Skip to main content

Checkpoint

Checkpoint Integration CardCheckpoint Integration Card

The CrowdSec Checkpoint integration connects CrowdSec's hosted blocklist endpoint to your Checkpoint firewall.
Check Point calls this feature Custom Intelligence (IoC) Feeds, which provide the ability to add custom cyber intelligence feeds into the Threat Prevention engine.

Ensure your Checkpoint device supports Custom Intelligence (IoC) Feeds.
The vendor documentation is available in the References section below.

Setup a Checkpoint Integration Endpoint

Step 1 — Create an integration in the CrowdSec Console

In your CrowdSec Console account, navigate to the Blocklist tab in the top menu bar, then select the Integrations sub-menu. Choose the integration type you need, then click Connect.

If you don't have a CrowdSec Console account, sign up here. On mobile, use the menu icon in the top-right corner, tap Blocklist, then Integrations.

CrowdSec Integrations ScreenCrowdSec Integrations Screen

Configure Checkpoint

In the Gateways and Servers tab, double-click the gateway you want to configure.

In the properties menu, select Threat Prevention (Custom), then activate at least Anti-Bot or Anti-Virus.

Go to the Security policies tab and click New IOC Feed.

Click Custom Policy, then Indicators. Add your feed information using the endpoint URL with Basic Auth credentials embedded:

https://<username>:<password>@admin.api.crowdsec.net/v1/integrations/<integration_id>/content

You can use the Raw IP List format and set the data column to 1. Click Test Feed.

Select the gateway and click Test Feed.

Verify the feed is working, then save the configuration.

Format example

The CrowdSec blocklist is served in Checkpoint format, with one entry per line:

Accessobserv2,192.168.38.187,IP,high,high,AB,C&C server IP
Accessobserv2,192.168.38.188,IP,high,high,AB,C&C server IP

Format: UNIQ-NAME, VALUE, TYPE, CONFIDENCE, SEVERITY, PRODUCT, COMMENT

Manage integration size limits with pagination

If you want to learn how to manage integration size limits with pagination, please refer to the Managing integrations size limits with pagination section.

References

Next Steps

Subscribe to blocklists in the Blocklist Catalog to populate your integration.