Check Point threat intelligence integration
Boost your Check Point firewall with Q-Feeds cyber threat intelligence (CTI). Use native Custom Intelligence Feeds to pull real-time IP and domain threat feeds into your Threat Prevention policy and block malicious traffic at the gateway, with minimal effort and maximum impact. For step-by-step Check Point configuration, see our knowledge base setup guide.
- 2,500+Intelligence sources
- 20 minUpdate interval
- 4 stepsTo full integration
- 2Feed types: IP, domain
What is the Q-Feeds and Check Point integration?
The Q-Feeds integration connects curated cyber threat intelligence directly to your Check Point Security Gateway using native Custom Intelligence Feeds. The gateway periodically fetches Q-Feeds blocklists of malicious IP addresses and domains over HTTPS and enforces them through the Anti-Bot and Anti-Virus Software Blades.
The result is automated, always-current protection: known-bad indicators are blocked at the gateway before they reach your users or servers, with no manual list management. It runs alongside your existing ThreatCloud protections to add independent, multi-source intelligence.
Whether you run a single gateway or a large managed estate, the integration scales from a free proof of concept to full production use.
What you can block on Check Point
Malicious IP feeds
Import an IP address feed to block inbound and outbound traffic to known-malicious hosts, botnets and command-and-control servers in your Threat Prevention policy.
Malicious domain feeds
Import a domain feed so the gateway blocks command-and-control and phishing domains through Anti-Bot and Anti-Virus.
Native to Threat Prevention
Custom Intelligence Feeds are built into Check Point from R80.20. No extra appliance or connector is required, just a feed URL and your API key.
Curated categories
Choose focused feeds for phishing, botnets, malware and dark web threats, so you only enforce what is relevant to your organisation.
Why add Q-Feeds to your Check Point gateway
-
Fewer false positives
Indicators are cross-referenced across commercial, OSINT and governmental sources and curated to cut noise, so you block real threats, not legitimate traffic.
-
Refreshed every 20 minutes
Feeds update every 20 minutes on Premium, so your gateway stays ahead of fast-moving campaigns automatically.
-
Multi-source resilience
Combining many independent sources removes single-vendor blind spots and hardens your coverage.
-
Faster incident response
Blocking at the gateway means faster, more precise response and less time spent on internal investigations.
The Multi-Eyed Principle
The Multi-Eyed Principle emphasises using multiple sources of threat intelligence to strengthen the security and effectiveness of your existing firewall. By combining diverse feeds you achieve a more comprehensive, robust defence against cyber threats.
Multiple sources of IOCs
Commercial, OSINT and governmental intelligence combined in one firewall.
Simple 4-step implementation
Implementation is fast and easy with our 4-step manuals, and a proof of concept is completely free.
Integrate Q-Feeds with Check Point in 4 steps
Create your free account
Sign up on the Q-Feeds Threat Intelligence Portal and copy your personal feed URLs for IP and domain indicators.
Add a Custom Intelligence Feed
In SmartConsole add a New IoC Feed (or use the ioc_feeds CLI) pointing to your Q-Feeds feed URL, with the value column and indicator type set.
Set the retrieval interval
Set the global External Feed interval to match your license: 24 hours for Community, 4 hours for Plus, 20 minutes for Premium.
Install the policy
Install the Threat Prevention policy so the gateway enforces the feeds through Anti-Bot and Anti-Virus immediately.
Implementation
Native support for Check Point Custom Intelligence Feeds. Our step-by-step manuals cover SmartConsole and CLI, so your gateway can be hardened in no time.
Check Point setup guideYour own Check Point feed project?
Want to use Q-Feeds threat intelligence with Check Point? Sign up for free and see the power of Q-Feeds for yourself.
Get startedPrefer a different platform?
Threat intelligence feeds
Curated IP, URL and domain feeds for your whole stack.
Fortinet
Elevate your Fortinet FortiGate firewall by adding our intelligence.
Palo Alto
Palo Alto firewalls can be hardened with our threat intelligence.
Sophos XGS
Enhance the Sophos XGS firewall with our threat intelligence.
Frequently asked questions about the Check Point integration
What is a Check Point Custom Intelligence Feed?
A Custom Intelligence Feed lets a Check Point Security Gateway automatically download a list of malicious IPs or domains from an external source like Q-Feeds and enforce it through Anti-Bot and Anti-Virus.
Which threat feeds can I add to Check Point?
With Q-Feeds you can add IP address feeds and domain feeds and enforce them in your Threat Prevention policy through the Anti-Bot and Anti-Virus blades.
How often are the Q-Feeds threat feeds updated?
Update speed depends on your license: every 24 hours on Community, every 4 hours on Plus and every 20 minutes on Premium. Set the Check Point retrieval interval to match.
Do I need a specific Check Point version?
Custom Intelligence Feeds are supported from R80.20 onwards. You also need the Anti-Bot and/or Anti-Virus Software Blade enabled on the gateway.
Is there a free version?
Yes. The Q-Feeds Community edition is free and lets you test the Check Point integration before upgrading to Plus or Premium for faster, premium intelligence.
Does it work alongside ThreatCloud?
Yes. Q-Feeds adds independent, multi-source intelligence on top of your existing Check Point ThreatCloud protections for broader coverage.
Evaluate our intelligence today!
Simplify your security operations, start your free Q-Feeds trial and experience the difference.
Activate free access