<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Updateable Objects - Office 365 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updateable-Objects-Office-365/m-p/243455#M47302</link>
    <description>&lt;P&gt;I will say in general they work well for us - I am sure however that we also in some cases have broad firewall rules somewhere below in the rule base catching any missing IP missed by the&amp;nbsp;&lt;SPAN class="lia-message-unread lia-message-unread-windows"&gt;Updateable Objects.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-message-unread lia-message-unread-windows"&gt;Some pitfalls we see, where some are listed directly, and some are implicit demands due to architecture:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-message-unread lia-message-unread-windows"&gt;- Are your outbound internet firewall using the same dns server as clients? If not, there could be cache/geo issues with lookups.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-message-unread lia-message-unread-windows"&gt;- Is it even the same firewall, the client and internet firewalls? Updateable Objects often contain wildcard fqdns. This requires &lt;A href="https://support.checkpoint.com/results/sk/sk161612" target="_self"&gt;DNS passive learning&lt;/A&gt; to work. If the firewalls are different there is no way to share Updatable Object information between them. A low key solution is to enable passive learning on both, and hope that your dns servers does not use &lt;SPAN class="ILfuVd"&gt;&lt;SPAN class="hgKElc"&gt;&lt;SPAN&gt;DoH, &lt;SPAN class="c5aZPb" data-enable-toggle-animation="true" data-extra-container-classes="ZLo7Eb" data-hover-hide-delay="1000" data-hover-open-delay="500" data-send-open-event="true" data-theme="0" data-width="250" data-ved="2ahUKEwiAjfmI-P-LAxWyzzgGHdJaFS8QmpgGegQIKxAD"&gt;&lt;SPAN class="JPfdse" data-bubble-link="" data-segment-text="DoT"&gt;DoT&lt;/SPAN&gt;&lt;/SPAN&gt;, or DNSCrypt&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;. But how is sync between the two firewalls ensured? and how do you measure it? Is FQDN resolved to cache at the same time for the two firewalls?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-message-unread lia-message-unread-windows"&gt;So in conclusion for clients asking the answer I give is always - It works, (maybe always?). Which is of course not the best answer in the world.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-message-unread lia-message-unread-windows"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-message-unread lia-message-unread-windows"&gt;Henrik&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 10 Mar 2025 16:43:25 GMT</pubDate>
    <dc:creator>Henrik_Noerr1</dc:creator>
    <dc:date>2025-03-10T16:43:25Z</dc:date>
    <item>
      <title>Updateable Objects - Office 365</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updateable-Objects-Office-365/m-p/243422#M47290</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;How accurate are the Update Objects for Microsoft&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can we be sure they cover the URLs listed in the Microsoft Documentation&lt;/P&gt;&lt;P&gt;Do they cover the&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Allow&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;and&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Optimise&amp;nbsp;&lt;/STRONG&gt;categories?&lt;/P&gt;&lt;P&gt;Many thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2025 12:14:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updateable-Objects-Office-365/m-p/243422#M47290</guid>
      <dc:creator>Networks_Team_B</dc:creator>
      <dc:date>2025-03-10T12:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: Updateable Objects - Office 365</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updateable-Objects-Office-365/m-p/243431#M47294</link>
      <description>&lt;P&gt;Check Point pulls directly from Microsoft for this information. sk131852 has more information including limitations.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk131852" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk131852&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 10 Mar 2025 13:13:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updateable-Objects-Office-365/m-p/243431#M47294</guid>
      <dc:creator>masher</dc:creator>
      <dc:date>2025-03-10T13:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: Updateable Objects - Office 365</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updateable-Objects-Office-365/m-p/243455#M47302</link>
      <description>&lt;P&gt;I will say in general they work well for us - I am sure however that we also in some cases have broad firewall rules somewhere below in the rule base catching any missing IP missed by the&amp;nbsp;&lt;SPAN class="lia-message-unread lia-message-unread-windows"&gt;Updateable Objects.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-message-unread lia-message-unread-windows"&gt;Some pitfalls we see, where some are listed directly, and some are implicit demands due to architecture:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-message-unread lia-message-unread-windows"&gt;- Are your outbound internet firewall using the same dns server as clients? If not, there could be cache/geo issues with lookups.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-message-unread lia-message-unread-windows"&gt;- Is it even the same firewall, the client and internet firewalls? Updateable Objects often contain wildcard fqdns. This requires &lt;A href="https://support.checkpoint.com/results/sk/sk161612" target="_self"&gt;DNS passive learning&lt;/A&gt; to work. If the firewalls are different there is no way to share Updatable Object information between them. A low key solution is to enable passive learning on both, and hope that your dns servers does not use &lt;SPAN class="ILfuVd"&gt;&lt;SPAN class="hgKElc"&gt;&lt;SPAN&gt;DoH, &lt;SPAN class="c5aZPb" data-enable-toggle-animation="true" data-extra-container-classes="ZLo7Eb" data-hover-hide-delay="1000" data-hover-open-delay="500" data-send-open-event="true" data-theme="0" data-width="250" data-ved="2ahUKEwiAjfmI-P-LAxWyzzgGHdJaFS8QmpgGegQIKxAD"&gt;&lt;SPAN class="JPfdse" data-bubble-link="" data-segment-text="DoT"&gt;DoT&lt;/SPAN&gt;&lt;/SPAN&gt;, or DNSCrypt&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;. But how is sync between the two firewalls ensured? and how do you measure it? Is FQDN resolved to cache at the same time for the two firewalls?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-message-unread lia-message-unread-windows"&gt;So in conclusion for clients asking the answer I give is always - It works, (maybe always?). Which is of course not the best answer in the world.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-message-unread lia-message-unread-windows"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-message-unread lia-message-unread-windows"&gt;Henrik&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2025 16:43:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updateable-Objects-Office-365/m-p/243455#M47302</guid>
      <dc:creator>Henrik_Noerr1</dc:creator>
      <dc:date>2025-03-10T16:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: Updateable Objects - Office 365</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updateable-Objects-Office-365/m-p/243476#M47309</link>
      <description>&lt;P&gt;From all I had seen in R81.20 and R82, they are very accurate.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2025 22:29:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updateable-Objects-Office-365/m-p/243476#M47309</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-10T22:29:58Z</dc:date>
    </item>
  </channel>
</rss>

