Custom security intelligence lists
A custom Security Intelligence list is a static list that
-
contains IP addresses, address blocks, URLs, or domain names that you manually upload to the system,
-
enables you to augment and fine-tune feeds or global lists for the managed devices of a single Cloud-Delivered Firewall Management Center, and
-
is useful when you need to override or supplement existing feed behavior without removing the entire feed from a policy.
Formatting requirements for custom security intelligence lists
-
Netmasks for address blocks must be integers from
0to32for IPv4 or from0to128for IPv6. -
Encode Unicode in domain names using Punycode format. The encoding is not case sensitive.
-
Characters in domain names are not case sensitive.
-
Unicode in URLs must be percent-encoded.
-
Characters in URL subdirectories are case sensitive.
-
List entries that start with the number sign (
#) are treated as comments. -
For more information about formatting requirements, see the List custom lists and feeds requirements.
-
If you add a higher-level domain to a URL or DNS list, any sub-level domains also match. For example, if you add
example.comto a DNS list,www.example.comandtest.example.comalso match. -
DNS lookups (forward or reverse) are not performed on DNS or URL list entries. For example, if you add
http://198.51.100.2to a URL list, the list matches only that exact address and not any domain it resolves to.
Note | You cannot add address blocks to a Block or Do Not Block list using a |
-
If a global feed blocks access to a vital resource but is otherwise useful, you can upload a custom list to allow access to that resource without disabling the feed entirely.
-
You can supplement an existing feed by adding URLs or domains relevant to your organization.