CPUG: The Check Point User Group

Resources for the Check Point Community, by the Check Point Community.


First, I hope you're all well and staying safe.
Second, I want to give a "heads up" that you should see more activity here shortly, and maybe a few cosmetic changes.
I'll post more details to the "Announcements" forum soon, so be on the lookout. -E

 

Results 1 to 3 of 3

Thread: SANS ISC/DShield Block List Not Updating, Check Point Seems To Have Trouble Resolving

  1. #1
    Join Date
    2007-10-31
    Location
    Great Plains - USA
    Posts
    161
    Rep Power
    16

    Default SANS ISC/DShield Block List Not Updating, Check Point Seems To Have Trouble Resolving

    R77.30 in impacted environment, SMS Smart-1 225 and 5800 HA Clusters.

    On April 5 SANS moved to a new TLS certificate and removed support for TLS 1.0, since that time the DShield block list has stopped updating. https://isc.sans.edu/forums/diary/IS...Updates/23521/

    We worked with our 3rd party support vendor on the issue, they then escalated to Check Point in mid-May, 12th or 13th I recall. Initial response from CP was sk21534, which we thoroughly covered with 3rd party support. After some back and forth we're informed on May 17 that "There is an issue that is happening to multiple customer and there is a fix that will be integrated with the R80.10 JHF. We are currently verifying if this will also be included on the JHF for R77.30."

    Now almost a month later and CP is still in the testing phase with the R77.30 HotFix. Very disappointing from my point of view.

    Are others here still using DShield? Is DShield integrated into Anti-Bot (which we have enabled) and thus redundant?
    Last edited by dbrown3611; 2018-06-11 at 12:16. Reason: Add SANS URL.

  2. #2
    Join Date
    2012-08-16
    Posts
    182
    Rep Power
    11

    Default Re: SANS ISC/DShield Block List Not Updating, Check Point Seems To Have Trouble Resol

    I stopped using the Check Point version with Dynamic Objects and instead implemented the CPDBL.net method

    https://www.cpug.org/forums/showthre...ic-block-lists

  3. #3
    Join Date
    2007-10-31
    Location
    Great Plains - USA
    Posts
    161
    Rep Power
    16

    Default Re: SANS ISC/DShield Block List Not Updating, Check Point Seems To Have Trouble Resol

    Quote Originally Posted by aweldon View Post
    I stopped using the Check Point version with Dynamic Objects and instead implemented the CPDBL.net method

    https://www.cpug.org/forums/showthre...ic-block-lists
    That is attractive and thank you for pointing it out. We may well take that path if Outgoing traffic were also to be inspected (hopefully is still on the roadmap).

Similar Threads

  1. Current List of All Check Point Exams
    By Barry J. Stiefel in forum General Exam Topics
    Replies: 3
    Last Post: 2008-04-14, 15:45
  2. Check Point FW1 and Astaro 6.3 Lan2Lan VPN peer ID trouble
    By Joffer in forum IPsec VPN Blade (Virtual Private Networks)
    Replies: 1
    Last Post: 2007-09-19, 11:14
  3. retrieve Dshield block list
    By bernardpasche in forum IPS Blade (Formerly SmartDefense)
    Replies: 1
    Last Post: 2007-08-17, 03:51
  4. Check Point to continue their mailing list
    By RayPesek in forum Miscellaneous
    Replies: 0
    Last Post: 2007-03-28, 21:42
  5. Can Check Point block googletalk ?
    By Wutkung in forum IPS Blade (Formerly SmartDefense)
    Replies: 1
    Last Post: 2007-03-05, 07:01

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •