<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Best practice to add Geo Policy in R80.30 VSX in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practice-to-add-Geo-Policy-in-R80-30-VSX/m-p/137117#M55776</link>
    <description>&lt;P&gt;We added Geo Policy using default Profile and installed Policy on VS2.&lt;/P&gt;&lt;P&gt;IPS blade is enabled.&lt;/P&gt;&lt;P&gt;However Geo Policy is not enforced.&lt;/P&gt;&lt;P&gt;We started debugging using following SK (sk92823) and noticed Geo process is not running.&lt;/P&gt;&lt;P&gt;Can you confirm if using&amp;nbsp; Updatable object for Geo Policy in R80.30 only way to make Geo Policy work?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We also tried using updatable object and it dropped traffic.&lt;/P&gt;&lt;P&gt;We can access user center using VS0 (not from VS2, and VS2 is our FW)&lt;/P&gt;&lt;P&gt;We can also perform DNS Lookup from VS0&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;We ran unified_dl UPDATE ONLINE_SERVICES, and it shows completed successfully but&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;last_revision.xml file has a July 2020 timestamp.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Can you share tips as how to update last_revision.xml successfully?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Dec 2021 16:54:21 GMT</pubDate>
    <dc:creator>Habib_Rahman_TX</dc:creator>
    <dc:date>2021-12-23T16:54:21Z</dc:date>
    <item>
      <title>Best practice to add Geo Policy in R80.30 VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practice-to-add-Geo-Policy-in-R80-30-VSX/m-p/137117#M55776</link>
      <description>&lt;P&gt;We added Geo Policy using default Profile and installed Policy on VS2.&lt;/P&gt;&lt;P&gt;IPS blade is enabled.&lt;/P&gt;&lt;P&gt;However Geo Policy is not enforced.&lt;/P&gt;&lt;P&gt;We started debugging using following SK (sk92823) and noticed Geo process is not running.&lt;/P&gt;&lt;P&gt;Can you confirm if using&amp;nbsp; Updatable object for Geo Policy in R80.30 only way to make Geo Policy work?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We also tried using updatable object and it dropped traffic.&lt;/P&gt;&lt;P&gt;We can access user center using VS0 (not from VS2, and VS2 is our FW)&lt;/P&gt;&lt;P&gt;We can also perform DNS Lookup from VS0&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;We ran unified_dl UPDATE ONLINE_SERVICES, and it shows completed successfully but&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;last_revision.xml file has a July 2020 timestamp.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Can you share tips as how to update last_revision.xml successfully?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 16:54:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practice-to-add-Geo-Policy-in-R80-30-VSX/m-p/137117#M55776</guid>
      <dc:creator>Habib_Rahman_TX</dc:creator>
      <dc:date>2021-12-23T16:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice to add Geo Policy in R80.30 VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practice-to-add-Geo-Policy-in-R80-30-VSX/m-p/137148#M55777</link>
      <description>&lt;P&gt;Probably it is best to take it with TAC&lt;/P&gt;</description>
      <pubDate>Fri, 24 Dec 2021 08:45:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practice-to-add-Geo-Policy-in-R80-30-VSX/m-p/137148#M55777</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-12-24T08:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice to add Geo Policy in R80.30 VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practice-to-add-Geo-Policy-in-R80-30-VSX/m-p/137170#M55778</link>
      <description>&lt;P&gt;I was under impression that geo policy would be the same regardless of platform you are running, but I could be mistaken...I know starting in R80.20, its recommended to use updatable objects in the policy, but if you are saying that process is not even running, then definitely worth considering TAC case.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below is what TAC gave me few months back when customer had issues with geo updates and it did fix it (you do this on mgmt server, just make sure you backup thise directories first, in case or even do backup quickly)&lt;/P&gt;
&lt;P&gt;Procedure:&lt;BR /&gt;1. Change the name of the folder $MDS_FWDIR/conf/SMC_Files/uo to uo_original&lt;BR /&gt;2. Run cpstop &amp;amp;&amp;amp; cpstart on the mgmt server&lt;BR /&gt;3. Re-open updatable object picker&lt;BR /&gt;4. Make sure the $FWDIR/conf/SMC_Files/uo was created again&lt;BR /&gt;&lt;BR /&gt;These steps, should enforce the management server to re-download the Updatable Object package and should solve the issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Dec 2021 16:08:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practice-to-add-Geo-Policy-in-R80-30-VSX/m-p/137170#M55778</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-12-24T16:08:57Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice to add Geo Policy in R80.30 VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practice-to-add-Geo-Policy-in-R80-30-VSX/m-p/137599#M55779</link>
      <description>&lt;P&gt;Thank you.&amp;nbsp; I have a case open with TAC.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jan 2022 16:25:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practice-to-add-Geo-Policy-in-R80-30-VSX/m-p/137599#M55779</guid>
      <dc:creator>Habib_Rahman_TX</dc:creator>
      <dc:date>2022-01-03T16:25:26Z</dc:date>
    </item>
  </channel>
</rss>

