<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Create whitelist for single IP when using Geo-blocking objects in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265397#M53582</link>
    <description>&lt;P&gt;So there is no way to remove just 1 IP from a geo block list and let that IP run through the rest of the rule base?&lt;/P&gt;&lt;P&gt;This feels like such a simple ask as well.&lt;/P&gt;&lt;P&gt;I will do what I did with this one, build an inline rule above the Geo Block with just the correct rules for this IP, and hope we don't get too many IPs we need to add to our exception list.&lt;/P&gt;</description>
    <pubDate>Tue, 16 Dec 2025 09:19:50 GMT</pubDate>
    <dc:creator>Secret-goblin-5</dc:creator>
    <dc:date>2025-12-16T09:19:50Z</dc:date>
    <item>
      <title>Create whitelist for single IP when using Geo-blocking objects</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265190#M53575</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-12-12 135538.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32411iFA412C289216A34D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2025-12-12 135538.png" alt="Screenshot 2025-12-12 135538.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We have a geo blocking rule, so far so simple.&lt;/P&gt;&lt;P&gt;However, we now have 1 specific IP which needs to&amp;nbsp;get to the rest of the rules below the geo blocking rule... but is from one of the countries which we block.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do I add an exception for specific IPs to the geo blocking rule, while still having all the other rules below the geo blocking function?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2025 13:58:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265190#M53575</guid>
      <dc:creator>Secret-goblin-5</dc:creator>
      <dc:date>2025-12-12T13:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: Create whitelist for single IP when using Geo-blocking objects</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265192#M53576</link>
      <description>&lt;P&gt;We just add bypass rules above the GeoBlock, like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GeoBypass.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32412iDA3875CB06BBF8B2/image-size/large?v=v2&amp;amp;px=999" role="button" title="GeoBypass.png" alt="GeoBypass.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2025 14:12:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265192#M53576</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2025-12-12T14:12:33Z</dc:date>
    </item>
    <item>
      <title>Re: Create whitelist for single IP when using Geo-blocking objects</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265193#M53577</link>
      <description>&lt;P&gt;I cant see how this can work with rule below geo block, as first rule will always block the country. You need to add exception above.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2025 14:12:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265193#M53577</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-12T14:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: Create whitelist for single IP when using Geo-blocking objects</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265196#M53578</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the quick reply.&lt;/P&gt;&lt;P&gt;This works if you know exactly which service etc the allowed IP needs.&lt;BR /&gt;But we have 470 rules below the geo block I want the IP to be checked against.&lt;/P&gt;&lt;P&gt;I don't want to give it access to everything (HTTP(S) in your example) encase it gain access to something it should not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A workaround is to build an inline layer for just them above the geo block, with just the access they need.&lt;BR /&gt;Basically what you have, but more granular&lt;BR /&gt;But I would then need to build a new inline layer for every exception to our geo blocklist.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2025 14:22:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265196#M53578</guid>
      <dc:creator>Secret-goblin-5</dc:creator>
      <dc:date>2025-12-12T14:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: Create whitelist for single IP when using Geo-blocking objects</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265197#M53579</link>
      <description>&lt;P&gt;Right, but if you think about it, any fw policy goes top to bottom, left to right, so if you try an exception below that geo block rule, it will never work, since upper rule will always take effect first.&lt;/P&gt;
&lt;P&gt;Hope that makes sense.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2025 14:28:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265197#M53579</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-12T14:28:05Z</dc:date>
    </item>
    <item>
      <title>Re: Create whitelist for single IP when using Geo-blocking objects</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265198#M53580</link>
      <description>&lt;P&gt;Thats exactly how I do it and recommend to customers.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2025 15:12:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265198#M53580</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-12T15:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: Create whitelist for single IP when using Geo-blocking objects</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265245#M53581</link>
      <description>&lt;P&gt;That is true, but there is no sadly better choice. That is just how policy works with any fw vendor out there.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Dec 2025 13:46:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265245#M53581</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-13T13:46:56Z</dc:date>
    </item>
    <item>
      <title>Re: Create whitelist for single IP when using Geo-blocking objects</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265397#M53582</link>
      <description>&lt;P&gt;So there is no way to remove just 1 IP from a geo block list and let that IP run through the rest of the rule base?&lt;/P&gt;&lt;P&gt;This feels like such a simple ask as well.&lt;/P&gt;&lt;P&gt;I will do what I did with this one, build an inline rule above the Geo Block with just the correct rules for this IP, and hope we don't get too many IPs we need to add to our exception list.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 09:19:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265397#M53582</guid>
      <dc:creator>Secret-goblin-5</dc:creator>
      <dc:date>2025-12-16T09:19:50Z</dc:date>
    </item>
    <item>
      <title>Re: Create whitelist for single IP when using Geo-blocking objects</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265406#M53583</link>
