<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Geo Policy question:  New deployment using geo objects only (R80.30) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-question-New-deployment-using-geo-objects-only-R80-30/m-p/154475#M26185</link>
    <description>&lt;P&gt;It's now downloaded via a different mechanism.&lt;BR /&gt;The Troubleshooting section of the following SK should tell you what you need to know:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk131852" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk131852&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Aug 2022 20:05:22 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-08-03T20:05:22Z</dc:date>
    <item>
      <title>Geo Policy question:  New deployment using geo objects only (R80.30)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-question-New-deployment-using-geo-objects-only-R80-30/m-p/106755#M14265</link>
      <description>&lt;P&gt;My current company recently wanted to start implementing geo based updatable object rules following SK126172 (&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk126172&amp;amp;partition=Basic&amp;amp;product=Security" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk126172&amp;amp;partition=Basic&amp;amp;product=Security&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;During my PTO, our security team deployed a set of rules to one one country (Russia) and it looks to be working right now.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;I was checking logs and noticed that there were a few IP addresses that were being blocked but listed as another country:&lt;/P&gt;&lt;P&gt;Example:&amp;nbsp; 85.209.0.186&lt;/P&gt;&lt;P&gt;1) Our gateway is blocking this thinking its in Russia&lt;/P&gt;&lt;P&gt;2) Our 'flag' from the smartconsole logs is showing this in "Saudi Arabia"&lt;/P&gt;&lt;P&gt;3) MaxMind site states this is in Country Code of "CZ" and Location of "&lt;SPAN&gt;Czechia,&lt;/SPAN&gt;&lt;SPAN&gt;Europe"&amp;nbsp; (Using link:&amp;nbsp;&lt;A href="https://www.maxmind.com/en/geoip-demo" target="_blank" rel="noopener"&gt;https://www.maxmind.com/en/geoip-demo&lt;/A&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I started to think that its possible that the ip list was not being updated from the gateways and stated to look at SK114216 (&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114216&amp;amp;partition=Advanced&amp;amp;product=IPS" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114216&amp;amp;partition=Advanced&amp;amp;product=IPS&lt;/A&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Based on that SK, I looked at the 'in.geod' process and the file locations mentioned and none of the GWs have I have checked have this running nor have the files in place (&lt;EM&gt;$FWDIR/tmp/geo_location_tmp/updates/IpToCountry.csv)&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Since this was a brand new geo deployment, the shared "Geo Policy" activation mode it still set to "inactive' (First screen shot) and I can't seem to find documentation on where having the activation is required (i.e. no mention on&amp;nbsp;SK126172 and can't seem to find in deployment docs).&lt;/P&gt;&lt;P&gt;I have checked my 80.40 lab and I do see that when I set the geo policy to "Monitor Only" and leaving the rest as default. my lab gateway shows the daemon running and the updated file list within 24 hours like SK114216 mentions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So my long question is this:&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&amp;nbsp;Is there a Geo Policy activation requirement when using&amp;nbsp;geo based updatable object rules following SK126172 &amp;nbsp;&lt;OL&gt;&lt;LI&gt;I.E&amp;nbsp; setting to "monitor only" and using the updatable object method only in access rules&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;If there is no requirement on the Geo Policy activation, how can I validate proper updates of the IP country list against the MaxMind DB since&amp;nbsp;SK114216 shows no list updates?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Thank in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Dec 2020 19:59:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-question-New-deployment-using-geo-objects-only-R80-30/m-p/106755#M14265</guid>
      <dc:creator>Scottc98</dc:creator>
      <dc:date>2020-12-31T19:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: Geo Policy question:  New deployment using geo objects only (R80.30)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-question-New-deployment-using-geo-objects-only-R80-30/m-p/106756#M14266</link>
      <description>&lt;P&gt;First of all, for R80.20 and above, you should be using Updatable Objects in your regular access policy versus the legacy Geo Policy mechanism.&lt;BR /&gt;You can create a very granular policy in this manner (e.g. allow access to a specific website from anywhere but block all other access to/from a specific country).&lt;/P&gt;
