<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R81 geo policy in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/121078#M76721</link>
    <description>&lt;P&gt;Thats great it will be corrected, because I suspected something was wrong with that command in the sk.&lt;/P&gt;</description>
    <pubDate>Sun, 13 Jun 2021 21:24:34 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2021-06-13T21:24:34Z</dc:date>
    <item>
      <title>R81 geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110671#M76699</link>
      <description>&lt;P&gt;Hey everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know that&amp;nbsp;&lt;SPAN&gt;sk126172 says to use updatable objects and thats fine, but at the bottom if the article, it gives the procedure on how to unhide default geo policy tab in dashboard. Funny enough, customer has cloud instance, so we can do that, but, I thought based on reading the article that command is ran on gateway itself? Regardless, tried it and did not do anything...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;By the way, I had 2 R81 labs (one standalone and one distributed) and when I ran the commands, it messed something up that I had to disable IPS blade to get policy working again. Just sounds too coincidental that issue would happen literally 15 mins after running the script from the sk.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Anyone experienced something similar?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 18:32:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110671#M76699</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-02-12T18:32:48Z</dc:date>
    </item>
    <item>
      <title>Re: R81 geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110677#M76700</link>
      <description>&lt;P&gt;The mechanism is still there, we just hide it in the management UI in R81.&lt;/P&gt;
&lt;P&gt;And yes the legacy method is tied to IPS.&lt;BR /&gt;Believe it operates similar to Core IPS protections (ie requires an Access Policy install to make changes).&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 19:47:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110677#M76700</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-02-12T19:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: R81 geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110679#M76701</link>
      <description>&lt;P&gt;It's hidden for a reason. I'm following Check Point's recommendation. No issues with updatable objects so far.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10540i1BC7DE27E5205287/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 19:51:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110679#M76701</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2021-02-12T19:51:10Z</dc:date>
    </item>
    <item>
      <title>Re: R81 geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110682#M76702</link>
      <description>&lt;P&gt;Thanks for the responses guys, but that does not answer my question at all. I know I can use updatable objects, but had few customers where there was an issue...say specific country is blocked and just randomly, traffic is being allowed for no reason and TAC never found an explanation why. When we switched to default geo policy, worked fine. So again, seems like sk I indicated is not very useful, as it does not give the right procedure. Its highly unlikely commands are correct, considering I did it in 2 lab R81 setups and it failed in both...makes no sense.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 20:14:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110682#M76702</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-02-12T20:14:25Z</dc:date>
    </item>
    <item>
      <title>Re: R81 geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110684#M76703</link>
      <description>&lt;P&gt;That might just be a &lt;A href="https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97891/highlight/true#M19173" target="_self"&gt;visual issue&lt;/A&gt; which tricks you to think that traffic is accepted for a blocked country because you probably din't update the &lt;EM&gt;ip2country.csv&lt;/EM&gt; on your SmartCenter every night. I've created a&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/API-CLI-Discussion/One-liner-to-update-IpToCountry-data-on-Security-Managements/m-p/97922" target="_self"&gt;One-liner&lt;/A&gt; that solves this.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 20:24:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110684#M76703</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2021-02-12T20:24:48Z</dc:date>
    </item>
    <item>
      <title>Re: R81 geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110699#M76704</link>
      <description>&lt;P&gt;Danny&amp;nbsp; - off topic, but it looks like in your screenshot, rule 2, is the source a group of updatable objects?&amp;nbsp; Every time I've tried to group updatable geo objects, i receive a "field network object group members ...." error. so unfortunately i have ~100 objects in my geo rules.&amp;nbsp; R80.40&lt;/P&gt;</description>
      <pubDate>Sat, 13 Feb 2021 02:49:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110699#M76704</guid>
      <dc:creator>D_TK</dc:creator>
      <dc:date>2021-02-13T02:49:09Z</dc:date>
    </item>
    <item>
      <title>Re: R81 geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110701#M76705</link>
