<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GeoPolicy not working in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GeoPolicy-not-working/m-p/152580#M25448</link>
    <description>&lt;P&gt;hey,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;your Russia drop rules are positioned where, compared with the Allow rules that you show in the screenshots ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ty,&lt;/P&gt;</description>
    <pubDate>Fri, 08 Jul 2022 11:18:00 GMT</pubDate>
    <dc:creator>Sorin_Gogean</dc:creator>
    <dc:date>2022-07-08T11:18:00Z</dc:date>
    <item>
      <title>GeoPolicy not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GeoPolicy-not-working/m-p/152571#M25445</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So we have some rules to block all incoming and outgoing traffic to russia.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But after we see the logs we get a amount of Accepts coming from russia. Why is this happening and what should i do?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Best regards,&lt;/P&gt;&lt;P&gt;PF&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 10:31:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GeoPolicy-not-working/m-p/152571#M25445</guid>
      <dc:creator>pfilipe</dc:creator>
      <dc:date>2022-07-08T10:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: GeoPolicy not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GeoPolicy-not-working/m-p/152578#M25446</link>
      <description>&lt;P&gt;Is it an implied rule accepting the traffic?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 10:57:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GeoPolicy-not-working/m-p/152578#M25446</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2022-07-08T10:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: GeoPolicy not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GeoPolicy-not-working/m-p/152579#M25447</link>
      <description>&lt;P&gt;There are some Logs with implied yes but there are more logs with other rules.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 11:06:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GeoPolicy-not-working/m-p/152579#M25447</guid>
      <dc:creator>pfilipe</dc:creator>
      <dc:date>2022-07-08T11:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: GeoPolicy not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GeoPolicy-not-working/m-p/152580#M25448</link>
      <description>&lt;P&gt;hey,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;your Russia drop rules are positioned where, compared with the Allow rules that you show in the screenshots ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ty,&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 11:18:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GeoPolicy-not-working/m-p/152580#M25448</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-07-08T11:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: GeoPolicy not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GeoPolicy-not-working/m-p/152581#M25449</link>
      <description>&lt;P&gt;Hey,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;My Geopolicy rules is number 2 and 3.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ty&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 11:25:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GeoPolicy-not-working/m-p/152581#M25449</guid>
      <dc:creator>pfilipe</dc:creator>
      <dc:date>2022-07-08T11:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: GeoPolicy not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GeoPolicy-not-working/m-p/152582#M25450</link>
      <description>&lt;P&gt;OK, so first make sure that it isn't just a cosmetic issue as per&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120261&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_self"&gt;sk120261&lt;/A&gt;.&amp;nbsp; Check Point uses MaxMind for IP Geo-location, so doublecheck &lt;A href="https://www.maxmind.com/en/geoip-demo" target="_self"&gt;on their site&lt;/A&gt; as well.&lt;/P&gt;
&lt;P&gt;If everything checks out then you still need to keep in mind that updateable objects won't block traffic allowed by implied rules.&amp;nbsp; In order to work around that you can possibly do a rate-limiting SAM rule or use the "classic" geo policies.&lt;/P&gt;
&lt;P&gt;For traffic that is not being blocked and you are confident that it is not due to rule order I would say a call to TAC is in order.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 11:38:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GeoPolicy-not-working/m-p/152582#M25450</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2022-07-08T11:38:55Z</dc:date>
    </item>
    <item>
      <title>Re: GeoPolicy not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GeoPolicy-not-working/m-p/152586#M25451</link>
      <description>&lt;P&gt;I would run below script on mgmt if you can execute cpstop afterwards:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/API-CLI-Discussion/One-liner-to-update-IpToCountry-data-on-Security-Managements/m-p/97922" target="_blank"&gt;https://community.checkpoint.com/t5/API-CLI-Discussion/One-liner-to-update-IpToCountry-data-on-Security-Managements/m-p/97922&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I personally never experienced this issue myself, so hard to say for sure why those rules dont take full effect. As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9028"&gt;@Ruan_Kotze&lt;/a&gt;&amp;nbsp;indicated, if all fails, then contacting TAC might be your best option.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 13:00:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/GeoPolicy-not-working/m-p/152586#M25451</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-07-08T13:00:19Z</dc:date>
    </item>
  </channel>
</rss>

