We would like to use the "indicators" option in Threat Prevention policy and create an External IOC feed object pointing to a file with IP addresses only, one per line.
In specific, we would like to use Talos IP blacklist, for a start ( http://www.talosintelligence.com/documents/ip-blacklist )
First of all, I would like to ask if this is possible through Smartconsole. Documentation mentions that feeds which do not match Checkpoint's format, cannot be used in Smartconsole.
Secondly, if the above is possible, is there any documentation on how to fill up the "Custom feed settings"? In our case with an IP address file, I assume that we choose "type: IP address" on the dropdown menu and leave the "ignore lines that start with:" and "fields delimeter:" fields as blank.
What about the "Fields to column number mappings" section? "Value:" field cannot be empty. I guess that since I have "one column" in the file, shall I use "1" in that field?
Please be also informed of the versions in our environment.
Management server: R81.10, jhf 30
Security gateways: R80.30, most in jhf 237
Thank you in advance!