Block IP - Generic v2
Deprecated. Use the `Block IP - Generic v3` playbook instead. This playbook blocks malicious IPs using all integrations that are enabled. Supported integrations for this playbook: * Check Point Firewall * Palo Alto Networks Minemeld * Palo Alto Networks PAN-OS * Zscaler * FortiGate
- Pack
- CommonPlaybooks
- Tasks
- 24
Inputs
- IPBlacklistMiner — The name of the IP block list Miner in Minemeld.
- IP — Array of malicious IPs to block.
- CustomBlockRule — This input determines whether Palo Alto Networks Panorama or Firewall Custom Block Rules are used. Specify True to use Custom Block Rules.
- LogForwarding — Panorama log forwarding object name.
- AutoCommit — This input determines whether to commit the configuration automatically. Yes - Commit automatically. No - Commit manually.
- StaticAddressGroup — This input determines whether Palo Alto Networks Panorama or Firewall Static Address Groups are used. Specify the Static Address Group name for IP handling.
- IPListName — This input determines whether Palo Alto Networks Panorama or Firewall External Dynamic Lists are used for blocking IPs. Specify the EDL name for IP handling.
- EDLServerIP — This input determines whether Palo Alto Networks Panorama or Firewall External Dynamic Lists are used: * The IP address of the web server on which the files are stored. * The web server IP address is configured in the integration instance.
- DAG — This input determines whether Palo Alto Networks Panorama or Firewall Dynamic Address Groups are used. Specify the Dynamic Address Group tag name for IP handling.
Outputs
- CheckpointFWRule.Destination — Rule Destination.
- CheckpointFWRule.DestinationNegate — Rule destination negate status (True/False).
- PanoramaRule.Direction — Direction of the Panorama rule. Can be 'to','from', 'both'
- PanoramaRule.IP — The IP the Panorama rule blocks
- CheckpointFWRule.Name — Rule name.
- PanoramaRule.Name — Name of the Panorama rule
- CheckpointFWRule.UID — Rule UID.
- PanoramaRule — List of Panorama rules
- CheckpointFWRule.Type — Rule Type.
- CheckpointFWRule.Action — Rule action (Valid values are: Accept, Drop, Apply Layer, Ask, Info).
- CheckpointFWRule.ActionSetting — Rule action settings.
- CheckpointFWRule.CustomFields — Rule custom fields.
- CheckpointFWRule.Data — Rule data.
- CheckpointFWRule.DataDirection — Rule data direction.
- CheckpointFWRule.DataNegate — Rule data negate status (True/False).
- CheckpointFWRule.Domain — Rule domain.
- CheckpointFWRule.Enabled — Rule status.
- CheckpointFWRule.Hits — Rule hits count.
- CheckpointFWRule.Data.Name — Rule data object name.
- CheckpointFWRule.Data.Domain — Information about the domain the data object belongs to.
- CheckpointFWRule.Domain.Name — Rule domain name.
- CheckpointFWRule.Domain.UID — Rule domain UID.
- CheckpointFWRule.Domain.Type — Rule domain type.
- CheckpointFWRule.Hits.FirstDate — The date of the first hit for the rule.
- CheckpointFWRule.Hits.LastDate — The date of the last hit for the rule.
- CheckpointFWRule.Hits.Level — Level of rule hits.
- CheckpointFWRule.Hits.Percentage — Percentage of rule hits.
- CheckpointFWRule.Hits.Value — Value of rule hits.
Commands used
- checkpoint-block-ip
- fortigate-ban-ip
- zscaler-blacklist-ip