<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cheat sheet for &amp;quot;dynamic&amp;quot; type objects references in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/175860#M32115</link>
    <description>&lt;P&gt;good point! I'll need to collect info before I do &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Mar 2023 06:51:28 GMT</pubDate>
    <dc:creator>Kaspars_Zibarts</dc:creator>
    <dc:date>2023-03-23T06:51:28Z</dc:date>
    <item>
      <title>Cheat sheet for "dynamic" type objects references</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/175686#M32075</link>
      <description>&lt;P&gt;&lt;U&gt;&lt;FONT color="#FF0000"&gt;Updated May 2025!&lt;/FONT&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;I made presentation during CPX back in 2022 about the topic of objects that can keep rulebase up to date without actually installing policy (=helping automation and zero trust journey). There has been quite a few improvements since and I keep getting questions so I decided to make a reference point for myself here instead of trying to locate info every time I get asked&amp;nbsp;&lt;/P&gt;
&lt;TABLE style="width: 900px;" width="900"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="209"&gt;&lt;STRONG&gt;&lt;FONT size="2"&gt;Name&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="190"&gt;&lt;STRONG&gt;&lt;FONT size="2"&gt;Documentation&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="133"&gt;&lt;STRONG&gt;&lt;FONT size="2"&gt;Requirements&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="105"&gt;&lt;STRONG&gt;&lt;FONT size="2"&gt;Data formats&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="376"&gt;&lt;STRONG&gt;&lt;FONT size="2"&gt;Brief summary&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;Custom Intelligence Feeds (IoC)&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="190"&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk132193&amp;amp;partition=Basic&amp;amp;product=Anti-Virus," target="_blank" rel="noopener"&gt;&lt;FONT size="2"&gt;sk132193&lt;/FONT&gt;&lt;/A&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/IOC-Admin-Guide/Content/Topics/Introduction.htm" target="_self"&gt;Infinity IoC feeds&lt;/A&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;R80.30 + AB/AV blade&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;CSV or STIX XML&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="376"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;To be efficient, HTTPS inspection will be required&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;It can only block and cannot be used as an object in rules&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;CLI only (so each GW must be updated separately) before R81&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Supports many data types: IP, URL, domain, Hashes etc.&lt;BR /&gt;Infinity IoC feeds allows multiplexing of many external and internal feeds into one as well as publishing to be consumed by non-CP products and vendors.&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;Generic Datacenter object&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="190"&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk167210&amp;amp;partition=Basic&amp;amp;product=Quantum" target="_blank" rel="noopener"&gt;&lt;FONT size="2"&gt;sk167210&lt;/FONT&gt;&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;R81 + FW blade&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;JSON&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="376"&gt;&lt;FONT size="2"&gt;IP as source data only (no domains nor URLs)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Can be used in regular rules (drop and accept)&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="209"&gt;&lt;FONT size="2"&gt;External Network feed&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="190"&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Network_Feed.htm?tocpath=_____17" target="_blank" rel="noopener"&gt;&lt;FONT size="2"&gt;Security Management R81.20 Administration Guide&lt;/FONT&gt;&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;R81.20 + FW blade&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;Text or JSON&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="376"&gt;&lt;FONT size="2"&gt;Technically the same principle as Updatable Objects&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;IP and domains can be used as source data&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Can be used in regular rules&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Wildcards in domain names can be tricky, read manuals and test&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;Domain Objects (aka FQDN objects)&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="190"&gt;&lt;FONT size="2"&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120633&amp;amp;partition=Basic&amp;amp;product=Quantum" target="_blank" rel="noopener"&gt;sk120633&lt;/A&gt; - main article&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk161612&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank" rel="noopener"&gt;sk161612&lt;/A&gt; - DNS passive learning&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk161632&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank" rel="noopener"&gt;sk161632&lt;/A&gt; - domains tool&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;R80.10 + FW blade&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;CP Object&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="376"&gt;&lt;FONT size="2"&gt;Domain names only (not URLs)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Can be used in regular rules&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Wildcards (non-FQDN mode) can be tricky, read manuals and test&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Nothing to maintain externally&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;Dynamic Objects&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="190"&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=skI1915&amp;amp;partition=Basic&amp;amp;product=Quantum" target="_blank" rel="noopener"&gt;&lt;FONT size="2"&gt;skI1915&lt;/FONT&gt;&lt;/A&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk116367" target="_self"&gt;sk116367&lt;/A&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;R54 + FW blade&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;via CLI only&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="376"&gt;&lt;FONT size="2"&gt;IP as source data only (no