&lt;P&gt;The flags come from management which does NOT update its IP to Country mappings regularly.&lt;BR /&gt;This one liner should update it:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/API-CLI-Discussion/One-liner-to-update-IpToCountry-data-on-Security-Managements/m-p/97922#M5202" target="_blank"&gt;https://community.checkpoint.com/t5/API-CLI-Discussion/One-liner-to-update-IpToCountry-data-on-Security-Managements/m-p/97922#M5202&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Dec 2020 20:15:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-question-New-deployment-using-geo-objects-only-R80-30/m-p/106756#M14266</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-31T20:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: Geo Policy question:  New deployment using geo objects only (R80.30)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-question-New-deployment-using-geo-objects-only-R80-30/m-p/106762#M14268</link>
      <description>&lt;P&gt;Thank you PhoneBoy for the update.&amp;nbsp; &amp;nbsp; I wanted to make sure nothing was missed during the deployment and if all we have to do is use the objects per&amp;nbsp;&lt;SPAN&gt;SK126172.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am wondering if there is a database of change records within MaxMinds DB that I can match the log entry I see and validate if it was flagged as "russia" at the timestamp it was blocked.&amp;nbsp; &amp;nbsp; Using the example IP in the post, if I can see that at that exact time we blocked it, it was flagged as "russia' even though our 'flag' in the logs showed "Saudi Arabia", I'll feel a little better &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;With the 80.40 lab I am using with Geo policy in 'monitor only', I am blocking more countries than our prod environment and all of those blocks are indeed matching the countries i have in the rules with no need to make any update on the management server.&amp;nbsp; &amp;nbsp; &amp;nbsp;While my lab will generate far less than our prod environment, it seemed odd that all of those logs matched the country flags while my prod environment did not.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;That being said, I did check the file on the lab 80.40 management and it is old (Jan 2020)&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[Expert@LAB-MGMT:0]# ls -l $INDEXERDIR/conf/ip2country.csv&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;-rw-r----- 1 admin bin 13142995 Jan 17&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;2020 /opt/CPrt-R80.40/log_indexer/conf/ip2country.csv&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[Expert@LAB-MGMT:0]#&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;After running the script you mentioned, it's now updated:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[Expert@LAB-MGMT:0]# ls -l $INDEXERDIR/conf/ip2country.csv&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;-rwxrwx--- 1 admin root 12569389 Dec 31 12:46 /opt/CPrt-R80.40/log_indexer/conf/ip2country.csv&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[Expert@LAB-MGMT:0]# &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Are the missing flag logs in the management truly linked to updating of this file on the management server or is it related at all to DNS caching within smartconsole?&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;lastly, do you know if this update process has any plans to be automated in R81 or a future JHF for 80.40?&amp;nbsp; &amp;nbsp;I would have to agree that having to restart service each time here it not the idea way but I do appreciate the quick script to be able to update it from time to time &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Dec 2020 20:56:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-question-New-deployment-using-geo-objects-only-R80-30/m-p/106762#M14268</guid>
      <dc:creator>Scottc98</dc:creator>
      <dc:date>2020-12-31T20:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: Geo Policy question:  New deployment using geo objects only (R80.30)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-question-New-deployment-using-geo-objects-only-R80-30/m-p/106770#M14270</link>
      <description>&lt;P&gt;Yes, the country in the logs in the management are truly based on that file in the management server.&lt;BR /&gt;I'm not aware of specific plans to automate the update of this file, but it is relatively straightforward to update it manually on a regular basis.&amp;nbsp;&lt;BR /&gt;I do see the restart could be problematic.&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9372"&gt;@Tomer_Noy&lt;/a&gt;&amp;nbsp;is this something we can look at for the future?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jan 2021 00:10:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-question-New-deployment-using-geo-objects-only-R80-30/m-p/106770#M14270</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-01T00:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: Geo Policy question:  New deployment using geo objects only (R80.30)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-question-New-deployment-using-geo-objects-only-R80-30/m-p/106841#M14296</link>
      <description>&lt;P&gt;Today, we have two mechanisms that refer to countries so in some cases it can create confusion. However, we are working to improve that.&lt;/P&gt;
