cancel
Showing results for 
Search instead for 
Did you mean: 
mekafir
Level 7

Does MWG have daily updated list of Suspicious IP Addresses ?

People,

I wonder if the current McAfee Web Gateway procy application does have the daily updated list of suspicious IP addresses ?

For example, I'm a subscriber of https://www.recordedfuture.com/cyber-threat-intelligence list which sends me daily known / dangerous IP addresses like:

81[.]183[.]56[.]217

Hits: 23 | First seen in Recorded Future on 27 Oct 2014 22:17:57

178[.]32[.]173[.]180

Hits: 23 | First seen in Recorded Future on 03 Sep 2015 20:56:36

46[.]109[.]168[.]179

Hits: 22 | First seen in Recorded Future on 27 Oct 2014 22:48:33

185[.]129[.]148[.]19

Hits: 21 | First seen in Recorded Future on 03 Aug 2016 10:40:59

194[.]67[.]210[.]183

Hits: 20 | First seen in Recorded Future on 18 Aug 2016 14:29:18

Note: I'm using The hardware appliance MWG version 7.5.2.5.0 (20828), so not sure if there is a feature like that ?

Any help and suggestion would be greatly appreciated.

Thanks,

M

0 Kudos
2 Replies
lubomir_cerny
Level 12

Re: Does MWG have daily updated list of Suspicious IP Addresses ?

Naturally MWG uses its GTI integration feature for IP reputation. See Check Single URL

if you have external list of IPs, you can store it as text file and use such file as source for Customer maintained list. See doc at

Hope it helps.

Troja
Level 14

Re: Does MWG have daily updated list of Suspicious IP Addresses ?

Hi ​,

IP-Reputation is updated in regulary intervals. You can change the scheduling value. Additional, if there is not entry in the local URL Filter Database (IP Reputation is included in the URL Filter database) MWG does a GTI lookup in Real Time.

You can configure forward and backward DNS lookup (and other stuff) in the URL Filter settings.

MWG URL Filter Settings.GIF

Finally, yes, IP Reputation is updated in regular intervals and also in real time.

Hope this helps,

Cheers.