<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.40 - Updatable Objects Issue on VS in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/R80-40-Updatable-Objects-Issue-on-VS/m-p/118816#M22119</link>
    <description>&lt;P&gt;for updatable objects, you need to access a different FQDN. Refer to&amp;nbsp;&lt;SPAN&gt;sk83520 for full info. I believe it is dl3.checkpoint.com, but please check there, just in case.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I also believe, updatable objects are pulled from the target VS and not VS0.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 19 May 2021 14:55:37 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2021-05-19T14:55:37Z</dc:date>
    <item>
      <title>R80.40 - Updatable Objects Issue on VS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-40-Updatable-Objects-Issue-on-VS/m-p/118815#M22118</link>
      <description>&lt;P&gt;I configured updatable objects in my Access Policy but was greeted with a deny log stating &lt;STRONG&gt;"updatable objects is used in policy but gateway package is missing"&lt;/STRONG&gt;..&amp;nbsp; this is a VSX environment and i am getting these logs on a VS.. i have proxy, DNS configured.. i read on another forum that individual NAT and access is to be allowed towards updates.checkpoint.com on the VS..if my VS0 is already able to resolve everything then is individual access required on other VS ? .. moreover how do i allow access towards URL "updates.checkpoint.com' and how the NAT has to be setup for this.. my external bond interface has a public IP.&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 14:44:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-40-Updatable-Objects-Issue-on-VS/m-p/118815#M22118</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2021-05-19T14:44:03Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 - Updatable Objects Issue on VS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-40-Updatable-Objects-Issue-on-VS/m-p/118816#M22119</link>
      <description>&lt;P&gt;for updatable objects, you need to access a different FQDN. Refer to&amp;nbsp;&lt;SPAN&gt;sk83520 for full info. I believe it is dl3.checkpoint.com, but please check there, just in case.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I also believe, updatable objects are pulled from the target VS and not VS0.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 14:55:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-40-Updatable-Objects-Issue-on-VS/m-p/118816#M22119</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-05-19T14:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 - Updatable Objects Issue on VS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-40-Updatable-Objects-Issue-on-VS/m-p/118817#M22120</link>
      <description>&lt;P&gt;Here is a similar discussion with more details:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Updatable-Objects-in-VSX/m-p/99187" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Updatable-Objects-in-VSX/m-p/99187&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;TL'DR - VS itself has to have connectivity to the update service. There should be a NAT rule allowing it to get packets back.&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 15:00:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-40-Updatable-Objects-Issue-on-VS/m-p/118817#M22120</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-05-19T15:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 - Updatable Objects Issue on VS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-40-Updatable-Objects-Issue-on-VS/m-p/118828#M22125</link>
      <description>&lt;P&gt;In this discussion it is mentioned to create a NAT and an ACL .. how do i provide access rule towards a URL ? and my external interface is configured with a public ip and i can ping external addresses via it.. is NAT required in this case ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 15:55:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-40-Updatable-Objects-Issue-on-VS/m-p/118828#M22125</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2021-05-19T15:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 - Updatable Objects Issue on VS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-40-Updatable-Objects-Issue-on-VS/m-p/118869#M22134</link>
      <description>&lt;P&gt;You do not have to have a rule, actually, GW to internet access is covered by implied rules already. What you need is NAT.&amp;nbsp; When a VS is sending traffic, one of the "funny IPs" is used. It should be NAT-ed in the way traffic can return.&amp;nbsp;Please carefully read the discussion I referred above, it is explained there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 06:23:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-40-Updatable-Objects-Issue-on-VS/m-p/118869#M22134</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-05-20T06:23:46Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 - Updatable Objects Issue on VS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-40-Updatable-Objects-Issue-on-VS/m-p/119059#M22169</link>
      <description>&lt;P&gt;Ok..i got the funny ip part..so here is what i have done.&lt;/P&gt;&lt;P&gt;1)Applied a NAT rule from src 192.168.96.0/24 towards any with a hideNAT (Public IP)&lt;/P&gt;&lt;P&gt;2)tried curl_cli updates.checkpoint.com and i am able to resolve it from the VS&lt;/P&gt;&lt;P&gt;3)ran unified_dl UPDATE ONLINE_SERVICES&lt;/P&gt;&lt;P&gt;however..after doing all this i still cannot see last_resvision.xml being created in #CPDIR/database/downloads/ONLINE_SERVICES/1.0 of the VS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;just one thing which i suppose may be an issue..i have a proxy configured in SmartConsole/VS0.. VS2 cannot reach that proxy..is vs2 trying to reach internet via Proxy even when a direct NAT is available ? any way to get around this.&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 13:37:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-40-Updatable-Objects-Issue-on-VS/m-p/119059#M22169</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2021-05-21T13:37:05Z</dc:date>
    </item>
  </channel>
</rss>

