy
ioc indicators links:
http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt
https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt
https://github.com/firehol/blocklist-ipsets
https://www.misp-project.org/feeds/
Hey boys,
Just a quick question...any idea if Check Point has recommended link of bad IP addresses that get updated automatically or is this more up to customer to find and use at their discretion?
Best,
Andy
I see links in the sk below, but not sure if there is anything else or not...
https://support.checkpoint.com/results/sk/sk132193
Okay, you you looked into sk132193. There are many free and commercial IoCs from different sources, but I am not aware of anything Check Point would consider recommended per se.
The lists are quite different and vary per industry.
K, sounds good. I sort of figured that was the case, just wanted to clarify.
Thank you as always 🙂
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
2 | |
1 |
Wed 10 Sep 2025 @ 11:00 AM (CEST)
Effortless Web Application & API Security with AI-Powered WAF, an intro to CloudGuard WAFWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY