Hi Matt,
In R80.20 it is more effective to do this with the following command on SecureXL level. You may have to build a small script yourself. I'll be creating a script in the next few days.
The blacklist blocks all traffic to and from the specified IP addresses.
The blacklist drops occur in SecureXL, which is more efficient than an Access Control Policy to drop the packets.
This can be very helpful e.g. with DoS attacks to block an IP on SecureXL level.
# fwaccel dos blacklist -a <ip>
# fwaccel dos blacklist -s
# fwaccel dos blacklist -d <ip>
More see here:
R80.20 - IP blacklist in SecureXL
Regards
Heiko
➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips