Firewall Integration Pulling Zero IPs
The Firewall Integration Pulling Zero IPs issue means that none of its subscribed blocklists have IPs in them.
What Triggers This Issue
- Trigger condition: On your last Pull your integration content was empty.
- Criticality: ⚠️ High
- Impact: Firewall pulling empty content — not contributing to protection.
Common Root Causes
- No blocklist subscriptions: The integration has no blocklists subscribed to it, so the endpoint has nothing to return.
- All subscribed blocklists are empty: The subscribed blocklists currently contain no entries (rare, but possible for user created or dynamic lists).
Diagnosis & Resolution
This is the most common cause. When a Firewall integration is created in the Console, it must have at least one blocklist subscribed to it before the endpoint will return any IPs.
🔎 See blocklists subscriptions for your integration
- Navigate to Blocklists > Integrations
- Look if the mentioned integration's tile to see if it has Blocklists
- If no blocklists are listed, the BLaaS endpoint will return an empty list on every pull.
- User made blocklists you have created might be empty
- Note that the premium-tier blocklist Threat Forecast Blocklist, generated specially for your organization, might be empty if you share no or too few signals
🛠️ Solution: subscribe to one or more blocklists
- Browse the blocklists catalogue ↗️ via the left side menu or by clicking Add Blocklist on your integration tile.
- Follow the blocklists subscription documentation
Related Issues
- Firewall Integration Offline — If the firewall has stopped pulling entirely
- Remediation Component Integration Offline — Similar issue for RC-based integrations
Getting Help
If your firewall integration still shows zero IPs after subscribing to blocklists: