<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic “Legacy GeoProtection Maximum Ranges” alert in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-GeoProtection-Maximum-Ranges-alert/m-p/261939#M51351</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;While reviewing the latest &lt;STRONG&gt;HCP report&lt;/STRONG&gt;, I noticed the following alert:&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;STRONG&gt;Legacy GeoProtection Maximum Ranges&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Description:&lt;/STRONG&gt;&lt;BR /&gt;This test verifies if legacy GeoProtection will be able to update successfully based on the &lt;EM&gt;geo_max_ip_ranges&lt;/EM&gt; kernel parameter.&lt;BR /&gt;&lt;STRONG&gt;Finding:&lt;/STRONG&gt;&lt;BR /&gt;The number of ranges in the current &lt;EM&gt;IpToCountry.csv&lt;/EM&gt; exceeds the maximum allowed value in kernel parameter: geo_max_ip_ranges.&lt;BR /&gt;&lt;STRONG&gt;Suggested Solution:&lt;/STRONG&gt;&lt;BR /&gt;Increase the value of kernel parameter geo_max_ip_ranges to be higher than the current number of ranges in IpToCountry.csv (341359).&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I’m curious about this alert because it references a &lt;STRONG&gt;kernel-level parameter&lt;/STRONG&gt; that seems to have a &lt;STRONG&gt;defined limit&lt;/STRONG&gt;, and I’m not sure what the implications might be of modifying it.&lt;/P&gt;&lt;P&gt;So, I wanted to ask:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;How safe is it to increase the value of the geo_max_ip_ranges parameter?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Would there be any noticeable performance or memory impact if we modify it?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Is there an alternative way to handle or suppress this alert?&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Any guidance or experience with this specific HCP finding would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Thu, 06 Nov 2025 02:16:10 GMT</pubDate>
    <dc:creator>jennyado</dc:creator>
    <dc:date>2025-11-06T02:16:10Z</dc:date>
    <item>
      <title>“Legacy GeoProtection Maximum Ranges” alert</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-GeoProtection-Maximum-Ranges-alert/m-p/261939#M51351</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;While reviewing the latest &lt;STRONG&gt;HCP report&lt;/STRONG&gt;, I noticed the following alert:&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;STRONG&gt;Legacy GeoProtection Maximum Ranges&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Description:&lt;/STRONG&gt;&lt;BR /&gt;This test verifies if legacy GeoProtection will be able to update successfully based on the &lt;EM&gt;geo_max_ip_ranges&lt;/EM&gt; kernel parameter.&lt;BR /&gt;&lt;STRONG&gt;Finding:&lt;/STRONG&gt;&lt;BR /&gt;The number of ranges in the current &lt;EM&gt;IpToCountry.csv&lt;/EM&gt; exceeds the maximum allowed value in kernel parameter: geo_max_ip_ranges.&lt;BR /&gt;&lt;STRONG&gt;Suggested Solution:&lt;/STRONG&gt;&lt;BR /&gt;Increase the value of kernel parameter geo_max_ip_ranges to be higher than the current number of ranges in IpToCountry.csv (341359).&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I’m curious about this alert because it references a &lt;STRONG&gt;kernel-level parameter&lt;/STRONG&gt; that seems to have a &lt;STRONG&gt;defined limit&lt;/STRONG&gt;, and I’m not sure what the implications might be of modifying it.&lt;/P&gt;&lt;P&gt;So, I wanted to ask:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;How safe is it to increase the value of the geo_max_ip_ranges parameter?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Would there be any noticeable performance or memory impact if we modify it?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Is there an alternative way to handle or suppress this alert?&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Any guidance or experience with this specific HCP finding would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2025 02:16:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-GeoProtection-Maximum-Ranges-alert/m-p/261939#M51351</guid>
      <dc:creator>jennyado</dc:creator>
      <dc:date>2025-11-06T02:16:10Z</dc:date>
    </item>
    <item>
      <title>Re: “Legacy GeoProtection Maximum Ranges” alert</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-GeoProtection-Maximum-Ranges-alert/m-p/261943#M51354</link>
      <description>&lt;P&gt;Personally, and this is just me, I would not bother with any of that. Its simply refers to ip ranges, but truth be told, literally 99% of customers would simply add countries they wish to block, which you can use updatable objects for, thats it.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2025 02:39:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-GeoProtection-Maximum-Ranges-alert/m-p/261943#M51354</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-06T02:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: “Legacy GeoProtection Maximum Ranges” alert</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-GeoProtection-Maximum-Ranges-alert/m-p/262068#M51402</link>
      <description>&lt;P&gt;Hi Jenn,&lt;/P&gt;
&lt;P&gt;I verified this with TAC and they confirmed that all that message says is that gateway's IPToCountry.csv file contains more ranges that what kernel parameter sllows, so its totally safe to change it to something higher, no issues.&lt;/P&gt;
&lt;P&gt;Here is an example in my lab:&lt;/P&gt;
&lt;P&gt;[Expert@CP-GW:0]# fw ctl get int geo_max_ip_ranges&lt;BR /&gt;geo_max_ip_ranges = 300000&lt;BR /&gt;[Expert@CP-GW:0]# fw ctl set -f int geo_max_ip_ranges 500000&lt;BR /&gt;"fwkern.conf" was updated successfully&lt;BR /&gt;[Expert@CP-GW:0]# more /opt/CPsuite-R82/fw1/boot/modules/fwkern.conf&lt;BR /&gt;sip_forward_if_needed=1&lt;BR /&gt;geo_max_ip_ranges=500000&lt;BR /&gt;[Expert@CP-GW:0]#&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2025 20:50:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-GeoProtection-Maximum-Ranges-alert/m-p/262068#M51402</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-06T20:50:52Z</dc:date>
    </item>
  </channel>
</rss>

