Importing External Custom Intelligence Feeds in SmartConsole

Step

Instructions

1

In SmartConsoleClosed Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on., go to the applicable Threat Prevention profile > Indicators > Activation > make sure that Enable indicator scanning is selected.

2

In SmartConsole, go to Security Policies > Threat Prevention > Custom Policy > Custom Policy Tools > Indicators.

 

If you are working with Autonomous Threat Prevention, go to Security Policies > Threat Prevention > Autonomous Policy > Autonomous Policy Tools > Indicators.

3

Click New and select New IoC Feed.

The New IoC Feed configuration window opens.

4

In the top field, enter a unique object name.

5

In the Action field, select the applicable action:

6

In the Feed URL field, enter the full URL that starts with http:// or https://.

7

From the Format drop-down menu, select the applicable format (see sk132193):

8

Expand the Advanced section (click the ^ icon on the right side).

9

In the Authentication section, enter the applicable username and password, if the external feed requires authentication.

10

In the Network section, select Use gateway proxy for connection, if the Security GatewayClosed Dedicated Check Point server that runs Check Point software to inspect traffic and enforce Security Policies for connected network resources. must connect to the external feed through a proxy server.

11

Make sure the Security Gateways can get this feed:

  1. Click Test Feed.

  2. From the Select the Security Gateway drop-down menu, select the applicable Security Gateway or Security ClusterClosed Two or more Security Gateways that work together in a redundant configuration - High Availability, or Load Sharing..

    Note - Starting from R82 Jumbo Hotfix Accumulator Take 103, you can test the feed on all individual Cluster Members or on the cluster virtual IP address. This feature is available for all clusters types except VSXClosed Virtual System Extension. Check Point virtual networking solution, hosted on a computer or cluster with virtual abstractions of Check Point Security Gateways and other network devices. These Virtual Devices provide the same functionality as their physical counterparts. Cluster.

  3. Click Test Feed.

  4. Click Close.

Note - The Select the Security Gateway menu does not show Virtual Switches.

12

Click OK.

The new indicator appears on the Indicators page.

13

The Security Gateway fetches the configured feeds every 30 minutes and enforce them immediately.

To change the fetching interval:

  1. From the left navigation panel, click Manage & Settings. > Blades > Threat Prevention > Advanced Settings.

  2. From the left tree, click External Feed.

  3. Configure the applicable interval.

  4. Click OK.

14

Install the Threat Prevention Policy.