<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Updatable Objects in VSX in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99502#M8665</link>
    <description>&lt;P&gt;Thank you very much&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11456"&gt;@Kaspars_Zibarts&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp; and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/2029"&gt;@Arne_Boettger&lt;/a&gt;&amp;nbsp; for the information.&lt;/P&gt;&lt;P&gt;I understand now based on your feedback that we do need to allow some traffic from each VS that uses Updatable Objects. Right now we have the following:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Access from virtual firewall (vs) to DNS servers for DNS requests&lt;/LI&gt;&lt;LI&gt;Access from virtual firewall (vs) to updates.checkpoint.com for HTTPS requests&lt;/LI&gt;&lt;LI&gt;NAT for internal network (192.168.196.0/22) to virtual firewall (vs) external interface&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Regarding the NAT of the internal addresses (192.168.196.0/22) we had to configure it to get the Updatable Objects working, but perhaps it was an order of operations issue. We will test to remove the NAT rule and see if we can get it to work. Could it potentially also be due to that we run an older JHA (118) for R80.20?&lt;/P&gt;&lt;P&gt;Thanks again for your help!&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Harry&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 19 Oct 2020 14:00:34 GMT</pubDate>
    <dc:creator>net-harry</dc:creator>
    <dc:date>2020-10-19T14:00:34Z</dc:date>
    <item>
      <title>Updatable Objects in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99187#M8654</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a question regarding updatable Objects in VSX. We needed to use this feature in one VS and had some trouble getting it working.&lt;/P&gt;&lt;P&gt;Initially we did not have DNS configured and followed sk121877 (Package of Updatable Objects is missing on the Security Gateway) to get last_revision.xml on the VSX hosts (vs 0).&lt;/P&gt;&lt;P&gt;However, things did not start working until we, with the help of TAC, created a NAT rule for the external interface of the VS and allowed traffic to Check Point also for that address.&lt;/P&gt;&lt;P&gt;My question is if/why we need to allow traffic from the VS to get Updatable Objects working in VSX? It would seem better if only the host (vs0) had access to Check Point to download updated and that the objects could then be used by any VS.&lt;/P&gt;&lt;P&gt;We are currently running R80.20 JHF 118.&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Harry&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2020 10:00:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99187#M8654</guid>
      <dc:creator>net-harry</dc:creator>
      <dc:date>2020-10-15T10:00:00Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99379#M8655</link>
      <description>&lt;P&gt;I presume the VS itself needs access to the Internet to use Updatable Objects the same way a VS needs access if you’re using many ThreatCloud features.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Oct 2020 05:42:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99379#M8655</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-18T05:42:16Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99406#M8656</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp; for the information!&lt;/P&gt;&lt;P&gt;Besides creating a rule for the virtual firewall (vs) to access Check Point cloud we also needed to create a NAT rule for the internal address (192.168.196.0/22) to translate to the external IP address of the vs in order to get Updatable Objects working.&lt;/P&gt;&lt;P&gt;Are there any plans to improve this behavior or should it be possible to get this to work in a different way?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;&lt;P&gt;Harry&lt;/P&gt;</description>
      <pubDate>Sun, 18 Oct 2020 10:24:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99406#M8656</guid>
      <dc:creator>net-harry</dc:creator>
      <dc:date>2020-10-18T10:24:36Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99422#M8657</link>
      <description>&lt;P&gt;Theoretically it should use the external IP.&lt;BR /&gt;What’s the main IP of the VS in your case?&lt;/P&gt;</description>
      <pubDate>Sun, 18 Oct 2020 15:47:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99422#M8657</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-18T15:47:11Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99426#M8658</link>
      <description>&lt;P&gt;The main IP address (which is also used for the external interface) is 172.21.x.y. We have another external firewall (also Check Point) that does a NAT to a public IP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Oct 2020 16:24:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99426#M8658</guid>
      <dc:creator>net-harry</dc:creator>
