12-07-2019 11:45 AM - edited 02-21-2020 09:45 AM
Hi guys,
I have just a short question:
How can a realize a blocking for a long list of IP addresses without entering them manually one by one.
The list is here:
https://paste.cryptolaemus.com/emotet/2019/06/21/emotet-malware-IoCs_06-21-19.html
Is there a trick that I don't need to enter them manually in a group object to create a blocking access control rule against it?
Every hint is very welcome!
Thanks a lot and have a nice weekend!
Bye
R.
Solved! Go to Solution.
12-07-2019 06:52 PM
If you're OK with blocking the IP addresses altogether you can just import them as a plain text file into the IP Blacklist object.
The listing you referred to has address:port combos. Those you would probably have to enter manually. You could use the API but learning the prerequisites for doing that probably takes longer than manual entry. :)
12-07-2019 06:52 PM
If you're OK with blocking the IP addresses altogether you can just import them as a plain text file into the IP Blacklist object.
The listing you referred to has address:port combos. Those you would probably have to enter manually. You could use the API but learning the prerequisites for doing that probably takes longer than manual entry. :)
12-08-2019 12:22 PM
Hi Marvin,
this sounds good!
I will prepare an ASCII file and import it to an IP Blacklist object.
Thanks a lot!
12-08-2019 07:40 AM
Hi,
You could create a manual Security Intelligence feed, essentially you just list the IP addresses to blacklist in a text file. The file can either be uploaded to the FMC or alternatively store the file on a web server and the FMC will query the list (as a feed) at regular intervals. Useful links here and here.
HTH
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide