> Source: [sk180440](https://support.checkpoint.com/results/sk/sk180440)

# sk180440 - Adding an external IoC Feed fails during the authentication

| Property | Value |
|----------|-------|
| Solution ID | sk180440 |
| Date Created | 2022-12-22 |
| Last Modified | 2024-01-23 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.10 (EOS) |
| OS | Gaia |

## Symptoms

- * After an upgrade of the Security Gateway to R81.10, adding an external IoC Feed with the "`ioc_feeds add ... -transport {http | https} ... --user_name`" command (see [sk132193](https://support.checkpoint.com/results/sk/sk132193)) fails during the authentication.

* After fetching the feed in the debug mode on the Security Gateway with the "`$FWDIR/bin/ioc_feeder -d -f`" command, the log file *$FWDIR/log/ioc_feeder.elg* contains these lines:

  `
  [xxx xxx]@hostname[xxx] CIOCHTTPFetcher[121] ::trace: [INFO] == Info: The requested URL returned error: 401`  
  `
  [xxx xxx]@hostname[xxx] CIOCHTTPFetcher[121] ::trace: [INFO] == Info: Closing connection 0`  
  `
  [xxx xxx]@hostname[xxx] CIOCHTTPFetcher[121] ::trace: [INFO] == Info: TLSv1.3 (OUT), TLS alert, [no content] (0):`  
  `
  [xxx xxx]@hostname[xxx] CIOCHTTPFetcher[121] ::trace: [INFO] == Info: TLSv1.3 (OUT), TLS alert, close notify (256):`  
  `
  [xxx xxx]@hostname[xxx] CIOCHTTPFetcher[480] ::download: [ERROR] curl_easy_perform() failed: HTTP response code said error`  
  `
  [xxx xxx]@hostname[xxx] CIOCHTTPFetcher[81] ::fetch: [ERROR] download failed`  
  `
  [xxx xxx]@hostname[xxx] CIOCFeed[222] ::doFeed: [ERROR] Fetch failed for <Name of IoC Feed>`  
  `
  [xxx xxx]@hostname[xxx] CIOCFeederManger[958] ::run: [ERROR] Feed <Name of IoC Feed> failed`  
  `
  [xxx xxx]@hostname[xxx] CIOCFeederManger[967] ::run: [ERROR] External Indicators processing failed`  
  `
  [xxx xxx]@hostname[xxx] CIOCFeederManger[1094] ::logFinalStatus: [INFO] logging "External IOC - External Indicators processing failed`  
  `
  <Name of IoC Feed>: Failed to fetch feed. Resource: <URL of IoC Feed>, Reason: HTTP response code said error" severity 3`  
  `
  [xxx xxx]@hostname[xxx] CIOCLogger[115] ::log: [INFO] CplogClientSendLog sucess`  
  `
  [xxx xxx]@hostname[xxx] ############## FAILED ##############`  
  `
  [xxx xxx]@hostname[xxx] #############################################`  
  `
  [xxx xxx]@hostname[xxx] Feed status <Name of IoC Feed> :: engine memory allocation error`

## Cause

The Security Gateway does not pass the entered password to the external server during the IoC feed fetch.

## Solution

This problem was fixed. The fix is included in:

* [Check Point R81.20](https://support.checkpoint.com/results/sk/sk173903)
* [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 79

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
