<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Updatable objects with geo policy in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97892#M19174</link>
    <description>&lt;P&gt;Fair enough. Please raise it to TAC, thanks&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 10:05:30 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2020-09-30T10:05:30Z</dc:date>
    <item>
      <title>Updatable objects with geo policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97434#M19125</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have an R80.30 Gateway and management, we apply a geo policy to allow only specific countries to our org.&lt;/P&gt;&lt;P&gt;now we transfer our mail service to 365 cloud and keep our on-perm mail relay and we want all outgoing emails to continue going through the on-prem mail relay.&amp;nbsp;&lt;/P&gt;&lt;P&gt;the issue is geo policy does not support the updateable objects and we cant update the 365 cloud ip addresses every other day.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any solution ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 13:02:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97434#M19125</guid>
      <dc:creator>nirmesika</dc:creator>
      <dc:date>2020-09-24T13:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable objects with geo policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97595#M19148</link>
      <description>&lt;P&gt;The traditional Geo Policy does not support Updatable Objects, nor is this planned.&lt;BR /&gt;You can use Updatable Objects for different geographies in the Access Policy, however.&amp;nbsp;&lt;BR /&gt;And, in fact, this is the approach we recommend for implementing Geo Policy in general in R80.20+ as it permits far more flexibility than the traditional Geo Policy provides.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Sep 2020 21:02:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97595#M19148</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-09-26T21:02:06Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable objects with geo policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97604#M19150</link>
      <description>&lt;P&gt;Also Geo Policy is hidden starting from R81 &amp;gt; see&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk126172" target="_self"&gt;&lt;SPAN&gt;sk126172&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Sep 2020 15:22:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97604#M19150</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2020-09-27T15:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable objects with geo policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97623#M19151</link>
      <description>&lt;P&gt;Geo Policy is still supported in R81, but it will be hidden in the SmartConsole if nothing has been changed in Geo Policy from the default settings "out of the box".&lt;/P&gt;</description>
      <pubDate>Sun, 27 Sep 2020 13:33:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97623#M19151</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-09-27T13:33:28Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable objects with geo policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97760#M19163</link>
      <description>&lt;P&gt;can you please elaborate on "d&lt;SPAN&gt;fferent geographies in the Access Policy" ? how do we implement this ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 05:55:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97760#M19163</guid>
      <dc:creator>nirmesika</dc:creator>
      <dc:date>2020-09-29T05:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable objects with geo policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97792#M19165</link>
      <description>&lt;P&gt;Here are some screenshots from my book showing how to utilize Geo Updatable Objects in R80.20+:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="geo_objects2.png" style="width: 561px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8191i33510ED17C45CB0F/image-size/large?v=v2&amp;amp;px=999" role="button" title="geo_objects2.png" alt="geo_objects2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="geo_objects1.png" style="width: 752px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8192i552B8DE6428EE8EC/image-size/large?v=v2&amp;amp;px=999" role="button" title="geo_objects1.png" alt="geo_objects1.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:11:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97792#M19165</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-09-29T12:11:14Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable objects with geo policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97842#M19169</link>
      <description>&lt;P&gt;The issue with these objects is that you can not fully trust your log files. This is because security gateways update their GeoIP database automatically (&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk126172" target="_self"&gt;&lt;EM&gt;sk126172&lt;/EM&gt;&lt;/A&gt;) while security managements don't (&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120261" target="_self"&gt;&lt;EM&gt;sk120261&lt;/EM&gt;&lt;/A&gt;). Checking to which region a security gateway actually resolves an IP address also is a manual process that includes some calculation and range checking and CLI command handling (&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk94364" target="_self"&gt;&lt;EM&gt;sk94364&lt;/EM&gt;&lt;/A&gt;).&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:17:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97842#M19169</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2020-09-29T22:17:46Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable objects with geo policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97884#M19172</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/687"&gt;@Danny&lt;/a&gt;, did you actually catch any mismatch?&amp;nbsp; Just to make sure your distrust is justifiable &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 09:22:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97884#M19172</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-09-30T09:22:18Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable objects with geo policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97891#M19173</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;sure, here is one recent example: Our security gateways as well as &lt;A href="https://www.maxmind.com/en/geoip-demo" target="_self"&gt;MaxMind&lt;/A&gt; locate&amp;nbsp;114.119.152.204 to be in Singapore while all SmartCenters that haven't manually been updated locate it in China.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 884px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8220iA5082CD9E7AD0B0F/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 10:59:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97891#M19173</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2020-09-30T10:59:04Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable objects with geo policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97892#M19174</link>
      <description>&lt;P&gt;Fair enough. Please raise it to TAC, thanks&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 10:05:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97892#M19174</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-09-30T10:05:30Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable objects with geo policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97901#M19176</link>
      <description>&lt;P&gt;Done. SR closed. Reason: That's the design of the product. Security Managements don't update their GeoIP database by themself. Workaround: Manual via&amp;nbsp;&lt;EM&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120261" target="_self" rel="noopener noreferrer"&gt;sk120261&lt;/A&gt;&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;as I mentioned above or via my &lt;A href="https://community.checkpoint.com/t5/API-CLI-Discussion-and-Samples/One-liner-to-update-IpToCountry-data-on-Security-Managements/m-p/97922#M5202" target="_self"&gt;One-liner to update IpToCountry data on Security Managements&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 17:54:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97901#M19176</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2020-09-30T17:54:19Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable objects with geo policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97903#M19177</link>
      <description>&lt;P&gt;Sorry to hear that. I will check internally and let you know&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 11:03:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97903#M19177</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-09-30T11:03:37Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable objects with geo policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97904#M19178</link>
      <description>&lt;P&gt;To add to Tim's message -&lt;/P&gt;
&lt;P&gt;The R80.20 way of updateable objects is the most recommended solution.&lt;/P&gt;
&lt;P&gt;In order to migrate from the geo policy to this new way, simply create an ordered layer prior to your firewall layer at the access control policy, and recreate the country rules. This will basically keep the same logics as the geo policy, only with up to date IP address ranges for the countries.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 11:11:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97904#M19178</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2020-09-30T11:11:22Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable objects with geo policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97983#M19186</link>
      <description>&lt;P&gt;Hi Tomer_Sole,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We want to allow only connections from Israel to our org and allow our org to all countries.&lt;/P&gt;&lt;P&gt;I have created a new access Policy layer beforce our default FW policy with these two rules attached, will these be OK ? the traffic will continue to the second access layer and will be processed according to our default policy ?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 09:08:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/97983#M19186</guid>
      <dc:creator>nirmesika</dc:creator>
      <dc:date>2020-10-01T09:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable objects with geo policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/98042#M19192</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/687"&gt;@Danny&lt;/a&gt;&amp;nbsp;I have spoken to the product owners. We do have dynamic update of Geo IPs on MGMT side on the road map, but the exact time frame is not clear. I hope it will be done soon.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2020 06:59:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/98042#M19192</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-10-02T06:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable objects with geo policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/98047#M19194</link>
      <description>&lt;P&gt;A connection must match an Accept rule in each ordered layer.&lt;BR /&gt;If the connection doesn't get blocked by your first rule as shown, then it hits an Accept rule and must hit an Accept rule in subsequent layers.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2020 07:35:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/98047#M19194</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-02T07:35:15Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable objects with geo policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/98119#M19210</link>
      <description>&lt;P&gt;I wanted to share a bit more on this topic:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;It's important to emphasize that the flags that you see on the logs are cosmetic information and do not affect the enforcement. They are calculated according to the csv (mentioned in other comments) during the log query.&lt;/LI&gt;
&lt;LI&gt;We do understand that it's confusing to see a flag that is not updated to the latest categorization of an IP. Even more so, if that IP was blocked on a geo rule. As stated, we don't yet update the flag csv file automatically, but following the feedback in the thread, we will make sure to update it more regularly in JHFs.&lt;/LI&gt;
&lt;LI&gt;If you are using updatable objects for geo-blocking in your policy (which is a good way to do it), then inside the log details (double click the log), you will also see the exact updatable object that was matched. This will include its name and icon. In case of a geo updatable object, that will include the country name and flag. That is the most accurate way to see which country was matched in the rule, especially since that value is attached during enforcement and not calculated later during the query.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Sat, 03 Oct 2020 19:10:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/98119#M19210</guid>
      <dc:creator>Tomer_Noy</dc:creator>
      <dc:date>2020-10-03T19:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable objects with geo policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/98167#M19218</link>
      <description>&lt;P&gt;Thank you everyone, the issue is resolved.&lt;/P&gt;&lt;P&gt;the old GEO policy was changed to inactive and the new GEO policy is applied by a new ordered layer before the access control policy !&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2020 05:35:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/98167#M19218</guid>
      <dc:creator>nirmesika</dc:creator>
      <dc:date>2020-10-05T05:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable objects with geo policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/99821#M19439</link>
      <description>&lt;P&gt;Is it possible to add an "exception" to the country objects? How do I allow an IP to connect from an otherwise blocked country?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Oct 2020 11:46:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/99821#M19439</guid>
      <dc:creator>Evan_Gillette</dc:creator>
      <dc:date>2020-10-22T11:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: Updatable objects with geo policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/99824#M19440</link>
      <description>&lt;P&gt;There aren't really true exceptions in an Access Control policy.&amp;nbsp; In that case just add a separate Accept rule for the permitted IP, somewhere above the rule using the Geo Updatable Object to block that country.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Oct 2020 11:54:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Updatable-objects-with-geo-policy/m-p/99824#M19440</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-10-22T11:54:53Z</dc:date>
    </item>
  </channel>
</rss>