&lt;P&gt;The Updatable Objects rely on our cloud service to automatically update IPs for countries and common SaaS services. The gateway fetches the information regularly and the data is very accurate. This is used for enforcement. When a connection is matched on an Updatable Object, the gateway puts the name and flag of that object in special fields on the log. If you double-click a log, you will be able to see them.&lt;/P&gt;
&lt;P&gt;The other mechanism, is our UI resolving for IPs to countries. This is based on a csv file that is brought with the version installation. The resolving is done upon querying the log server and will return information for any IP, even if not matched by the geo-protection / Updatable Objects.&lt;/P&gt;
&lt;P&gt;Following previous feedback about confusion when the flags aren't accurate, or don't match with the Updatable Objects, we are planning the following improvements:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;If a log was matched on an Updatable Object, we will show the icon from the Updatable Object, instead of resolving it from the csv. This will improve accuracy and consistency.&lt;/LI&gt;
&lt;LI&gt;We plan to update the .csv file regularly on JHFs and not just on a major version.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Sun, 03 Jan 2021 07:03:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-question-New-deployment-using-geo-objects-only-R80-30/m-p/106841#M14296</guid>
      <dc:creator>Tomer_Noy</dc:creator>
      <dc:date>2021-01-03T07:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: Geo Policy question:  New deployment using geo objects only (R80.30)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-question-New-deployment-using-geo-objects-only-R80-30/m-p/107824#M14473</link>
      <description>&lt;P&gt;Am I correct in assuming that the (possibly out of date) countries shown in the management logs are what would be forwarded to an external log server, e.g. if we Log Exporter to send our logs to Splunk?&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 13:53:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-question-New-deployment-using-geo-objects-only-R80-30/m-p/107824#M14473</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2021-01-14T13:53:10Z</dc:date>
    </item>
    <item>
      <title>Re: Geo Policy question:  New deployment using geo objects only (R80.30)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-question-New-deployment-using-geo-objects-only-R80-30/m-p/154471#M26183</link>
      <description>&lt;P&gt;Regarding the Updatable Objects using the cloud service to&amp;nbsp; automatically update IPs, a couple of questions:&lt;/P&gt;&lt;P&gt;1)&amp;nbsp; Does it still store the updated IPs for Geo Updatable Objects in the IpToCountry.csv on the gateway?&lt;/P&gt;&lt;P&gt;2)&amp;nbsp; If not, how can I tell if my IPs for Geo Updatable Objects are&amp;nbsp; up-to-date?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Q&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 17:07:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-question-New-deployment-using-geo-objects-only-R80-30/m-p/154471#M26183</guid>
      <dc:creator>Quentin_Antrim</dc:creator>
      <dc:date>2022-08-03T17:07:20Z</dc:date>
    </item>
    <item>
      <title>Re: Geo Policy question:  New deployment using geo objects only (R80.30)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-question-New-deployment-using-geo-objects-only-R80-30/m-p/154475#M26185</link>
      <description>&lt;P&gt;It's now downloaded via a different mechanism.&lt;BR /&gt;The Troubleshooting section of the following SK should tell you what you need to know:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk131852" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk131852&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 20:05:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-question-New-deployment-using-geo-objects-only-R80-30/m-p/154475#M26185</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-08-03T20:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: Geo Policy question:  New deployment using geo objects only (R80.30)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-question-New-deployment-using-geo-objects-only-R80-30/m-p/154479#M26186</link>
      <description>&lt;P&gt;Okay, thanks.&amp;nbsp; So, to answer my original question based upon that SK, it looks like the IP to Country mapping is in the&amp;nbsp;&lt;SPAN&gt;$CPDIR/database/downloads/ONLINE_SERVICES/1.0/&lt;EM&gt;latest&lt;/EM&gt;&lt;/SPAN&gt;&lt;EM&gt;versionnumber&lt;/EM&gt;&lt;SPAN&gt;/geo_location.C file now, rather than in the original CSV file.&amp;nbsp; &amp;nbsp;Thanks for the tip on that.&amp;nbsp; &amp;nbsp;I needed to prove that my gateway did indeed have the latest mappings, and I see that I'm good.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 20:34:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-question-New-deployment-using-geo-objects-only-R80-30/m-p/154479#M26186</guid>
      <dc:creator>Quentin_Antrim</dc:creator>
      <dc:date>2022-08-03T20:34:26Z</dc:date>
    </item>
  </channel>
</rss>

