<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Updatable Objects for MS Teams matches Github in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244679#M47621</link>
    <description>&lt;P&gt;I totally agree, it is flaw in my view as well. Did you contact TAC about it?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 25 Mar 2025 11:55:36 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-03-25T11:55:36Z</dc:date>
    <item>
      <title>Updatable Objects for MS Teams matches Github</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244574#M47598</link>
      <description>&lt;P&gt;Hello Folks,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;just stumbled over a possible MS Teams problem a customer is fighting for months ...&lt;BR /&gt;sometime the&amp;nbsp;Updatable Objects IP matches on a different category ... then of course the policy doesnt match anymore, resulting in a drop.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;dynamic_objects -ip 52.113.83.112&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The following objects contain IP 52.113.83.112&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Object name: &lt;STRONG&gt;CP_MS_Skype&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Object type: Updatable Object&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Object name: CP_Azure_Azure&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Object type: Updatable Object&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Object name: &lt;STRONG&gt;CP_GH_GITHUB&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Object type: Updatable Object&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;so IP&amp;nbsp;52.113.83.112 should be an IP from the O365 MS Teams Range&amp;nbsp;52.122.0.0/15&lt;BR /&gt;&lt;A href="https://learn.microsoft.com/de-de/microsoft-365/enterprise/urls-and-ip-address-ranges?view=o365-worldwide" target="_blank"&gt;https://learn.microsoft.com/de-de/microsoft-365/enterprise/urls-and-ip-address-ranges?view=o365-worldwide&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;this results in a drop on my policy:&lt;BR /&gt;&lt;BR /&gt;@;81095432.634111613;[vs_0];[tid_19];[fw4_19];fw_log_drop_ex: Packet proto=6 10.10.42.68:57203 -&amp;gt; 52.113.83.112:3478 dropped by fw_send_log_drop Reason: Rulebase drop - on layer "POLICY" rule 922;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;did anybody notice this already as well?&lt;BR /&gt;i was always thinking this&amp;nbsp;Updatable Objects are quite reliable ... but why this IP can matche on sometimes totally different categories?&amp;nbsp;&lt;STRONG&gt;CP_GH_GITHUB &amp;amp;&amp;nbsp;CP_MS_Skype&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Mar 2025 12:05:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244574#M47598</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2025-03-24T12:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects for MS Teams matches Github</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244620#M47600</link>
      <description>&lt;P&gt;I assume you mean 52.112.0.0/14 and not 52.122.0.0/15 , 52.113.83.112 matches the first subnet.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issue is that Microsoft states it belongs to them and Github does the same, that it belongs to Github.. Since Github uses more specific subnet I would pick them. But anyway there is something strange going on, outside reach of Check Point. Check Point uses 3d party info to fill the tables. And if both tables claim the ip is for them what can you do &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Here you can find that Github uses 52.113.83.0/24&lt;/P&gt;
&lt;P&gt;&lt;A href="https://api.github.com/meta" target="_blank"&gt;https://api.github.com/meta&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Mar 2025 20:08:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244620#M47600</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-03-24T20:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects for MS Teams matches Github</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244635#M47611</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;from my experience in the case of MS products AppCtr definitions seems to be more accurate than UO.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Microsoft has lots of those networks to use:&lt;/P&gt;&lt;P&gt;&lt;A href="https://search.arin.net/rdap/?query=52.113.83.0" target="_blank"&gt;https://search.arin.net/rdap/?query=52.113.83.0&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Mar 2025 22:29:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244635#M47611</guid>
      <dc:creator>JaAnd</dc:creator>
      <dc:date>2025-03-24T22:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects for MS Teams matches Github</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244636#M47612</link>
      <description>&lt;P&gt;Can you run command -&amp;gt; dynamic_objects -uo "whatever name of github updatable object"&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 24 Mar 2025 22:43:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244636#M47612</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-24T22:43:24Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects for MS Teams matches Github</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244651#M47617</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;well yes:&lt;BR /&gt;the thing is ... both Updateable Objects contain both subnets ... based on my policy it sometimes matches the subnet on "Microsoft Teams Worldwide" then on "GitHub Services"&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;[Expert@XXXXXXXXXXXX:0:ACTIVE]# dynamic_objects -uo "GitHub Services" | grep 52.113&lt;BR /&gt;range 1037 : 52.113.9.0 52.113.9.255&lt;BR /&gt;range 1038 : 52.113.12.0 52.113.12.255&lt;BR /&gt;range 1039 : 52.113.16.0 52.113.31.255&lt;BR /&gt;range 1040 : 52.113.37.0 52.113.63.255&lt;BR /&gt;range 1041 : 52.113.69.0 52.113.69.255&lt;BR /&gt;&lt;STRONG&gt;range 1042 : 52.113.83.0 52.113.83.255&lt;/STRONG&gt;&lt;BR /&gt;range 1043 : 52.113.85.0 52.113.86.255&lt;BR /&gt;range 1044 : 52.113.112.0 52.113.127.255&lt;BR /&gt;range 1045 : 52.113.129.0 52.113.130.255&lt;BR /&gt;range 1046 : 52.113.135.0 52.113.151.255&lt;BR /&gt;range 1047 : 52.113.160.0 52.113.191.255&lt;BR /&gt;range 1048 : 52.113.198.0 52.113.199.255&lt;BR /&gt;range 1049 : 52.113.205.0 52.113.206.255&lt;BR /&gt;range 1050 : 52.113.208.0 52.113.223.255&lt;BR /&gt;&lt;BR /&gt;[Expert@XXXXXXXXXXXX:0:ACTIVE]# dynamic_objects -uo "Microsoft Teams Worldwide" | grep 52.1&lt;BR /&gt;&lt;STRONG&gt;range 0 : 52.112.0.0 52.115.255.255&lt;/STRONG&gt;&lt;BR /&gt;range 1 : 52.122.0.0 52.123.255.255&lt;BR /&gt;&lt;BR /&gt;when it matches on Github it results in a drop ... because the existing Github Rule does not contain the services used for MS Teams and the packet matches again on the CleanUP rule ... sure i could move around some rules ... but i consider this as a flaw ..