ThreatGate Feeds

The feeds in this section are defined manually in the ThreatGate GUI or obtain their content from built-in services such as ThreatGateDB (Category Feeds) or MaxMind (Country Feeds).

Feed Settings

Enable Feed

Whether this feed is enabled.

Name

The name of the feed. Subject to firewall alias name format and restrictions.

Mode

Controls how ThreatGate acts on the content of the feed. See ThreatGate Overview for more detail.

Always Block

For feeds containing network prefixes, ThreatGate inserts firewall rules to block all traffic in any direction going to or from addresses on these lists. For feeds containing domain names or expressions, ThreatGate inserts Blocklists into all CoreDNS groups to block resolution of those entries.

Managed Alias

Creates a firewall alias using any network addresses in the list and a CoreDNS Blocklist for domains and expressions in the list. Administrators can then use the resulting firewall alias in manual firewall rules or use the CoreDNS Blocklist in CoreDNS Groups.

Threat Class

Indicates this feed will contain content from built-in services such as ThreatGateDB (Category Feeds) and MaxMind (Country Feeds).

Countries

Lists of network prefixes within countries. ThreatGate obtains GeoIP data from MaxMind (Country Feeds).

Country feeds are useful for controlling communication to or from specific countries. For example, a managed country alias could allow local users to only reach sites in the same country or region. Country feeds can also block all communication to or from countries that a company does not do business with to limit exposure.

Warning

Country classes require MaxMind credentials. If those credentials are not present, Country data will never populate into feeds.

Categories

Names and addresses associated with the chosen categories. Obtained from ThreatGateDB (Category Feeds).

Category feeds can be useful for blocking content such as malware and advertisements, typically by domain name.

ASNs

A list of BGP Autonomous System Numbers to query and use in the feed. This enables administrators to filter traffic based on the company that has been assigned the address blocks. Obtained from ThreatGateDB (Category Feeds).

A common use case for this type of feed is to block specific social media companies, such as Meta.

CIDRs

A manual list of CIDR networks added to the feed.

Domains

A manual list of fully qualified domain names or expressions added to the feed.