Check Point integration

Check Point threat intelligence integration

Boost your Check Point firewall with Q-Feeds cyber threat intelligence (CTI). Use native Custom Intelligence Feeds to pull real-time IP and domain threat feeds into your Threat Prevention policy and block malicious traffic at the gateway, with minimal effort and maximum impact. For step-by-step Check Point configuration, see our knowledge base setup guide.

  • 2,500+Intelligence sources
  • 20 minUpdate interval
  • 4 stepsTo full integration
  • 2Feed types: IP, domain
What it is

What is the Q-Feeds and Check Point integration?

The Q-Feeds integration connects curated cyber threat intelligence directly to your Check Point Security Gateway using native Custom Intelligence Feeds. The gateway periodically fetches Q-Feeds blocklists of malicious IP addresses and domains over HTTPS and enforces them through the Anti-Bot and Anti-Virus Software Blades.

The result is automated, always-current protection: known-bad indicators are blocked at the gateway before they reach your users or servers, with no manual list management. It runs alongside your existing ThreatCloud protections to add independent, multi-source intelligence.

Whether you run a single gateway or a large managed estate, the integration scales from a free proof of concept to full production use.

Custom Intelligence Feeds

What you can block on Check Point

Malicious IP feeds

Import an IP address feed to block inbound and outbound traffic to known-malicious hosts, botnets and command-and-control servers in your Threat Prevention policy.

Malicious domain feeds

Import a domain feed so the gateway blocks command-and-control and phishing domains through Anti-Bot and Anti-Virus.

Native to Threat Prevention

Custom Intelligence Feeds are built into Check Point from R80.20. No extra appliance or connector is required, just a feed URL and your API key.

Curated categories

Choose focused feeds for phishing, botnets, malware and dark web threats, so you only enforce what is relevant to your organisation.

Benefits

Why add Q-Feeds to your Check Point gateway

  • Fewer false positives

    Indicators are cross-referenced across commercial, OSINT and governmental sources and curated to cut noise, so you block real threats, not legitimate traffic.

  • Refreshed every 20 minutes

    Feeds update every 20 minutes on Premium, so your gateway stays ahead of fast-moving campaigns automatically.

  • Multi-source resilience

    Combining many independent sources removes single-vendor blind spots and hardens your coverage.

  • Faster incident response

    Blocking at the gateway means faster, more precise response and less time spent on internal investigations.

How it works

The Multi-Eyed Principle

The Multi-Eyed Principle emphasises using multiple sources of threat intelligence to strengthen the security and effectiveness of your existing firewall. By combining diverse feeds you achieve a more comprehensive, robust defence against cyber threats.

Multiple sources of IOCs

Commercial, OSINT and governmental intelligence combined in one firewall.

Simple 4-step implementation

Implementation is fast and easy with our 4-step manuals, and a proof of concept is completely free.

Setup

Integrate Q-Feeds with Check Point in 4 steps

  1. Create your free account

    Sign up on the Q-Feeds Threat Intelligence Portal and copy your personal feed URLs for IP and domain indicators.

  2. Add a Custom Intelligence Feed

    In SmartConsole add a New IoC Feed (or use the ioc_feeds CLI) pointing to your Q-Feeds feed URL, with the value column and indicator type set.

  3. Set the retrieval interval

    Set the global External Feed interval to match your license: 24 hours for Community, 4 hours for Plus, 20 minutes for Premium.

  4. Install the policy

    Install the Threat Prevention policy so the gateway enforces the feeds through Anti-Bot and Anti-Virus immediately.

Implementation

Implementation

Native support for Check Point Custom Intelligence Feeds. Our step-by-step manuals cover SmartConsole and CLI, so your gateway can be hardened in no time.

Check Point setup guide
Custom project

Your own Check Point feed project?

Want to use Q-Feeds threat intelligence with Check Point? Sign up for free and see the power of Q-Feeds for yourself.

Get started
FAQ

Frequently asked questions about the Check Point integration

What is a Check Point Custom Intelligence Feed?

A Custom Intelligence Feed lets a Check Point Security Gateway automatically download a list of malicious IPs or domains from an external source like Q-Feeds and enforce it through Anti-Bot and Anti-Virus.

Which threat feeds can I add to Check Point?

With Q-Feeds you can add IP address feeds and domain feeds and enforce them in your Threat Prevention policy through the Anti-Bot and Anti-Virus blades.

How often are the Q-Feeds threat feeds updated?

Update speed depends on your license: every 24 hours on Community, every 4 hours on Plus and every 20 minutes on Premium. Set the Check Point retrieval interval to match.

Do I need a specific Check Point version?

Custom Intelligence Feeds are supported from R80.20 onwards. You also need the Anti-Bot and/or Anti-Virus Software Blade enabled on the gateway.

Is there a free version?

Yes. The Q-Feeds Community edition is free and lets you test the Check Point integration before upgrading to Plus or Premium for faster, premium intelligence.

Does it work alongside ThreatCloud?

Yes. Q-Feeds adds independent, multi-source intelligence on top of your existing Check Point ThreatCloud protections for broader coverage.

Evaluate our intelligence today!

Simplify your security operations, start your free Q-Feeds trial and experience the difference.

Activate free access