<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Implementing a rule for access to ever changing Mirror/Repository FQDNs, is it possible? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implementing-a-rule-for-access-to-ever-changing-Mirror/m-p/197578#M36919</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;CentOS uses YUM, there is an object for that. Have you tried allowing based on application object in AppCtrl instead?&lt;/P&gt;
&lt;P&gt;Erling&lt;/P&gt;</description>
    <pubDate>Thu, 09 Nov 2023 12:01:35 GMT</pubDate>
    <dc:creator>Erling_Strand</dc:creator>
    <dc:date>2023-11-09T12:01:35Z</dc:date>
    <item>
      <title>Implementing a rule for access to ever changing Mirror/Repository FQDNs, is it possible?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implementing-a-rule-for-access-to-ever-changing-Mirror/m-p/197575#M36918</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;We had a request to permit a system access to centos and dell mirror/repositories. The FQDN objects .centos.org and .dell.com were added to the destination of the rule.&lt;/P&gt;&lt;P&gt;The rule matched a lot of traffic, but it was evident that when the system pulled its updates, it was contacting a whole bunch of different mirror FQDN's that do not even contain relevant words.&lt;/P&gt;&lt;P&gt;And so this made me think an FQDN-object based rule is not possible for this scenario. And likely the IP's and FQDNs will continually change for such mirrors over time.&lt;/P&gt;&lt;P&gt;And so, other than changing the destination to permit all internet access, I cannot think of a more restrictive way to manage this access. Does such a way exist?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 11:33:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implementing-a-rule-for-access-to-ever-changing-Mirror/m-p/197575#M36918</guid>
      <dc:creator>Parabol</dc:creator>
      <dc:date>2023-11-09T11:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: Implementing a rule for access to ever changing Mirror/Repository FQDNs, is it possible?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implementing-a-rule-for-access-to-ever-changing-Mirror/m-p/197578#M36919</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;CentOS uses YUM, there is an object for that. Have you tried allowing based on application object in AppCtrl instead?&lt;/P&gt;
&lt;P&gt;Erling&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 12:01:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implementing-a-rule-for-access-to-ever-changing-Mirror/m-p/197578#M36919</guid>
      <dc:creator>Erling_Strand</dc:creator>
      <dc:date>2023-11-09T12:01:35Z</dc:date>
    </item>
    <item>
      <title>Re: Implementing a rule for access to ever changing Mirror/Repository FQDNs, is it possible?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implementing-a-rule-for-access-to-ever-changing-Mirror/m-p/197588#M36920</link>
      <description>&lt;P&gt;Hi Erling! Would the Yum AppCtrl object essentially permit any repository/mirror downloads, regardless of FQDN/IP, as long as it's initiated in the Yum utility? This could be viable if so..&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 12:50:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implementing-a-rule-for-access-to-ever-changing-Mirror/m-p/197588#M36920</guid>
      <dc:creator>Parabol</dc:creator>
      <dc:date>2023-11-09T12:50:05Z</dc:date>
    </item>
  </channel>
</rss>

