Custom security intelligence lists

A custom Security Intelligence list is a static list that

  • contains IP addresses, address blocks, URLs, or domain names that you manually upload to the system,

  • enables you to augment and fine-tune feeds or global lists for the managed devices of a single Cloud-Delivered Firewall Management Center, and

  • is useful when you need to override or supplement existing feed behavior without removing the entire feed from a policy.

Formatting requirements for custom security intelligence lists

  • Netmasks for address blocks must be integers from 0 to 32 for IPv4 or from 0 to 128 for IPv6.

  • Encode Unicode in domain names using Punycode format. The encoding is not case sensitive.

  • Characters in domain names are not case sensitive.

  • Unicode in URLs must be percent-encoded.

  • Characters in URL subdirectories are case sensitive.

  • List entries that start with the number sign (#) are treated as comments.

  • For more information about formatting requirements, see the List custom lists and feeds requirements.

  • If you add a higher-level domain to a URL or DNS list, any sub-level domains also match. For example, if you add example.com to a DNS list, www.example.com and test.example.com also match.

  • DNS lookups (forward or reverse) are not performed on DNS or URL list entries. For example, if you add http://198.51.100.2 to a URL list, the list matches only that exact address and not any domain it resolves to.

Note

You cannot add address blocks to a Block or Do Not Block list using a /0 netmask in a Security Intelligence list. To monitor or block all traffic targeted by a policy, use an access control rule with the Monitor or Block action, and set the Source Networks and Destination Networks to any.

  • If a global feed blocks access to a vital resource but is otherwise useful, you can upload a custom list to allow access to that resource without disabling the feed entirely.

  • You can supplement an existing feed by adding URLs or domains relevant to your organization.