Importing External Custom Intelligence Feeds
Custom Intelligence Feeds lets you fetch feeds from a third-party server directly to the Security Gateway to be enforced by the Anti-Virus
Software Blade on a Check Point Firewall that uses real-time virus signatures and anomaly-based protections from ThreatCloud to detect and block malware at the Check Point Firewall before users are affected. Acronym: AV., Anti-Bot
Software Blade on a Check Point Firewall that blocks botnet behavior and communication to Command and Control (C&C) centers. Acronyms: AB, ABOT. and IPS
Software Blade on a Check Point Firewall that inspects and analyzes packets and data for numerous types of risks (Intrusion Prevention System). blades. The Custom Intelligence Feeds feature helps you manage and monitor indicators with minimum operational overhead.
Starting from R81.20, the Check PointSecurity Gateway supports at least 2 million patterns/observables for these observable types: URL, Domain, IP addresses, and Hashes. The maximum number of supported patterns/observables is limited by the available memory and disk space on the Security Gateway. Before the Security Gateway loads more patterns/observables, it checks if 50% of the total memory is free.
Enforcement and Policy Behavior
-
The Threat Prevention policy does not control feeds enforcement.
-
Policy installation does not fail if a Security Gateway cannot fetch a feed.
In this case, the Security Gateway generates a control log.