Block IP - Generic
Deprecated. Use "Block IP - Generic v2" playbook instead. This playbook blocks malicious IPs using all integrations that you have enabled. Supported integrations for this playbook: * Check Point Firewall * Palo Alto Networks Minemeld * Palo Alto Networks Panorama * Zscaler
- Pack
- DeprecatedContent
- Tasks
- 11
Inputs
- IPBlacklistMiner — The name of the IP block list Miner in Minemeld.
- IP — Array of malicious IPs to block.
Outputs
- CheckpointFWRule.Destination — Collection of Network objects identified by the name or UID. How much details are returned depends on the details-level field of the request. This table shows the level of detail shown when details-level is set to standard.
- CheckpointFWRule.DestinationNegate — True if negate is set for destination.
- PanoramaRule.Direction — Direction of the Panorama rule, could be 'to','from', 'both'
- PanoramaRule.IP — The IP the Panorama rule blocks
- CheckpointFWRule.Name — Object name. Should be unique in domain.
- PanoramaRule.Name — Name of the Panorama rule
- CheckpointFWRule.UID — Object unique identifier.
- PanoramaRule — List of Panorama rules
- CheckpointFWRule.Type — Type of the object.
- CheckpointFWRule.Action — Accept, Drop, Apply Layer, Ask, Info. How much details are returned depends on the details-level field of the request. This table shows the level of detail shown when details-level is set to standard.
- CheckpointFWRule.ActionSetting — Action settings.
- CheckpointFWRule.CustomFields — Custom fields.
- CheckpointFWRule.Data — How much details are returned depends on the details-level field of the request. This table shows the level of detail shown when details-level is set to standard.
- CheckpointFWRule.DataDirection — On which direction the file types processing is applied.
- CheckpointFWRule.DataNegate — True if negate is set for data.
- CheckpointFWRule.Domain — Information about the domain the object belongs to.
- CheckpointFWRule.Enabled — Enable/Disable the rule.
- CheckpointFWRule.Hits — Hits count object.
- CheckpointFWRule.Data.Name — Object name. Should be unique in domain.
- CheckpointFWRule.Data.Domain — Information about the domain the object belongs to.
- CheckpointFWRule.Domain.Name — Object name. Should be unique in domain.
- CheckpointFWRule.Domain.UID — Object unique identifier.
- CheckpointFWRule.Domain.Type — Domain type.
- CheckpointFWRule.Hits.FirstDate — First of hits.
- CheckpointFWRule.Hits.LastDate — Last date of hits.
- CheckpointFWRule.Hits.Level — Level of hits.
- CheckpointFWRule.Hits.Percentage — Percentage of hits
- CheckpointFWRule.Hits.Value — Value of hits.
Commands used
- checkpoint-block-ip
- zscaler-blacklist-ip