Hi,
As there is now way at this time (that I know of) to automatically insert a list of IP's for the UTM to block, I am trying to leverage the behavior of the APTP functionality to be able to bulk/automatically insert IP numbers for blocking.
Currently I have a setup that can upload my own threatdata file to the UTM and it blocks the IP's in the file, however I do not fully understand the mechanism the UTM uses to reaload the data from the file, sometimes it takes quite a while for the changes to be applied.
I would like to be able to upload a modified threatdata file to the UTM and then tell the UTM to read the file so it blocks the IPs immediately.
I have read here that the Sophos staff recommends against this solution on the grounds that the APTP updates from Sophos are frequent (it will overwrite my threatdata file) and that maybe down the line the threatdata file would be encrypted.
My hope is to work around the first caveat by having the APTP update set to manual and only work with my file and the second has not happened yet so...
Is there anyone on the forum that has tried the same and would be willing to share your findings? Any insight into the APTP mechanics would be appreciated (file structure,cron entries etc) .
Thanks in advance!
/Patrik K
This thread was automatically locked due to age.