Create security intelligence feeds

Configure security intelligence feeds to enhance your device's ability to detect and respond to threats by importing external or custom threat data sources.

You must have the IPS license (for Firewall Threat Defense devices) or the Protection license (all other device types).

Use this task when you need to add new threat intelligence feeds for IP, DNS, or URL data to your security device.

Procedure


Step 1

Choose Objects > Security Intelligence node, then choose a feed type you want to add.

Step 2

Click the option appropriate to the feed type you chose:

  • Add Network Lists and Feeds (for IP addresses)
  • Add DNS Lists and Feeds
  • Add URL Lists and Feeds

Step 3

Enter a Name for the feed.

Step 4

Choose Feed from the Type drop-down list.

Step 5

Enter a Feed URL.

Step 6

Enter an MD5 URL.

  • The MD5 URL is used to check if the feed content has changed since the last update and is required for update intervals shorter than 30 minutes.

  • If your feed provider does not supply an MD5 URL, set the update interval to at least 30 minutes.

Step 7

Choose an Update Frequency.

Step 8

Click Save.

Unless you disabled feed updates, the system downloads and verifies the feed.