      <description>&lt;P&gt;Thats easy to fix...you say add countries to block via updatable objects and then allow all continents in the rule below. That actually works for the most part.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Feb 2021 02:53:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110701#M76705</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-02-13T02:53:21Z</dc:date>
    </item>
    <item>
      <title>Re: R81 geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110702#M76706</link>
      <description>&lt;P&gt;right, but in my block rule i have about 100 updatable country objects listed (which looks messy) because smartconsole won't let me create a group with updatable objects.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Feb 2021 02:56:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110702#M76706</guid>
      <dc:creator>D_TK</dc:creator>
      <dc:date>2021-02-13T02:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: R81 geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110703#M76707</link>
      <description>&lt;P&gt;Tell me about it :). I still recall similar things even back in R55 lol&lt;/P&gt;</description>
      <pubDate>Sat, 13 Feb 2021 03:05:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110703#M76707</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-02-13T03:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: R81 geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110704#M76708</link>
      <description>&lt;P&gt;But, in all seriousness, Im not joking now, you CAN do that. Here is how...super easy peasy. Highlight all those countries in the rule, then right click and select "group objects", give it a name, done. You are welcome : )&lt;/P&gt;</description>
      <pubDate>Sat, 13 Feb 2021 03:13:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110704#M76708</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-02-13T03:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: R81 geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110708#M76709</link>
      <description>&lt;P&gt;Doesn't work for me with updatable objects.&amp;nbsp; receive this error every time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-02-12 192045.jpg" style="width: 690px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10543iBE38F14D4B1E6EEB/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2021-02-12 192045.jpg" alt="Screenshot 2021-02-12 192045.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Feb 2021 03:22:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110708#M76709</guid>
      <dc:creator>D_TK</dc:creator>
      <dc:date>2021-02-13T03:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: R81 geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110709#M76710</link>
      <description>&lt;P&gt;Yes, you are right...I know this worked for me in R80.10, but I see it fails now in R80.40. Ah, Check Point...man, always something : ). Ok, let me test this tomorrow morning and I will update you.&lt;/P&gt;
&lt;P&gt;Happy weekend!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 13 Feb 2021 03:33:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110709#M76710</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-02-13T03:33:20Z</dc:date>
    </item>
    <item>
      <title>Re: R81 geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110716#M76711</link>
      <description>&lt;P&gt;1. The functionality is there. However the “legacy” ui was so front end in the ui, the product actually mis-guided the user to use the wrong thing. So we hidden the ui by default if you dont use it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;2. If you are fresh user, you will now be directed to use the right way and if you used the legacy, and dont want to migrate, we dont force you&lt;/P&gt;
&lt;P&gt;3. Please use the new way if you can because its the right way. In addition, &amp;nbsp;updateable objects are necessary for good use of the&amp;nbsp;&amp;nbsp;product in modern scenarios. If updateable objects dont work in good way, we are not aware and we need to fix it. So please assume that we expect them to work and if there are issues, open TAC case so that we can handle them&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Feb 2021 07:05:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110716#M76711</guid>
      <dc:creator>Dorit_Dor</dc:creator>
      <dc:date>2021-02-13T07:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: R81 geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110720#M76712</link>
      <description>&lt;P&gt;I never quite logically understand why Check Point does things like that. Arent customers entitled to know if a feature is broken or something could be wrong with it? I asked TAC person the other night specifically, point blank, what would be the reason that you guys would remove default geo policy in R81? He took few minutes, came back and said that he found some internal notes, but is not allowed to share them with customers. Imagine how uncomfortable that must feel for an engineer...they know the reason, but are not allowed to share it. I dont personally see how is that a good business practise.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyway, all Im trying to figure out is why the sk I attempted fails and no one in TAC seems to know or is willing to test. The best answer I got is "Well, it is a new product"...to which I respond "Well, you are making money off people selling it to them, so it would be honest thing to try and make it work"&lt;/P&gt;</description>
      <pubDate>Sat, 13 Feb 2021 12:25:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110720#M76712</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-02-13T12:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: R81 geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110721#M76713</link>
