Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    pfBlockerNG - Proofpoint ET IQRISK IPv4 Reputation

    pfBlockerNG
    2
    3
    613
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      rtw915 last edited by

      I have been trying to figure out how to setup Proofpoint ET IQRISK IPv4 Reputation, but I must not be doing something right.
      bd65882b-17b3-4af4-a5ce-9782abb760b1-image.png
      The ET IQRisk Blocklist URL path breaks at /reputation/iprepdata.txt.gz. If I go to the path in a browser it contains snort\suricata versions. Like it is documented here https://rules.emergingthreatspro.com/PRO_download_instructions.html
      I have searched for documentation on how to set this up but have not found much.

      1 Reply Last reply Reply Quote 0
      • R
        rtw915 last edited by

        Hello everybody, Proofpoint ET IQRISK has changed its name to ET Intelligence. It is a separate offering that Proofpoint offers. The company I work for is looking to purchase this solution if I can get the trial to work.

        I am confused by the instructions I posted 16 days ago:

        • The trial gave me a url with what I think already contains the ETPro code referenced in the instructions. It looks like this but instead of "X" it has the code: https://rules.emergingthreatspro.com/XXXXXXXXXXXXXXXXX/reputation/

        • I appended /iprepdata.txt.gz to the end and it correctly downloads in a browser.

        • I go to the IPv4 list tab and "ET IQRisk" is not a format in the list.
          20cc25d6-2ae7-462d-8165-24cda36ba460-image.png

        • I leave it on Auto just to see what would happen. Now the Proofpoint ET IPRep
          files exist and have IP in them. So that seems good!

        60f3a099-e1b6-4385-9a3e-c2d10f648775-image.png

        • This is where I get lost. I go back to the reputation tab under IP populate the Header from the first screen shot and select the Block Categories. What does the step highlighted in blue mean?

        9db9111a-8b33-4ebf-81ed-63a4b5cc8362-image.png

        BBcan177 1 Reply Last reply Reply Quote 0
        • BBcan177
          BBcan177 Moderator @rtw915 last edited by

          @rtw915

          The text that you highlighted is referencing IP "Match" types. Its not needed if you want to Block those IPs. pfSense allows creating Match IP Rules, to allow for the "Logging" of the event any nothing further.

          "Experience is something you don't get until just after you need it."

          Website: http://pfBlockerNG.com
          Twitter: @BBcan177  #pfBlockerNG
          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

          1 Reply Last reply Reply Quote 1
          • First post
            Last post