      <dc:date>2020-10-18T16:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99427#M8659</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/20937"&gt;@net-harry&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Internet connectivity - make sure there is connectivity to the Internet.&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;You need the following:&lt;/P&gt;
&lt;P&gt;- A route in the direction of the Internet to reach &lt;STRONG&gt;updates.checkpoint.com&lt;/STRONG&gt;&lt;BR /&gt;- A NAT rule to a public address (if necessary on a VS gateway or your external firewall)&lt;BR /&gt;- A rule for https to allow the traffic to &lt;STRONG&gt;updates.checkpoint.com&lt;/STRONG&gt;&amp;nbsp; (if necessary on a VS gateway or your external firewall)&lt;BR /&gt;- DNS servers - make sure DNS servers are configured properly (changing DNS configuration in GAIA requires cprestart)&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Troubleshooting:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;DNS server(s) must be configured and reachable from the Security Gateway.&lt;/LI&gt;
&lt;LI&gt;If required, Proxy Server should be configured (in SmartConsole) and reachable from the Security Gateway.&lt;/LI&gt;
&lt;LI&gt;Run on your Gateway machine:&amp;nbsp;&lt;STRONG&gt;unified_dl UPDATE ONLINE_SERVICES&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Verify that the response is:&amp;nbsp;&lt;STRONG&gt;Request was completed successfully.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Search the &lt;STRONG&gt;last_revision.xml&lt;/STRONG&gt; file under &lt;STRONG&gt;&lt;EM&gt;$CPDIR/database/downloads/ONLINE_SERVICES/1.0/&lt;/EM&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;If it exists, you now have the Online Services package on your Gateway and can run policy installation.&lt;/LI&gt;
&lt;LI&gt;If the&amp;nbsp;&lt;STRONG&gt;last_revision.xml &lt;/STRONG&gt;is missing, please contact support. We will need to troubleshoot why this file is not downloading properly.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Reboot&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Sun, 18 Oct 2020 18:04:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99427#M8659</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-10-18T18:04:57Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99428#M8660</link>
      <description>&lt;P&gt;The following should be checked.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Ping&amp;nbsp;updates.checkpoint.com.&amp;nbsp;There should be resolving. (You might not get a reply. It is ok).&lt;/LI&gt;
&lt;LI&gt;If there is no resolving, check DNS server configuration and connectivity.&lt;/LI&gt;
&lt;LI&gt;Check connectivity using curl_cli:&lt;BR /&gt;# curl_cli&amp;nbsp; &lt;A href="https://updates.checkpoint.com/WebService/services/DownloadMetaDataService?wsdl" target="_blank" rel="noopener"&gt;https://updates.checkpoint.com/WebService/services/DownloadMetaDataService?wsdl&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Check that a proxy server is configured, if needed.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Sun, 18 Oct 2020 17:59:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99428#M8660</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-10-18T17:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99431#M8661</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21670"&gt;@HeikoAnkenbrand&lt;/a&gt;&amp;nbsp;for the suggestions!&lt;/P&gt;&lt;P&gt;Please note that the Updatable objects on the vs is currently working for us. I just wanted to check if we made the correct configuration, since ideally I would prefer not to:&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Create a firewall rule to access Check Point cloud (e.g. updates.checkpoint.com) from each VS. I had hoped that allowing the VSX host (vs 0) access to Check Point cloud to be enough.&lt;/LI&gt;&lt;LI&gt;Create a NAT on the VS for the internal network (192.168.196.0/22) to the external IP address of the vs to make access to Check Point cloud. I had hoped that the internally used IPs would never exit the firewall (vs).&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Harry&lt;/P&gt;</description>
      <pubDate>Sun, 18 Oct 2020 17:02:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99431#M8661</guid>
      <dc:creator>net-harry</dc:creator>
      <dc:date>2020-10-18T17:02:36Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99480#M8662</link>
      <description>&lt;P&gt;Each VS has to have access to the updatable objects distribution (updates.checkpoint.com) to fetch the relevant objects. Sharing between different VSs is essentially a potential RFE, as we do not have this functionality at this moment.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 10:26:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99480#M8662</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-10-19T10:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99494#M8663</link>
