Threat Blocker or the firewall's threat intelligence

Many firewalls already come with the vendor's threat intelligence service. What Threat Blocker adds, what it does not do, and when to use both.

In short

The two are not exclusive: in parallel mode Threat Blocker adds its list of malicious IPs to the rules of the firewall you already use.

Threat Blocker

Makes sense when:

  • You have firewalls from different vendors, or several sites, and want the same list of malicious IPs everywhere.
  • Your firewall has no active threat intelligence subscription.
  • You want to see the blocks in Cyber Console, next to controls and compliance.
  • A small site without a firewall needs a device that acts as one.

The firewall's threat intelligence

Makes sense when:

  • You have a single vendor and its full security bundle: IPS signatures, web filtering, sandbox.
  • You need to block categories of sites or single URLs: Threat Blocker blocks IP addresses.

Point by point

Comparison checked on 1 October 2026.
What it blocks Threat BlockerConnections to and from malicious IP addresses, inbound and outbound The firewall's threat intelligenceDepends on the vendor and licence: often IPs, web categories, IPS signatures
Source of the indicators Threat BlockerOur threat intelligence The firewall's threat intelligenceThe firewall vendor's service
Compatibility Threat BlockerFirewalls that read an external list of IP addresses, or in place of the firewall The firewall's threat intelligenceOnly that vendor's devices
Several sites or vendors Threat BlockerThe same list for every firewall The firewall's threat intelligenceOne service per vendor
Domains, URLs and files Threat BlockerChecks from Cyber Console and our APIs, not blocked by the device The firewall's threat intelligenceDepends on the licence: web filtering, sandbox
Visibility Threat BlockerIn Cyber Console: blocks, top sources by country, an exportable access log The firewall's threat intelligenceIn the firewall's console
Without a firewall Threat BlockerIn series mode the device is the firewall The firewall's threat intelligenceNeeds the firewall
Updates Threat BlockerAutomatic, at least once an hour The firewall's threat intelligenceAutomatic, while the licence is active

Getting started with Threat Blocker

  1. 1

    Mode

    We decide together whether to install it in parallel, next to the firewall, or in series, in its place.

  2. 2

    Device

    We prepare the device and connect it to your network.

  3. 3

    Rules

    In parallel mode, the firewall reads the list of malicious IPs and sends its logs to the device.

  4. 4

    Cyber Console

    Blocks and device status are visible in Cyber Console.

Frequently asked questions

Only if you install it in series. In parallel it works next to the firewall you already use, and the firewall applies the block.

Those that can read an external list of IP addresses and send logs over syslog. We check your model before installation.

No, it blocks IP addresses. Domains, URLs and files can be checked from Cyber Console and through our APIs.

Automatically, at least once an hour, with nothing for you to do.

Not sure yet which fits you?

The Cyber Check-up returns your company's cyber profile and the priorities to start from.