IP Threat Feed as Whitelist
Every couple minutes I query a few endpoints to gather a list of ipv4 public addresses for all of our remote work employees. These employees often travel and have ISPs that issue dynamic addresses, so this list will be dynamic.
I'm hesitant in creating a address group because this could be several thousand addresses. Not only that, address groups touch the firewall ssd/hdd drive so I worry that modifying addresses groups once a minute could be a heavy task on the firewall.
I'm wanting to use the External Connector Threat IP Feed as a whitelist on our SSLVPN portal. In the event that the .txt file can't be retrieved, this would need to fail open (allow all). I've tried forcing it to fail (changing the endpoint so it'll time out), but the log doesn't indicate it failed, thus I'm not able to use the Automation feature.
Any ideas on this?