domains nor URLs)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Can be used in regular rules (drop and accept)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;CLI updates only (so each GW must be updated separately) &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Must be scripted, won't update by itself&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;Updatable Objects&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="190"&gt;&lt;FONT size="2"&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk131852&amp;amp;partition=Basic&amp;amp;product=Quantum" target="_blank" rel="noopener"&gt;sk131852&lt;/A&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;R80.20 + FW blade&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;NA&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="376"&gt;&lt;FONT size="2"&gt;Pre-defined by Check Point, cannot be modified&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Can be used in regular rules to accept and drop&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;IoT Protect&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="190"&gt;&lt;FONT size="2"&gt;&lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Quantum-IoT-Admin-Guide/Topics-Admin-Guide/Introduction-to-Quantum-IoT-Protect.htm" target="_blank" rel="noopener"&gt;Quantum IoT Protect Administration Guide&lt;/A&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;FONT size="2"&gt;R81.20 + IOT blade&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;R81.10 is in EA&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;NA&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="376"&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Pre-defined by Check Point, cannot be modified&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Requires integration with CP Infinity cloud&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;License is required! All-in-one does not work&lt;/FONT&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;Identity Roles&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="190"&gt;&lt;A title="Identity Awareness R81.20 Administration Guide" href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_IdentityAwareness_AdminGuide/Content/Topics-IDAG/Introduction-to-Identity-Awareness.htm" target="_blank" rel="noopener"&gt;&lt;FONT size="2"&gt;Identity Awareness Administration Guide&amp;nbsp;&lt;/FONT&gt;&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;R77&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;NA&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="376"&gt;&lt;FONT size="2"&gt;External sources that will map users to IPs dynamically&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Whole separate&amp;nbsp;subject, but not to be forgotten&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;Data Center Query&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_CloudGuard_Controller_AdminGuide/Topics-CGRDG/Integrating-with-Data-Center-Servers.htm?TocPath=Integrating%20with%20Data%20Center%20Servers%7C_____2#Data_Center_Query_Objects" target="_blank" rel="noopener"&gt;Data Center Query Objects&lt;/A&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;R81.10&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;Tags obtained from DC&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;FONT size="2"&gt;&lt;SPAN class="Menu_Options"&gt;Query Object&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;based on attributes across multiple data centers&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Fri, 09 May 2025 07:50:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/175686#M32075</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2025-05-09T07:50:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cheat sheet for "dynamic" type objects references</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/175687#M32076</link>
      <description>&lt;P&gt;Thanks for this great overview!&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;BR /&gt;Could you please make the SKs clickable (&lt;EM&gt;add a link to them&lt;/EM&gt;)?&lt;BR /&gt;From my point of view these objects are dynamic as well:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Application Control objects and categories&lt;/LI&gt;
&lt;LI&gt;Custom application regex's&lt;/LI&gt;
&lt;LI&gt;IPS protections / Inspection settings&lt;/LI&gt;
&lt;LI&gt;Security zone objects&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 22 Mar 2023 09:06:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/175687#M32076</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2023-03-22T09:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cheat sheet for "dynamic" type objects references</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/175711#M32080</link>
      <description>&lt;P&gt;Nice one, &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11456"&gt;@Kaspars_Zibarts&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Fixed the table width, also I second the request to add links &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 11:36:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/175711#M32080</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-03-22T11:36:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cheat sheet for "dynamic" type objects references</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/175715#M32082</link>
      <description>&lt;P&gt;Very nice, thanks for sharing! &lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 11:42:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/175715#M32082</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-22T11:42:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cheat sheet for "dynamic" type objects references</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/175792#M32098</link>
      <description>&lt;P&gt;fixed! had very little time this morning, sorry &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 16:09:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/175792#M32098</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2023-03-22T16:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cheat sheet for "dynamic" type objects references</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/175860#M32115</link>
      <description>&lt;P&gt;good point! I'll need to collect info before I do &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 06:51:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/175860#M32115</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2023-03-23T06:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cheat sheet for "dynamic" type objects references</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/176316#M32275</link>
