<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configuring geo policies in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-geo-policies/m-p/123862#M79499</link>
    <description>&lt;P&gt;I would like to add an additional question to this.&amp;nbsp; We currently utilize updatable objects to block specific countries that love to send their packets to us. We are on R80.40.&amp;nbsp; Looks like we have a customer in one of these blocked countries.&amp;nbsp;&lt;/P&gt;&lt;P&gt;To create an exception, can I just add an ALLOW rule containing their network/IP above my country blocking rule?&amp;nbsp; I don't know if there is additional logic or checks when implementing country blocking in the security rule set.&amp;nbsp; I am not using a specific Geo policy on my gateway, just a block rule with updatable country objs at the top of my rule list.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;JJ&lt;/P&gt;</description>
    <pubDate>Wed, 14 Jul 2021 21:09:02 GMT</pubDate>
    <dc:creator>JT_Ohio</dc:creator>
    <dc:date>2021-07-14T21:09:02Z</dc:date>
    <item>
      <title>Configuring geo policies</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-geo-policies/m-p/90222#M79494</link>
      <description>&lt;P&gt;This is my first time working with geo policies, now I'm trying to implement a geo policy that blocks traffic from Russia, I have a 5000 appliance&amp;nbsp; R80.10.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do I just have to configured it like this?&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="geo policy.png" style="width: 305px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7050i67D598193A88526B/image-dimensions/305x271?v=v2" width="305" height="271" role="button" title="geo policy.png" alt="geo policy.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="geopolicy.png" style="width: 736px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7051i6521686F13103200/image-size/large?v=v2&amp;amp;px=999" role="button" title="geopolicy.png" alt="geopolicy.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your help.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 16:27:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-geo-policies/m-p/90222#M79494</guid>
      <dc:creator>origins26</dc:creator>
      <dc:date>2020-06-30T16:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring geo policies</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-geo-policies/m-p/90543#M79495</link>
      <description>Should be able to.&lt;BR /&gt;However it might be better to upgrade to R80.20 or later and use the Updatable Objects for Russia in the access policy, which is far more flexible.</description>
      <pubDate>Sat, 04 Jul 2020 20:47:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-geo-policies/m-p/90543#M79495</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-07-04T20:47:51Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring geo policies</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-geo-policies/m-p/90573#M79496</link>
      <description>&lt;P&gt;Yes, but normally if you are blocking a country you want to block "from and to" to drop both connections initiated from that country, and any "phone home" attempts to that country initiated by malware already inside your network.&amp;nbsp; Also ensure that "Default Geo Policy" is applied to your firewall on the Gateways screen.&lt;/P&gt;
&lt;P&gt;As Phoneboy says though use of Geo Updatable Objects in the mainline Access Control policy in R80.20+ is much more flexible and easy to work with.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jul 2020 14:12:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-geo-policies/m-p/90573#M79496</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-07-05T14:12:03Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring geo policies</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-geo-policies/m-p/90607#M79497</link>
      <description>&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;As said above from R80.20 you can use updatable objects anywere in the rulebase.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="step1.png" style="width: 844px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7116iEB155539F8F46B6B/image-dimensions/844x165?v=v2" width="844" height="165" role="button" title="step1.png" alt="step1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="step2.png" style="width: 857px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7117i2FDE45951928E100/image-dimensions/857x576?v=v2" width="857" height="576" role="button" title="step2.png" alt="step2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="step3.png" style="width: 857px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7118i45702389FF7656F9/image-dimensions/857x345?v=v2" width="857" height="345" role="button" title="step3.png" alt="step3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="step4.png" style="width: 859px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7119i2332861115A284BF/image-dimensions/859x41?v=v2" width="859" height="41" role="button" title="step4.png" alt="step4.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jul 2020 22:45:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-geo-policies/m-p/90607#M79497</guid>
      <dc:creator>Magnus-Holmberg</dc:creator>
      <dc:date>2020-07-05T22:45:10Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring geo policies</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-geo-policies/m-p/90700#M79498</link>
      <description>&lt;P&gt;Thank you all of you.&lt;/P&gt;&lt;P&gt;As of now I'm not able to upgrade to 80.20, so I'll be working with 80.10, as you said I'm going to configure it to block&amp;nbsp;&lt;SPAN&gt;"from and to Country". I verified and Default Geo policiy is in the gateways screen.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="default.png" style="width: 606px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7130iD73976CC24455AEE/image-size/large?v=v2&amp;amp;px=999" role="button" title="default.png" alt="default.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 16:21:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-geo-policies/m-p/90700#M79498</guid>
      <dc:creator>origins26</dc:creator>
      <dc:date>2020-07-06T16:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring geo policies</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-geo-policies/m-p/123862#M79499</link>
      <description>&lt;P&gt;I would like to add an additional question to this.&amp;nbsp; We currently utilize updatable objects to block specific countries that love to send their packets to us. We are on R80.40.&amp;nbsp; Looks like we have a customer in one of these blocked countries.&amp;nbsp;&lt;/P&gt;&lt;P&gt;To create an exception, can I just add an ALLOW rule containing their network/IP above my country blocking rule?&amp;nbsp; I don't know if there is additional logic or checks when implementing country blocking in the security rule set.&amp;nbsp; I am not using a specific Geo policy on my gateway, just a block rule with updatable country objs at the top of my rule list.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;JJ&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 21:09:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-geo-policies/m-p/123862#M79499</guid>
      <dc:creator>JT_Ohio</dc:creator>
      <dc:date>2021-07-14T21:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring geo policies</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-geo-policies/m-p/124076#M79500</link>
      <description>&lt;P&gt;Correct, if you are using Geo Updatable objects in a policy rule to block a certain country just add an Accept rule above that one to implement the exception.&amp;nbsp; You may want to double-check that you are not also blocking that country in the legacy Geo Policy configuration, because if you are that block will be applied long before the rulebase gets evaluated.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jul 2021 12:04:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-geo-policies/m-p/124076#M79500</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-07-15T12:04:48Z</dc:date>
    </item>
  </channel>
</rss>

