ThreatGate Feeds¶
The feeds in this section are defined manually in the ThreatGate GUI or obtain their content from built-in services such as ThreatGateDB (Category Feeds) or MaxMind (Country Feeds).
Feed Settings¶
- Enable Feed
Whether this feed is enabled.
- Name
The name of the feed. Subject to firewall alias name format and restrictions.
- Mode
Controls how ThreatGate acts on the content of the feed. See ThreatGate Overview for more detail.
- Always Block
For feeds containing network prefixes, ThreatGate inserts firewall rules to block all traffic in any direction going to or from addresses on these lists. For feeds containing domain names or expressions, ThreatGate inserts Blocklists into all CoreDNS groups to block resolution of those entries.
- Managed Alias
Creates a firewall alias using any network addresses in the list and a CoreDNS Blocklist for domains and expressions in the list. Administrators can then use the resulting firewall alias in manual firewall rules or use the CoreDNS Blocklist in CoreDNS Groups.
- Threat Class
Indicates this feed will contain content from built-in services such as ThreatGateDB (Category Feeds) and MaxMind (Country Feeds).
- Countries
Lists of network prefixes within countries. ThreatGate obtains GeoIP data from MaxMind (Country Feeds).
Country feeds are useful for controlling communication to or from specific countries. For example, a managed country alias could allow local users to only reach sites in the same country or region. Country feeds can also block all communication to or from countries that a company does not do business with to limit exposure.
Warning
Country classes require MaxMind credentials. If those credentials are not present, Country data will never populate into feeds.
- Categories
Names and addresses associated with the chosen categories. Obtained from ThreatGateDB (Category Feeds).
Category feeds can be useful for blocking content such as malware and advertisements, typically by domain name.
- ASNs
A list of BGP Autonomous System Numbers to query and use in the feed. This enables administrators to filter traffic based on the company that has been assigned the address blocks. Obtained from ThreatGateDB (Category Feeds).
A common use case for this type of feed is to block specific social media companies, such as Meta.
- CIDRs
A manual list of CIDR networks added to the feed.
- Domains
A manual list of fully qualified domain names or expressions added to the feed.