      <description>&lt;P&gt;Thanks for the great info!&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 14:35:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/176316#M32275</guid>
      <dc:creator>tibbe</dc:creator>
      <dc:date>2023-03-27T14:35:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cheat sheet for "dynamic" type objects references</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/176394#M32295</link>
      <description>&lt;P&gt;Very nice table!&lt;/P&gt;
&lt;P&gt;I am missing data center object and data center QUERY objects:&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_CloudGuard_Controller_AdminGuide/Topics-CGRDG/Integrating-with-Data-Center-Servers.htm?TocPath=Integrating%20with%20Data%20Center%20Servers%7C_____2#Data_Center_Query_Objects" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_CloudGuard_Controller_AdminGuide/Topics-CGRDG/Integrating-with-Data-Center-Servers.htm?TocPath=Integrating%20with%20Data%20Center%20Servers%7C_____2#Data_Center_Query_Objects&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Would be great to add it &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Thank you&lt;BR /&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 07:03:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/176394#M32295</guid>
      <dc:creator>Pavel_Krejci</dc:creator>
      <dc:date>2023-03-28T07:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cheat sheet for "dynamic" type objects references</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/198428#M37148</link>
      <description>&lt;P&gt;This is precisely what I was looking for. I think this table should be published as SK. Great job!&lt;/P&gt;&lt;P&gt;What about IP Block / URL block feature? As per &lt;A href="https://support.checkpoint.com/results/sk/sk103154" target="_blank"&gt;sk103154&lt;/A&gt; it is "R80.30 / R80.40 without Anti-Virus or Anti-Bot, no longer the best practice" but perhaps still worth mentioning.&lt;/P&gt;&lt;P&gt;P.S. Here is fresh recorded session on the same subject - &lt;A href="https://community.checkpoint.com/t5/API-CLI-Discussion/Dynamic-Updatable-and-API-Generated-Objects/m-p/196365" target="_self"&gt;Tips and Tricks for Dynamic, Updatable, and API-Generated Objects&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 20:31:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/198428#M37148</guid>
      <dc:creator>Sergej_Gurenko</dc:creator>
      <dc:date>2023-11-20T20:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cheat sheet for "dynamic" type objects references</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/198429#M37149</link>
      <description>&lt;P&gt;Great to hear that I just didn't waste my time for myself &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; will have to sit and update it!&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 20:41:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/198429#M37149</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2023-11-20T20:41:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cheat sheet for "dynamic" type objects references</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/206285#M38967</link>
      <description>&lt;P&gt;Hello, one quick question about dynamic objects. The customer is asking about managing the Check Point object using PUSH (e.g. MISP platform connecting to the CP and modifying the group of IPs directly) rather than PULL (e.g. checkpoint checking and downloading the feed from the Web server every N minutes). We have used PULL IoC feeds many times before, and the setup is clear.&lt;/P&gt;&lt;P&gt;I'm struggling to find an example of programming Check Point via the API - an example of REST code and authentication token generation. I tried to find an answer on &lt;A href="https://developer.checkpoint.com/" target="_blank"&gt;https://developer.checkpoint.com/&lt;/A&gt; but was quickly lost.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2024 12:49:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/206285#M38967</guid>
      <dc:creator>Sergej_Gurenko</dc:creator>
      <dc:date>2024-02-16T12:49:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cheat sheet for "dynamic" type objects references</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/206288#M38968</link>
      <description>&lt;P&gt;EXCELLENT query&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8698"&gt;@Sergej_Gurenko&lt;/a&gt;&amp;nbsp;. I had one customer ask me about it while back, but I never bothered to open TAC case about it, as it was more their curiosity if it was possible or not, but would be nice to know, for sure.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2024 13:04:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/206288#M38968</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-16T13:04:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cheat sheet for "dynamic" type objects references</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/206291#M38970</link>
      <description>&lt;P&gt;I'm not entirely sure how MISP is pushing data (API, file transfer?), apologies for ignorance &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;But the first thing that came to my mind was that MISP could push a text (API/file) to an intermediate server and CP could use external network feeds to read it. Then you kind of meet in the middle: MISP still does PUSH and CP does the PULL &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2024 13:19:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/206291#M38970</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2024-02-16T13:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cheat sheet for "dynamic" type objects references</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/206292#M38971</link>
      <description>&lt;P&gt;I found the "Introduction" and "Tips &amp;amp; Best Practices" sections in &lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/#tips_best_practices~v1.9.1%20" target="_self"&gt;Management API Reference&lt;/A&gt; fairly handy. As always, the ultimate answer would require a lab.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2024 13:27:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/206292#M38971</guid>
      <dc:creator>Sergej_Gurenko</dc:creator>