      <description>&lt;P&gt;We got "stung" pretty badly by this too - there is no solution for VSX to use VS0 as a "proxy" in case of updatable objects. You will need individual connectivity from each VS to Checkpoint. Can't agreee more that it's not ideal but it works&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 12:48:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99494#M8663</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2020-10-19T12:48:01Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99496#M8664</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;If I understand you correctly, you had to create a NAT rule for the Funny-IP of the VS? This should not be necessary in my experience. But we also managed to "break" the automatic NAT mechanism behind Funny IPs with manual No-NAT rules in the past.&lt;/P&gt;&lt;P&gt;Regarding external connectivity: For us it would also be great if VS0 would be used for this kind of external communication.&lt;/P&gt;&lt;P&gt;Another warning: We had a VS drop nearly all traffic when we used Updatable Objects for the first time. If the VS is NOT able to fetch these objects, the rule transformed into an any-any-drop rule.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 13:24:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99496#M8664</guid>
      <dc:creator>Arne_Boettger</dc:creator>
      <dc:date>2020-10-19T13:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99502#M8665</link>
      <description>&lt;P&gt;Thank you very much&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11456"&gt;@Kaspars_Zibarts&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp; and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/2029"&gt;@Arne_Boettger&lt;/a&gt;&amp;nbsp; for the information.&lt;/P&gt;&lt;P&gt;I understand now based on your feedback that we do need to allow some traffic from each VS that uses Updatable Objects. Right now we have the following:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Access from virtual firewall (vs) to DNS servers for DNS requests&lt;/LI&gt;&lt;LI&gt;Access from virtual firewall (vs) to updates.checkpoint.com for HTTPS requests&lt;/LI&gt;&lt;LI&gt;NAT for internal network (192.168.196.0/22) to virtual firewall (vs) external interface&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Regarding the NAT of the internal addresses (192.168.196.0/22) we had to configure it to get the Updatable Objects working, but perhaps it was an order of operations issue. We will test to remove the NAT rule and see if we can get it to work. Could it potentially also be due to that we run an older JHA (118) for R80.20?&lt;/P&gt;&lt;P&gt;Thanks again for your help!&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Harry&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 14:00:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99502#M8665</guid>
      <dc:creator>net-harry</dc:creator>
      <dc:date>2020-10-19T14:00:34Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99516#M8666</link>
      <description>&lt;P&gt;like many who already posted we got hit by this as well. Especially the fact, that you cannot verify that it will work before you actually install the policy with the updateable objects. If for some reason the VS cannot download the lists, it will start dropping traffic - It will inform you in the policy install, but it is only a warning, and not a blocking error &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Furthermore, since VSs can only use the DNS from VS0 - good luck using dynamic objects and URLF, Captive Portal, etc. if the VSs represent different customers, each with their own dns resolvers.&lt;/P&gt;&lt;P&gt;This has been a limitation long running, I think I read something is in the works for r81 - But then again, that means r82 until stable &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Henrik&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 17:26:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/99516#M8666</guid>
      <dc:creator>Henrik_Noerr1</dc:creator>
      <dc:date>2020-10-19T17:26:04Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/119060#M16846</link>
      <description>&lt;P&gt;were you using proxy in this setup ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 13:39:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/119060#M16846</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2021-05-21T13:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable Objects in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/119061#M16847</link>
      <description>&lt;P&gt;i am yet to find a solution for this.. if i am using a proxy in vs0 ..does vs2 also uses the same proxy for any outbound update request even though i have created a separate NAT for it in vs2 policy&amp;nbsp; ?.. for some reason vs2 cant reach the proxy in vs0 in my environment. I am suspecting this might be the issue for me.&lt;/P&gt;&lt;P&gt;i am able to ping and resolve updates.checkpoint.com but not getting last_revision.xml file in VS2 at this location : $CPDIR/database/download/ONLINE_SERVICES/1.0/&lt;/P&gt;&lt;P&gt;however ..this is available in VS0 at the same location&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 13:52:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Updatable-Objects-in-VSX/m-p/119061#M16847</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2021-05-21T13:52:00Z</dc:date>
    </item>
  </channel>
</rss>