      <description>&lt;P&gt;You cant do that. Again, think about it in logical way. Since any policy goes top to bottom, left to right, if country is blocked on the top of the rulebase, then ANY ip originating from that country would also be blocked, so adding exception BELOW such rule would never work, as initial rule would block the traffic.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 11:47:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265406#M53583</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-16T11:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: Create whitelist for single IP when using Geo-blocking objects</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265409#M53584</link>
      <description>&lt;P&gt;I think you misunderstand my ask.&lt;/P&gt;&lt;P&gt;I want to geo block all of Sweden&amp;nbsp;&lt;EM&gt;except&amp;nbsp;&lt;/EM&gt;IP 2.3.4.5 (for example)&lt;/P&gt;&lt;P&gt;Then have IP 2.3.4.5 move through the other ~450 rules until it is accepted or blocked.&lt;/P&gt;&lt;P&gt;I have been told this is not possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I will need to do instead is make a new inline rule for just IP 2.3.4.5 &lt;EM&gt;above&lt;/EM&gt; my geo block which gives it access to only what it needs, and then do this for every other IP I need to allow.&lt;/P&gt;&lt;P&gt;This increases the size of the policy, makes admin harder (if we add an object I need to add it to multiple whitelisted IPs) and is just uglier.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 12:08:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265409#M53584</guid>
      <dc:creator>Secret-goblin-5</dc:creator>
      <dc:date>2025-12-16T12:08:12Z</dc:date>
    </item>
    <item>
      <title>Re: Create whitelist for single IP when using Geo-blocking objects</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265410#M53585</link>
      <description>&lt;P&gt;Im totally clear mate &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I get what you are trying to do, thats why both&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/75772"&gt;@CaseyB&lt;/a&gt;&amp;nbsp; and I are saying you need to add exception for that IP ABOVE the geo block rule, there is no other way around it, You are more than welcome to open TAC case for this, but I can bet in any money I have they will tell you exact same thing.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 12:14:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265410#M53585</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-16T12:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: Create whitelist for single IP when using Geo-blocking objects</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265411#M53586</link>
      <description>&lt;P&gt;Okay, but the exception above it (obviously above) would be a blanket allow, it would not then take it through the other 450 rules.&lt;/P&gt;&lt;P&gt;The issue is I do not want to copy all 450 rules into a set of rules just for this IP, and I do not want to administer that many extra rules just for a single IP.&lt;/P&gt;&lt;P&gt;I want it to "skip" to geo blocking rule and move onto the one below it, not just be blanked accepted and never get checked against anything else. This is not possible, so I am accepting that my work load will increase for each outlier we have.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 12:19:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265411#M53586</guid>
      <dc:creator>Secret-goblin-5</dc:creator>
      <dc:date>2025-12-16T12:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: Create whitelist for single IP when using Geo-blocking objects</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265413#M53587</link>
      <description>&lt;P&gt;Just for the context, if traffic is blocked on any given rule, it will never check any more rules, thats it, so creating exception below block rule would be work for nothing.&lt;/P&gt;
&lt;P&gt;Just saying.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 12:28:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265413#M53587</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-16T12:28:04Z</dc:date>
    </item>
    <item>
      <title>Re: Create whitelist for single IP when using Geo-blocking objects</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265414#M53588</link>
      <description>&lt;P&gt;I know this, I want the exception to be above. I have always wanted that.&lt;/P&gt;&lt;P&gt;The problem is that the &lt;SPAN&gt;exception&amp;nbsp;&lt;/SPAN&gt;is a blanket allow, which I do NOT want.&lt;/P&gt;&lt;P&gt;I want it to flow through all the other rules encase one of those blocks it.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 12:30:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265414#M53588</guid>
      <dc:creator>Secret-goblin-5</dc:creator>
      <dc:date>2025-12-16T12:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: Create whitelist for single IP when using Geo-blocking objects</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265415#M53589</link>
      <description>&lt;P&gt;Ok, as long as you are aware of that, then you would need to somehow figure out best way to allow those exceptions (services etc...)&lt;/P&gt;
&lt;P&gt;Good luck!&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 12:47:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265415#M53589</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-16T12:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: Create whitelist for single IP when using Geo-blocking objects</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265457#M53590</link>
      <description>&lt;P&gt;The requirement is clear and we even have something that enables such things: "Group with Exclusions."&lt;BR /&gt;You create it like so:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32453iB250C5D6FB4A60E3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;This object requires two regular groups to be created and referenced:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The objects you want to be part of the group&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;The objects you want to be excluded&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Unfortunately, when I tried to do this using an Updatable Object in R82, I got the following error:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32454i76A9DA712CDBA522/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;This object type only supports groups with regular host/network objects.&lt;/P&gt;
&lt;P&gt;If you can find a feed of IP addresses for Sweden, you can use &lt;A href="https://github.com/CheckPointSW-Community/IPaddressFeed2CheckPoint" target="_blank"&gt;a script like the following for Office 365&lt;/A&gt;&amp;nbsp;referenced in &lt;A href="https://support.checkpoint.com/results/sk/sk167000" target="_blank"&gt;sk167000&lt;/A&gt;.&lt;BR /&gt;This will convert the feed into the necessary static objects that will allow this object type to be used.&lt;BR /&gt;You lose the dynamicness of the updatable object, of course, and any changes will require a policy push.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 17:41:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Create-whitelist-for-single-IP-when-using-Geo-blocking-objects/m-p/265457#M53590</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-12-16T17:41:01Z</dc:date>
    </item>
  </channel>
</rss>