      <dc:date>2024-02-16T13:27:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cheat sheet for "dynamic" type objects references</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/206295#M38972</link>
      <description>&lt;P&gt;Great suggestion. But If i recall correctly, the whole PUSH vs PULL discussion started due to the debate on who will be responsible for maintaining the web server with feed file.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;I'm not a &lt;SPAN&gt;&lt;EM&gt;MISP&lt;/EM&gt; (Malware Information Sharing Platform) expert either, but i believe it has a built-in functionality to export anything into any format and store on the local or remote server:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="generating-iocs-to-export-in-json-format.jpg" style="width: 900px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24533i88F928D5060F58EE/image-size/large?v=v2&amp;amp;px=999" role="button" title="generating-iocs-to-export-in-json-format.jpg" alt="generating-iocs-to-export-in-json-format.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2024 13:37:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/206295#M38972</guid>
      <dc:creator>Sergej_Gurenko</dc:creator>
      <dc:date>2024-02-16T13:37:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cheat sheet for "dynamic" type objects references</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/206303#M38973</link>
      <description>&lt;P&gt;Technically you could even drop using SSH keys directly onto CP Mgmt, nothing to maintain &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; if SSH is supported by MISP&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2024 14:06:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/206303#M38973</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2024-02-16T14:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cheat sheet for "dynamic" type objects references</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/206307#M38974</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8698"&gt;@Sergej_Gurenko&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Let's be clear about the term "dynamic object" I actually blame our own&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11456"&gt;@Kaspars_Zibarts&lt;/a&gt;&amp;nbsp;for this confusion, because his post subject should say UPDATABLE objects, not DYNAMIC objects.&lt;BR /&gt;&lt;BR /&gt;Updatable objects are just that, a logical list of IPs from external feeds.&lt;BR /&gt;&lt;BR /&gt;You really need something else, and we do call it a "dynamic object". It is in essence a logical container defined on the GW itself via CLI commands. It preceded Updatable Objects for a couple of decades, actually.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Please look on the &lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_CLI_ReferenceGuide/Topics-CLIG/FWG/dynamic_objects.htm" target="_self"&gt;CLI syntax for dynamic objects in the documentation&lt;/A&gt;. However, since the tech is a bit old, you will have to write your own scripts to automate it.&lt;BR /&gt;&lt;BR /&gt;If you are looking for something with less automation effort, there is another thing you can leverage - &lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Generic-DC-Object.htm" target="_self"&gt;Generic Data Center Objects.&lt;/A&gt;&amp;nbsp;You will be able to feed info into json file to control it.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2024 14:46:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/206307#M38974</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-02-16T14:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cheat sheet for "dynamic" type objects references</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/206330#M38982</link>
      <description>&lt;P&gt;Pushing will require interacting with the Management API, which will include a policy installation to the relevant gateways.&lt;BR /&gt;Read the relevant API documentation:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;login:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html#web/login~v1.9.1%20" target="_self"&gt;https://sc1.checkpoint.com/documents/latest/APIs/index.html#web/login~v1.9.1%20&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;add-host:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html#web/add-host~v1.9.1%20" target="_self"&gt;https://sc1.checkpoint.com/documents/latest/APIs/index.html#web/add-host~v1.9.1%20&lt;/A&gt;&amp;nbsp;(can add to an existing group in the same call)&lt;/LI&gt;
&lt;LI&gt;publish:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html#web/publish~v1.9.1%20" target="_self"&gt;https://sc1.checkpoint.com/documents/latest/APIs/index.html#web/publish~v1.9.1%20&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;install-policy:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html#web/install-policy~v1.9.1%20" target="_self"&gt;https://sc1.checkpoint.com/documents/latest/APIs/index.html#web/install-policy~v1.9.1%20&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;logout:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html#web/logout~v1.9.1%20" target="_self"&gt;https://sc1.checkpoint.com/documents/latest/APIs/index.html#web/logout~v1.9.1%20&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;You will log in, add the hosts (one per API call), publish (should be done every ~100 or so calls for performance reasons).&lt;BR /&gt;Once you've published all the changes, you will need to install-policy on the relevant gateways.&lt;BR /&gt;Logout when done.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2024 19:02:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/206330#M38982</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-02-16T19:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cheat sheet for "dynamic" type objects references</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/248433#M48528</link>
      <description>&lt;P&gt;nice one! thanks - could you please edit "Dynamic Objects" SK? The link leads to a deleted article.&lt;/P&gt;&lt;P&gt;new one might be&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk116367" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk116367&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2025 11:39:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cheat-sheet-for-quot-dynamic-quot-type-objects-references/m-p/248433#M48528</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2025-05-08T11:39:47Z</dc:date>
    </item>
  </channel>
</rss>