&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2025 07:14:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244651#M47617</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2025-03-25T07:14:46Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects for MS Teams matches Github</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244679#M47621</link>
      <description>&lt;P&gt;I totally agree, it is flaw in my view as well. Did you contact TAC about it?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2025 11:55:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244679#M47621</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-25T11:55:36Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects for MS Teams matches Github</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244680#M47622</link>
      <description>&lt;P&gt;I also tried grepping for teams with that command, but nothing came up, but those IPs definitely match.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2025 11:57:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244680#M47622</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-25T11:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects for MS Teams matches Github</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244685#M47623</link>
      <description>&lt;P&gt;Well yes, i bet its time to contact TAC.&lt;BR /&gt;i will keep you informed...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2025 12:51:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244685#M47623</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2025-03-25T12:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects for MS Teams matches Github</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244686#M47624</link>
      <description>&lt;P&gt;Thanks so much Thomas, Im also super curious about this.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2025 12:52:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244686#M47624</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-25T12:52:33Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects for MS Teams matches Github</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244716#M47630</link>
      <description>&lt;P&gt;We use the information provided by the relevant vendor for our Updatable Objects.&lt;BR /&gt;If there are errors in that data...&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2025 16:05:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244716#M47630</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-03-25T16:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects for MS Teams matches Github</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244717#M47631</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;I suppose no way around it other than modifying the rules?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2025 17:09:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244717#M47631</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-25T17:09:50Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects for MS Teams matches Github</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244772#M47640</link>
      <description>&lt;P&gt;Hello Guys,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;well i see NO reason to change any rules, because the policy matching, or lets say, which Updateable Object the FW chooses for policy matching is changing from session to session.&lt;BR /&gt;&lt;BR /&gt;take a look:&lt;BR /&gt;my logging resulsts, during a MS teams call.&lt;BR /&gt;SRC: 10.10.42.68 and DST: 52.113.83.112&lt;BR /&gt;sometimes accept, sometimes drop.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Logs1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30022i0D15A4DF62B02BBA/image-size/large?v=v2&amp;amp;px=999" role="button" title="Logs1.png" alt="Logs1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditor_4b2e77c9613e7aThomas_Eichelbu_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;fist the accept, it matches on &lt;STRONG&gt;MS Teams&lt;/STRONG&gt; ...&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="logs2.png" style="width: 813px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30025iA0781C3057977070/image-size/large?v=v2&amp;amp;px=999" role="button" title="logs2.png" alt="logs2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;then the drop:&lt;BR /&gt;same SRC &amp;amp; same DST. just new SRC port, so lets say a new connection ...&lt;BR /&gt;but is says Github this time ...&amp;nbsp;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Log3.png" style="width: 657px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30026i1EEF87CAC9C0D110/image-size/large?v=v2&amp;amp;px=999" role="button" title="Log3.png" alt="Log3.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;lets see what TAC can do here, since the firewall changes its match on the DST IP from time to time.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 08:57:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244772#M47640</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2025-03-26T08:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects for MS Teams matches Github</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244795#M47643</link>
      <description>&lt;P&gt;I agree with you, rules look fine.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 10:44:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-for-MS-Teams-matches-Github/m-p/244795#M47643</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-26T10:44:43Z</dc:date>
    </item>
  </channel>
</rss>

