Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlockerNG - Proofpoint ET IQRISK IPv4 Reputation

    Scheduled Pinned Locked Moved pfBlockerNG
    3 Posts 2 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      rtw915
      last edited by

      I have been trying to figure out how to setup Proofpoint ET IQRISK IPv4 Reputation, but I must not be doing something right.
      bd65882b-17b3-4af4-a5ce-9782abb760b1-image.png
      The ET IQRisk Blocklist URL path breaks at /reputation/iprepdata.txt.gz. If I go to the path in a browser it contains snort\suricata versions. Like it is documented here https://rules.emergingthreatspro.com/PRO_download_instructions.html
      I have searched for documentation on how to set this up but have not found much.

      1 Reply Last reply Reply Quote 0
      • R
        rtw915
        last edited by

        Hello everybody, Proofpoint ET IQRISK has changed its name to ET Intelligence. It is a separate offering that Proofpoint offers. The company I work for is looking to purchase this solution if I can get the trial to work.

        I am confused by the instructions I posted 16 days ago:

        • The trial gave me a url with what I think already contains the ETPro code referenced in the instructions. It looks like this but instead of "X" it has the code: https://rules.emergingthreatspro.com/XXXXXXXXXXXXXXXXX/reputation/

        • I appended /iprepdata.txt.gz to the end and it correctly downloads in a browser.

        • I go to the IPv4 list tab and "ET IQRisk" is not a format in the list.
          20cc25d6-2ae7-462d-8165-24cda36ba460-image.png

        • I leave it on Auto just to see what would happen. Now the Proofpoint ET IPRep
          files exist and have IP in them. So that seems good!

        60f3a099-e1b6-4385-9a3e-c2d10f648775-image.png

        • This is where I get lost. I go back to the reputation tab under IP populate the Header from the first screen shot and select the Block Categories. What does the step highlighted in blue mean?

        9db9111a-8b33-4ebf-81ed-63a4b5cc8362-image.png

        BBcan177B 1 Reply Last reply Reply Quote 1
        • BBcan177B
          BBcan177 Moderator @rtw915
          last edited by

          @rtw915

          The text that you highlighted is referencing IP "Match" types. Its not needed if you want to Block those IPs. pfSense allows creating Match IP Rules, to allow for the "Logging" of the event any nothing further.

          "Experience is something you don't get until just after you need it."

          Website: http://pfBlockerNG.com
          Twitter: @BBcan177  #pfBlockerNG
          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

          1 Reply Last reply Reply Quote 1
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.