<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: updatable objects with wildcard entries in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/updatable-objects-with-wildcard-entries/m-p/75874#M11686</link>
    <description>&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk131852&amp;amp;partition=Basic&amp;amp;product=Security" target="_blank"&gt;sk131852: &lt;STRONG&gt;Updatable&lt;/STRONG&gt; Objects in R80.20 and above&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122636&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank"&gt;sk122636: How to troubleshoot &lt;STRONG&gt;Updatable&lt;/STRONG&gt; Objects in R80.20 and higher&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Feb 2020 12:24:22 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2020-02-20T12:24:22Z</dc:date>
    <item>
      <title>updatable objects with wildcard entries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/updatable-objects-with-wildcard-entries/m-p/75857#M11685</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;we are using updatable objects in our o365 policy.&lt;BR /&gt;The updatable object "Office Worldwide Services" includes some Wildcard Domain entries, e.g. "*.msappproxy.net". We figured out, requests which should match these wildcards do not work.&lt;BR /&gt;Should they work? - We assume that the gateway does a dns lookup for every fqdn which is listed in the updatable object and cashs it. For wildcard entries it is not possible. Are we Right?&lt;BR /&gt;Can someone explain how the updatable object mechanism works? Or is there a good article in the knowledgebase?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2020 11:24:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/updatable-objects-with-wildcard-entries/m-p/75857#M11685</guid>
      <dc:creator>Markus_Kress</dc:creator>
      <dc:date>2020-02-20T11:24:28Z</dc:date>
    </item>
    <item>
      <title>Re: updatable objects with wildcard entries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/updatable-objects-with-wildcard-entries/m-p/75874#M11686</link>
      <description>&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk131852&amp;amp;partition=Basic&amp;amp;product=Security" target="_blank"&gt;sk131852: &lt;STRONG&gt;Updatable&lt;/STRONG&gt; Objects in R80.20 and above&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122636&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank"&gt;sk122636: How to troubleshoot &lt;STRONG&gt;Updatable&lt;/STRONG&gt; Objects in R80.20 and higher&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2020 12:24:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/updatable-objects-with-wildcard-entries/m-p/75874#M11686</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-02-20T12:24:22Z</dc:date>
    </item>
    <item>
      <title>Re: updatable objects with wildcard entries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/updatable-objects-with-wildcard-entries/m-p/92862#M11687</link>
      <description>&lt;P&gt;Same question here - I'm thinking about using updatable object for Zoom, but their list contains *.zoom.us.&lt;/P&gt;&lt;P&gt;I know that it is advised NOT to use non-FQDN Objects in Checkpoint R80.20 since every packet passing the firewall will be checked for reversed-dns lookup and can choke the firewall.&lt;/P&gt;&lt;P&gt;Would that also be the case with updatable objects when wildcard is present?&lt;/P&gt;&lt;P&gt;I couldn't find any answer to this in the links links G_W_Albrecht provided.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2020 12:40:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/updatable-objects-with-wildcard-entries/m-p/92862#M11687</guid>
      <dc:creator>Jonathan</dc:creator>
      <dc:date>2020-07-30T12:40:49Z</dc:date>
    </item>
    <item>
      <title>Re: updatable objects with wildcard entries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/updatable-objects-with-wildcard-entries/m-p/92871#M11688</link>
      <description>&lt;P&gt;&lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk163633&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank"&gt;sk163633:&amp;nbsp;&lt;STRONG&gt;Updatable&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;Objects&lt;/STRONG&gt;&amp;nbsp;for Zoom Services&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk135572&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank"&gt;sk135572: Microsoft Office 365 &lt;STRONG&gt;objects&lt;/STRONG&gt; as Network &lt;STRONG&gt;Objects&lt;/STRONG&gt; &lt;STRONG&gt;in&lt;/STRONG&gt; &lt;STRONG&gt;R80&lt;/STRONG&gt;.&lt;STRONG&gt;20&lt;/STRONG&gt; &lt;STRONG&gt;and&lt;/STRONG&gt; &lt;STRONG&gt;above&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2020 13:54:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/updatable-objects-with-wildcard-entries/m-p/92871#M11688</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-07-30T13:54:00Z</dc:date>
    </item>
    <item>
      <title>Re: updatable objects with wildcard entries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/updatable-objects-with-wildcard-entries/m-p/93119#M11689</link>
      <description>&lt;P&gt;Thanks for those links G_W_Albrecht, I've already read them but still don't have answer for my question -&amp;nbsp;&lt;/P&gt;&lt;P&gt;Checkpoint says these updateable objects contains list of IP addresses and DOMAINS. I've checked Zoom's list and it contains *.zoom.us.&lt;/P&gt;&lt;P&gt;Will the gateway treat this the same as a non-FQDN object and try to reverse-lookup for it on every packet?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 05:25:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/updatable-objects-with-wildcard-entries/m-p/93119#M11689</guid>
      <dc:creator>Jonathan</dc:creator>
      <dc:date>2020-08-03T05:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: updatable objects with wildcard entries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/updatable-objects-with-wildcard-entries/m-p/93137#M11690</link>
      <description>&lt;P&gt;Hi Markus_Kress,&lt;/P&gt;&lt;P&gt;I think you are looking for Domain Objects. These work like you mention, where the Gateway does a dns lookup for every FQDN, then caches it.&lt;/P&gt;&lt;P&gt;Updatable Objects work slightly differently, but on the same premise.&lt;/P&gt;&lt;P&gt;Some Services do not function with Domain objects, for various reasons, and we require the Updatable Objects.&lt;/P&gt;&lt;P&gt;These are a dynamic list of IP's that is provided as a service from Check Point. (No special licensing required)&lt;/P&gt;&lt;P&gt;We work with Vendors such as Zoom, Microsoft, and new vendors all the time.&lt;/P&gt;&lt;P&gt;They provide a list of IP's and Domains to us. -- We provide this to you, in the form of an Updatable Object.&lt;/P&gt;&lt;P&gt;We can see in&amp;nbsp;&lt;SPAN&gt;sk163633 --&amp;nbsp;Updatable Objects for Zoom Services&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"Zoom publishes a list of IP ranges and domains which are dynamically updated."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If more granular control is required, you will need to use Domain Objects, or reach out to your local SE, or TAC if this doesn't suit your needs.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 08:03:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/updatable-objects-with-wildcard-entries/m-p/93137#M11690</guid>