      <description>&lt;P&gt;Thank you for the feedback&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: inherit; background-color: #ffffff; -webkit-tap-highlight-color: transparent; -webkit-text-size-adjust: 100%;"&gt;The change was not supposed to be secret or hidden and it was not supposed to be hard to get answers on “why”&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: inherit; background-color: #ffffff; -webkit-tap-highlight-color: transparent; -webkit-text-size-adjust: 100%;"&gt;Therefore, we appreciate the report and will use it to learn what went wrong, improve documentation and improve the process going forward&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Dorit&lt;/P&gt;</description>
      <pubDate>Sat, 13 Feb 2021 14:58:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110721#M76713</guid>
      <dc:creator>Dorit_Dor</dc:creator>
      <dc:date>2021-02-13T14:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: R81 geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110722#M76714</link>
      <description>&lt;P&gt;Hi Dorit,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Im happy to give you my honest feedback offline, if you really care to know about it (you are more than welcome to message me privately offline). All I will say is this...there is RIGHT way of doing this and there is WRONG way of doing thigs. Sadly, my experience with lots of SKs and procedures in them, as well as way TAC does things, has not been a positive one and I can assure you, I am not the only one that says that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 13 Feb 2021 15:54:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110722#M76714</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-02-13T15:54:00Z</dc:date>
    </item>
    <item>
      <title>Re: R81 geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110727#M76715</link>
      <description>&lt;P&gt;Sorry to say this, but I dont think its possible...maybe if someone from escalations or R&amp;amp;D sees this thread, they can confirm, but I tried everything I can think of and no dice, apologies.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 13 Feb 2021 20:08:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110727#M76715</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-02-13T20:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: R81 geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110865#M76716</link>
      <description>&lt;P&gt;1. &lt;SPAN&gt;sk126172&amp;nbsp; stated that&lt;/SPAN&gt;&amp;nbsp;&lt;STRONG&gt;Starting from R81&lt;/STRONG&gt;&lt;SPAN&gt;, Geo Policy is hidden from the navigation pane if no rules are configured in that window. Geo Policy is now supported through Updatable Objects in the Access Control Policy. Geo Policy rules can still be configured in Updatable Objects as described above.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We are having offline discussion to learn why the communication went wrong and we will improve it&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. The other point here is that grouping (needed to manage large number of geographies) does not work. There is indeed issue w specific grouping of updateable objects (UI validation on grouping that is too strong).&amp;nbsp;The issue was already raised by others and grouping is supported in R81.10&amp;nbsp; (join the EA soon). Until then you can continue to use the old geo policy&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We appreciate the product feedback.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 07:03:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/110865#M76716</guid>
      <dc:creator>Dorit_Dor</dc:creator>
      <dc:date>2021-02-16T07:03:18Z</dc:date>
    </item>
    <item>
      <title>Re: R81 geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/120883#M76717</link>
      <description>&lt;P&gt;FYI: the sk126172 to unset Geo in R81 392 (had to enable it temporary to remove Geo logging) results in:&lt;/P&gt;
&lt;P&gt;"Failed to reload Env variables to CPM. Check /opt/CPsuite-R81/fw1/log/cpm.elg for errors."&lt;BR /&gt;The error is:&lt;BR /&gt;invalid format in line [unset disableHiddenGeoPolicy=1] in file [/opt/CPsuite-R81/fw1/conf/dynamic_system_env]&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jun 2021 17:19:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/120883#M76717</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2021-06-10T17:19:53Z</dc:date>
    </item>
    <item>
      <title>Re: R81 geo policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/121073#M76718</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11879"&gt;@Vladimir&lt;/a&gt;, thanks for bringing the issue to our attention, of course you are right and in the SK instead of:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;./reload_env_vars.sh -u "disableHiddenGeoPolicy=1"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It should have been&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;./reload_env_vars.sh -u "disableHiddenGeoPolicy"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I'll make sure to fix the SK as well.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 13 Jun 2021 15:25:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-geo-policy/m-p/121073#M76718</guid>
      <dc:creator>CPIshai</dc:creator>
      <dc:date>2021-06-13T15:25:08Z</dc:date>
    </item>
  </channel>
</rss>

