Submenu – Threat Intelligence
This page contains the general settings for the threat intelligence feed provided by Webroot.
Prerequisites
To enable the threat intelligence feed provided by Webroot, the following prerequisites must be met:
- A valid license for the Threat Intelligence Feed must be installed.
- DNS resolution must be available for the BrightCloud service endpoints.
- Airlock Gateway must be able to establish outbound HTTPS connections to the following currently used endpoints:
Hostname
IP version
Protocol
Port
Purpose
api-dualstack.bcti.brightcloud.comIPv4/IPv6
TCP
443BrightCloud API endpoint
localdb-ip-daily.brightcloud.comIPv4
TCP
443Database update endpoint
localdb-ip-rtu.brightcloud.comIPv4
TCP
443Real-time database update endpoint
localdb-ipv6-daily.brightcloud.comIPv6
TCP
443IPv6 database update endpoint
The database update hostnames are provided dynamically by api-dualstack.bcti.brightcloud.com and may change over time. Therefore, additional BrightCloud database update hostnames may be returned by the service.
Connectivity must be possible through a back-end interface or through the management interface. Airlock Gateway does not use the external interface to connect to the threat intelligence feed service.