      <dc:creator>SSlater</dc:creator>
      <dc:date>2020-08-03T08:03:05Z</dc:date>
    </item>
    <item>
      <title>Re: updatable objects with wildcard entries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/updatable-objects-with-wildcard-entries/m-p/93140#M11691</link>
      <description>&lt;P&gt;Hi Stephen,&lt;/P&gt;&lt;P&gt;Thanks for reply, this is all very clear, but still you did not address both Markus_Kress and my issue.&lt;/P&gt;&lt;P&gt;Checkpoint recommends not to use Domain Objects in a Non-FQDN setting, which as I understand is kinda' the equivalent to a wildcard domain (*.zoom.us).&lt;/P&gt;&lt;P&gt;Updatable Objects also relay on list of domains which include wildcard.&lt;/P&gt;&lt;P&gt;We want to know how the gateway addresses these wildcards domain and can they also have negative impact on performance like Non-FQDN Domain Objects do?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 09:17:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/updatable-objects-with-wildcard-entries/m-p/93140#M11691</guid>
      <dc:creator>Jonathan</dc:creator>
      <dc:date>2020-08-03T09:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: updatable objects with wildcard entries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/updatable-objects-with-wildcard-entries/m-p/93142#M11692</link>
      <description>&lt;P&gt;This is not true -&amp;nbsp;&lt;SPAN&gt;Updatable Objects&amp;nbsp;are a dynamic list of IP's that is provided as a service from Check Point. So there are no wildcards and these are not Domain objects - it is always a list of IPs&amp;nbsp;8)&lt;/img&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I do not understand why this is so unclear although&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk131852&amp;amp;partition=Basic&amp;amp;product=Security" target="_blank" rel="noopener noreferrer"&gt;sk131852&lt;/A&gt;,&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk163633&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank" rel="noopener noreferrer"&gt;sk163633&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;and&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk135572&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank" rel="noopener noreferrer"&gt;sk135572&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;does explain that in detail ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 09:30:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/updatable-objects-with-wildcard-entries/m-p/93142#M11692</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-08-03T09:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: updatable objects with wildcard entries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/updatable-objects-with-wildcard-entries/m-p/93145#M11693</link>
      <description>&lt;P&gt;Well, I quote this from the links you've sent:&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;External services providers publish lists of IP addresses, or &lt;STRONG&gt;Domains&lt;/STRONG&gt;, or both,"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"This Zoom Updatable Object matches a list of IP addresses and &lt;STRONG&gt;domains&lt;/STRONG&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Each Office 365 Updatable Object matches a list of IP addresses and &lt;STRONG&gt;Domains&lt;/STRONG&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And if you follow the link from Checkpoint's Import dialog box, to Zoom's firewall setting webpage you can see even see that *.zoom.us is part of the list.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This was also the original question of Markus_Kress regarding Office365.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 09:54:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/updatable-objects-with-wildcard-entries/m-p/93145#M11693</guid>
      <dc:creator>Jonathan</dc:creator>
      <dc:date>2020-08-03T09:54:27Z</dc:date>
    </item>
    <item>
      <title>Re: updatable objects with wildcard entries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/updatable-objects-with-wildcard-entries/m-p/93146#M11694</link>
      <description>&lt;P&gt;In this context, "domain" means FQDN.&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;is correct, Updatable objects contain a list of IP addresses. If you experience any connectivity issue with updatable objects, please raise those issues with TAC&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 10:01:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/updatable-objects-with-wildcard-entries/m-p/93146#M11694</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-08-03T10:01:14Z</dc:date>
    </item>
    <item>
      <title>Re: updatable objects with wildcard entries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/updatable-objects-with-wildcard-entries/m-p/93208#M11695</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/42085"&gt;@Jonathan&lt;/a&gt;&amp;nbsp;Thanks for your clarification. I had focused on "&lt;SPAN&gt;Can someone explain how the updatable object mechanism works?"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Updatable objects should not have a negative impact on performance like Non-FQDN Domain Objects.&amp;nbsp; &amp;nbsp;--- We should not consider them equivalents.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you see degredation, or performance impact when using them, contact TAC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regardless of the content of the actual Updatable Object, Whether IP's or Domains;&amp;nbsp; &amp;nbsp;Fortunately for us, from the FW/Traffic perspective, this should not have any difference in behavior.&amp;nbsp; --- If you see any issues that would constitute "Updatable Objects do not have consistent Matching behavior when used in Rulebase" -- A TAC case should be raised with a similar title.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 00:32:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/updatable-objects-with-wildcard-entries/m-p/93208#M11695</guid>
      <dc:creator>SSlater</dc:creator>
      <dc:date>2020-08-04T00:32:19Z</dc:date>
    </item>
  </channel>
</rss>

