<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Updatable Objects - Audit changes and contents in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-Audit-changes-and-contents/m-p/217798#M41510</link>
    <description>&lt;P&gt;I figured the source files would probably be the most useful &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Jun 2024 16:07:56 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-06-17T16:07:56Z</dc:date>
    <item>
      <title>Updatable Objects - Audit changes and contents</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-Audit-changes-and-contents/m-p/217510#M41428</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have been looking at rolling out Updatable Objects on our firewall policies, specifically for Zscaler at the moment. Is there a way to:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Check in SmartConsole Logs when the Objects are changed/updated?&lt;/LI&gt;&lt;LI&gt;Interrogate the contents of the Updatable Object on the Gateways themselves?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;For context, I have looked at&amp;nbsp;&lt;SPAN&gt;sk131852 (&lt;A href="https://support.checkpoint.com/results/sk/sk131852" target="_blank" rel="noopener"&gt;Updatable Objects (checkpoint.com)&lt;/A&gt;),&amp;nbsp;sk173416 (&lt;A href="https://support.checkpoint.com/results/sk/sk173416" target="_blank" rel="noopener"&gt;How to manage access to external services using Updatable objects - FAQ (checkpoint.com)&lt;/A&gt;) and&amp;nbsp;sk161632 (&lt;A href="https://support.checkpoint.com/results/sk/sk161632" target="_blank" rel="noopener"&gt;Domains Tool (domains_tool) (checkpoint.com)&lt;/A&gt;). The Domains_Tool is useful but only shows that domains are used, not IP addresses.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The admin guides shows the following, but it does not seem to work for me, or I cannot filter enough to see it!:&lt;/P&gt;&lt;DIV class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-06-14_11-56-11.jpg" style="width: 571px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26254i0619A7C87C14F20A/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-06-14_11-56-11.jpg" alt="2024-06-14_11-56-11.jpg" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;The InfoSec team within my Company would like to be able to audit the Updatable Objects periodically to ensure the dynamic access granted is correct and appropriate. Any help on this would be gratefully received,&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;Andy&lt;/DIV&gt;</description>
      <pubDate>Fri, 14 Jun 2024 11:12:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-Audit-changes-and-contents/m-p/217510#M41428</guid>
      <dc:creator>Andrew_Rawlinso</dc:creator>
      <dc:date>2024-06-14T11:12:50Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects - Audit changes and contents</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-Audit-changes-and-contents/m-p/217583#M41461</link>
      <description>&lt;P&gt;You can use domains_tool to show you what IPs are associated with each domain.&lt;BR /&gt;The updatable objects are updated from files downloaded to&amp;nbsp;&lt;SPAN&gt;$CPDIR/database/downloads/ONLINE_SERVICES on the gateways.&lt;BR /&gt;The original source material for each of the Updatable Objects should be listed here: &lt;A href="https://support.checkpoint.com/results/sk/sk131852" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk131852&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2024 22:51:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-Audit-changes-and-contents/m-p/217583#M41461</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-14T22:51:51Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects - Audit changes and contents</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-Audit-changes-and-contents/m-p/217755#M41501</link>
      <description>&lt;P&gt;Thanks for the response. I can see within the "ONLINE_SERVICES" folders all the services listed:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="42ddf892-8cdd-4fa7-a7ce-7c3356da86b6.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26301i757C50621E4FEE07/image-size/medium?v=v2&amp;amp;px=400" role="button" title="42ddf892-8cdd-4fa7-a7ce-7c3356da86b6.jpg" alt="42ddf892-8cdd-4fa7-a7ce-7c3356da86b6.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If you "cat" one these services files you get the complete listing of domains and IPs associated with the services. &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-06-17_13-48-02.jpg" style="width: 926px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26302i9446935846621819/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-06-17_13-48-02.jpg" alt="2024-06-17_13-48-02.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;That should answer everything my infosec colleagues would required, so thanks for the point in the right direction. I appreciate it.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 12:53:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-Audit-changes-and-contents/m-p/217755#M41501</guid>
      <dc:creator>Andrew_Rawlinso</dc:creator>
      <dc:date>2024-06-17T12:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects - Audit changes and contents</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-Audit-changes-and-contents/m-p/217798#M41510</link>
      <description>&lt;P&gt;I figured the source files would probably be the most useful &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 16:07:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-Audit-changes-and-contents/m-p/217798#M41510</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-17T16:07:56Z</dc:date>
    </item>
  </channel>
</rss>

