Importing External Custom Intelligence Feeds

Custom Intelligence Feeds lets you fetch feeds from a third-party server directly to the Security Gateway to be enforced by the Anti-VirusClosed Software Blade on a Check Point Firewall that uses real-time virus signatures and anomaly-based protections from ThreatCloud to detect and block malware at the Check Point Firewall before users are affected. Acronym: AV., Anti-BotClosed Software Blade on a Check Point Firewall that blocks botnet behavior and communication to Command and Control (C&C) centers. Acronyms: AB, ABOT. and IPSClosed Software Blade on a Check Point Firewall that inspects and analyzes packets and data for numerous types of risks (Intrusion Prevention System). blades. The Custom Intelligence Feeds feature helps you manage and monitor indicators with minimum operational overhead.

Starting from R81.20, the Check PointSecurity Gateway supports at least 2 million patterns/observables for these observable types: URL, Domain, IP addresses, and Hashes. The maximum number of supported patterns/observables is limited by the available memory and disk space on the Security Gateway. Before the Security Gateway loads more patterns/observables, it checks if 50% of the total memory is free.

Enforcement and Policy Behavior