<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Geo policy in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Geo-policy/m-p/57555#M57560</link>
    <description>&lt;P&gt;Do you have such a long list in your Geo Policy?&lt;/P&gt;</description>
    <pubDate>Fri, 05 Jul 2019 14:57:04 GMT</pubDate>
    <dc:creator>Danny</dc:creator>
    <dc:date>2019-07-05T14:57:04Z</dc:date>
    <item>
      <title>Geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Geo-policy/m-p/57554#M57559</link>
      <description>&lt;P&gt;Good Morning,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to generate/extract the list of countries that we currently block under Geopolicy? we are running on R80.20.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 14:33:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Geo-policy/m-p/57554#M57559</guid>
      <dc:creator>Basilio_Alcant1</dc:creator>
      <dc:date>2019-07-05T14:33:07Z</dc:date>
    </item>
    <item>
      <title>Re: Geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Geo-policy/m-p/57555#M57560</link>
      <description>&lt;P&gt;Do you have such a long list in your Geo Policy?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 14:57:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Geo-policy/m-p/57555#M57560</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2019-07-05T14:57:04Z</dc:date>
    </item>
    <item>
      <title>Re: Geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Geo-policy/m-p/57556#M57561</link>
      <description>&lt;P&gt;yes we do, it s a very long list.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 15:23:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Geo-policy/m-p/57556#M57561</guid>
      <dc:creator>Basilio_Alcant1</dc:creator>
      <dc:date>2019-07-05T15:23:51Z</dc:date>
    </item>
    <item>
      <title>Re: Geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Geo-policy/m-p/57560#M57562</link>
      <description>&lt;P&gt;Getting this Geo Policy country list does not seem possible through the SmartConsole GUI or the API from what I can see.&lt;/P&gt;
&lt;P&gt;However this information can be pulled out of the compiled policy out on the gateway similarly to the &lt;A href="https://community.checkpoint.com/t5/Enterprise-Appliances-and-Gaia/One-liner-for-Address-Spoofing-Troubleshooting/m-p/33204?search-action-id=5809136351&amp;amp;search-result-uid=33204" target="_self"&gt;antispoofing configuration&lt;/A&gt;.&amp;nbsp; The file to look at on the gateway is $FWDIR/state/local/FW1/local.set.&amp;nbsp; There is a section called &lt;STRONG&gt;block_by_countries_protection&lt;/STRONG&gt; in that file that shows all the countries listed under "Policy for Specific Countries".&amp;nbsp; A fast way to access the list is the following command you can run on the gateway:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;grep country_dispaly_name $FWDIR/state/local/FW1/local.set&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;(Note that I did not make a typo in the above command, it truly is&lt;STRONG&gt; country_dispaly_name&lt;/STRONG&gt; in the file itself)&lt;/P&gt;
&lt;P&gt;Obviously this one-liner does not show direction of enforcement and action (Drop/Accept) but if you know that all countries listed have an action of Drop this should be sufficient.&lt;/P&gt;
&lt;P&gt;I sense an impending update to the ccc tool...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 15:24:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Geo-policy/m-p/57560#M57562</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-07-10T15:24:39Z</dc:date>
    </item>
    <item>
      <title>Re: Geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Geo-policy/m-p/57572#M57563</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/19304"&gt;@Basilio_Alcant1&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;Use this script on management server to show countries and country IP lists.&lt;/P&gt;
&lt;P&gt;This script lists all country entries from the file ip2country. csv and displays the countries sorted for R80.10+.&lt;BR /&gt;The country code can then be insert. For the selected country all IP Ranges are displayed.&lt;/P&gt;
&lt;P&gt;So you can find all IP range, which are blocked by GeoProtection for a country.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/API-CLI-Discussion-and-Samples/Bash-script-to-show-IP-ranges-for-countrys-from-GeoProtection/td-p/39667" target="_self"&gt;Bash script to show IP ranges for countrys from GeoProtection&lt;/A&gt;&lt;BR /&gt;or&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/API-CLI-Discussion-and-Samples/GEO-Location-Objects-in-Firewall-Policy-with-Dynamic-Objects/m-p/40647/highlight/true#M2730" target="_self"&gt;GEO Location Objects in Firewall Policy (with Dynamic Objects)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Heiko&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 18:10:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Geo-policy/m-p/57572#M57563</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-07-05T18:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: Geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Geo-policy/m-p/57923#M57564</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/19304"&gt;@Basilio_Alcant1&lt;/a&gt;&amp;nbsp;looks for a list of countries, not IP ranges.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 15:01:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Geo-policy/m-p/57923#M57564</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2019-07-10T15:01:44Z</dc:date>
    </item>
    <item>
      <title>Re: Geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Geo-policy/m-p/57925#M57565</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;senses are powerful. Solution here:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Enterprise-Appliances-and-Gaia/One-liner-to-show-Geo-Policy-on-gateways/m-p/57922#M4339" target="_self"&gt;&lt;SPAN&gt;One-liner to show Geo Policy on gateways&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-2214-common-check-point-commands-ccc" target="_blank" rel="noopener"&gt;ccc script&lt;/A&gt;&lt;/STRONG&gt; updated.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 15:04:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Geo-policy/m-p/57925#M57565</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2019-07-10T15:04:40Z</dc:date>
    </item>
  </channel>
</rss>

