- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Dear All,
We have Check Point R81.10 security gateways, and we want to automate the blocking of malicious IPs and URLs gathered by the SOC team. We want the SOC team to add the malicious IPs and URLs to a separate server in a text file, and then we will link these files to our gateways using the IOC. Is there any documentation available that can help me achieve this?
Thanks
Just to update, I did remote session with @Ihenock1011 and his colleague and I showed them exactly what I have configured in the lab, as well as good reference below:
https://support.checkpoint.com/results/sk/sk132193
Once again, as we discussed, please try upgrade to R81.20, as its recommended anyway and also, below are all the links I sent before, including new one we tested today.
Andy
ioc indicators links:
http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt
https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt
https://github.com/firehol/blocklist-ipsets
https://www.misp-project.org/feeds/
K, sounds good. I sort of figured that was the case, just wanted to clarify.
Thank you as always 🙂
Andy
This is covered in the Threat Prevention Admin Guide for the version. e.g.
Is there a particular issue that you're facing here or a unique requirement?
If you have a significant number of IoCs, I highly recommend upgrading to R81.20.
You also have Network Feed objects in R81.20, which allow for more flexible reporting and Network Feed objects can be directly used in the Access Policy.
This is also a good reference SK: sk132193
What I didn't get from the SK is
How do I make the gateways refer to the CSV file?
Where should I put the CSV file, either on a file server or any server?
Lastly, can you share with me a sample CSV file that contains both optional and mandatory fields?
I can send you one tomorrow, as well as example of some fqdn's you can use, and best thing about is that they are dynamically updated. And yes, I agree with Phoneboy, R81.20 is the way to go if you plan to use this feature.
Best,
Andy
Hey mate,
As promised, here it is. Attached the screenshot, as well as the file.
Let me know if you are not clear and happy to do remote and show you my lab. Remember, you need EITHER av OR ab blade enabled for this to work.
Andy
http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt
https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt
https://github.com/firehol/blocklist-ipsets
@the_rock Thanks a lot!
Hope that was useful info? If not, let me know, we can do remote and I can show you more in my lab.
Best,
Andy
@the_rockThat was helpful! If we could do a remote session, it would be much better for me. I could then clear up a lot of things.
Sure, what time zone you in?
Andy
GMT+3 EAT 8:00AM-12:00PM or 2:00PMto 5:00PM will be best.
So its 2.35 pm now for you?
Yes
K, messaged you offline
Just to update, I did remote session with @Ihenock1011 and his colleague and I showed them exactly what I have configured in the lab, as well as good reference below:
https://support.checkpoint.com/results/sk/sk132193
Once again, as we discussed, please try upgrade to R81.20, as its recommended anyway and also, below are all the links I sent before, including new one we tested today.
Andy
ioc indicators links:
http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt
https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt
https://github.com/firehol/blocklist-ipsets
https://www.misp-project.org/feeds/
Hey boys,
Just a quick question...any idea if Check Point has recommended link of bad IP addresses that get updated automatically or is this more up to customer to find and use at their discretion?
Best,
Andy
I see links in the sk below, but not sure if there is anything else or not...
https://support.checkpoint.com/results/sk/sk132193
Okay, you you looked into sk132193. There are many free and commercial IoCs from different sources, but I am not aware of anything Check Point would consider recommended per se.
The lists are quite different and vary per industry.
K, sounds good. I sort of figured that was the case, just wanted to clarify.
Thank you as always 🙂
Andy
Did you try test feed before adding them as Indicators though? I;ve tried and says "test failed. No data was found in the feed".
Gateway has connectivity to site.
I did. yes.
Well, for some reason my gateway shows that error message. Is there a difference between adding these feeds under Indicators vs using a Network feed object and placing it as src & dst in a Threat prevention policy?
I only tested this on R82 latest jumbo, but dont think it makes any difference.
Indicators are primarily for Threat Prevention purposes.
The file format is specific (CSV).
Network Feed objects can be used for Threat Prevention, but they are mainly for Access Control.
The file format can either be a flat file (one indicator per line) or parseable JSON.
They are different files and use a different validation process.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY