Skip to main content

Firewall Integration Pulling Zero IPs

The Firewall Integration Pulling Zero IPs issue means that none of its subscribed blocklists have IPs in them.

What Triggers This Issue

  • Trigger condition: On your last Pull your integration content was empty.
  • Criticality: ⚠️ High
  • Impact: Firewall pulling empty content — not contributing to protection.

Common Root Causes

Diagnosis & Resolution

This is the most common cause. When a Firewall integration is created in the Console, it must have at least one blocklist subscribed to it before the endpoint will return any IPs.

🔎 See blocklists subscriptions for your integration

  1. Navigate to Blocklists > Integrations
  2. Look if the mentioned integration's tile to see if it has Blocklists
  • If no blocklists are listed, the BLaaS endpoint will return an empty list on every pull.
  • User made blocklists you have created might be empty
  • Note that the premium-tier blocklist Threat Forecast Blocklist, generated specially for your organization, might be empty if you share no or too few signals

🛠️ Solution: subscribe to one or more blocklists

  1. Browse the blocklists catalogue ↗️ via the left side menu or by clicking Add Blocklist on your integration tile.
  2. Follow the blocklists subscription documentation

Getting Help

If your firewall integration still shows zero IPs after subscribing to blocklists:

  • Check Discourse for similar cases
  • Ask on Discord with your integration configuration
  • Contact CrowdSec support via the Console