<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 5 Year celebration hangover - Q regarding dynamic network object in R81.20 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/5-Year-celebration-hangover-Q-regarding-dynamic-network-object/m-p/150088#M26002</link>
    <description>&lt;P&gt;Unfortunately, we cannot port these features to older versions. They depend on new schema configuration in the DB and functionality in the gateway that cannot be added in JHF.&lt;/P&gt;
&lt;P&gt;Note that the log sending to multiple servers (distributed logging) was already added in R81.10, so it's GA.&lt;/P&gt;
&lt;P&gt;I can only recommend a swift upgrade strategy to at least R81.10 right now, and soon to R81.20 as those releases bring many improvements on all fronts (quality, performance, features).&lt;/P&gt;</description>
    <pubDate>Fri, 03 Jun 2022 07:09:20 GMT</pubDate>
    <dc:creator>Tomer_Noy</dc:creator>
    <dc:date>2022-06-03T07:09:20Z</dc:date>
    <item>
      <title>5 Year celebration hangover - Q regarding dynamic network object in R81.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/5-Year-celebration-hangover-Q-regarding-dynamic-network-object/m-p/149985#M25990</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9372"&gt;@Tomer_Noy&lt;/a&gt;&amp;nbsp;- thanks for really outstanding presentation yesterday! Made many notes regarding R81.20!&lt;/P&gt;
&lt;P&gt;One thing that I loved most is dynamic network object list / feed. I generally love dynamic objects and we strive to go away from static rulebase managed by FW administrators to more dynamic build - i.e updatable objects, domain objects, old school dynamic objects, API based updates etc etc&lt;/P&gt;
&lt;P&gt;And this new network feed object type would perfectly fit our bill! It would allow us to delegate responsibility to service owners and cut many "middle-man" hours. Plus it's less complex than API and does not require policy install! Win-win&lt;/P&gt;
&lt;P&gt;How does it fit together with generic datacentre object that was released in R81? It seems to be doing the same thing but is just more cumbersome to manage (format requirements etc)&lt;/P&gt;
&lt;P&gt;Will it require any additional licensing? I.e. to deploy IOC feeds (that are somewhat similar with exception that they would only allow blocking traffic) you need AB or AV license.&lt;/P&gt;
&lt;P&gt;Thanks again for insights!&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2022 07:12:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/5-Year-celebration-hangover-Q-regarding-dynamic-network-object/m-p/149985#M25990</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2022-11-18T07:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: 5 Year celebration hangover - Q regarding dynamic network object in R81.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/5-Year-celebration-hangover-Q-regarding-dynamic-network-object/m-p/149989#M25991</link>
      <description>&lt;P&gt;Thanks for the positive feedback Kaspars!&lt;BR /&gt;It means a lot coming from a skilled and veteran customer&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I'm glad that this new feature is a good fit for your plans to further modernize your policy management. I hope that many customers adopt it.&lt;/P&gt;
&lt;P&gt;Regarding your questions:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;How do "Network Feeds" fit together or compare with "Generic DataCenter" objects?
&lt;UL&gt;
&lt;LI&gt;The benefits of Generic DataCenter is that it supports hierarchy of objects, so a single feed can provide multiple objects for the policy. Also, it can be installed on R81.10 gateways.&lt;/LI&gt;
&lt;LI&gt;The benefits of Network Feeds are that they are much simpler to define and use (no strict formatting), the gateway independently updates content from the feed (so Management maintenance / downtime will not affect it), and it's scalable for a lot of IPs.&lt;/LI&gt;
&lt;LI&gt;IMO, if you are in doubt, go with the Network Feeds. We hope that this feature will reach the masses as there is not widespread adoption of Generic DataCenter.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Unlike IoCs, Network Feeds are an Access Policy feature, so they do not require an additional license.
&lt;UL&gt;
&lt;LI&gt;BTW, IoCs are a great feature and support many more blocking constructs (such as URLs, regular expressions, ...). These are actually used by many customers and we continue to encourage that.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I hope the above clarifies things.&lt;/P&gt;
&lt;P&gt;Please continue to share feedback (also if you have on other content in the demo), and if you have experience later on with adopting R81.20.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2022 06:45:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/5-Year-celebration-hangover-Q-regarding-dynamic-network-object/m-p/149989#M25991</guid>
      <dc:creator>Tomer_Noy</dc:creator>
      <dc:date>2022-06-02T06:45:43Z</dc:date>
    </item>
    <item>
      <title>Re: 5 Year celebration hangover - Q regarding dynamic network object in R81.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/5-Year-celebration-hangover-Q-regarding-dynamic-network-object/m-p/150065#M26000</link>
      <description>&lt;P&gt;You know that I have been planning in my head a "centralised tool to manage old school dynamic objects" just like network feeds does.. you stole my idea from my head! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Oh well, I have time now for other 100 ideas in my head! And can you please port it to R80.40 as i doubt it very much that we will venture to R81.20 anytime soon &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; plus the log sending to two servers!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2022 21:09:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/5-Year-celebration-hangover-Q-regarding-dynamic-network-object/m-p/150065#M26000</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2022-06-02T21:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: 5 Year celebration hangover - Q regarding dynamic network object in R81.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/5-Year-celebration-hangover-Q-regarding-dynamic-network-object/m-p/150088#M26002</link>
      <description>&lt;P&gt;Unfortunately, we cannot port these features to older versions. They depend on new schema configuration in the DB and functionality in the gateway that cannot be added in JHF.&lt;/P&gt;
&lt;P&gt;Note that the log sending to multiple servers (distributed logging) was already added in R81.10, so it's GA.&lt;/P&gt;
&lt;P&gt;I can only recommend a swift upgrade strategy to at least R81.10 right now, and soon to R81.20 as those releases bring many improvements on all fronts (quality, performance, features).&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jun 2022 07:09:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/5-Year-celebration-hangover-Q-regarding-dynamic-network-object/m-p/150088#M26002</guid>
      <dc:creator>Tomer_Noy</dc:creator>
      <dc:date>2022-06-03T07:09:20Z</dc:date>
    </item>
    <item>
      <title>Re: 5 Year celebration hangover - Q regarding dynamic network object in R81.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/5-Year-celebration-hangover-Q-regarding-dynamic-network-object/m-p/150095#M26003</link>
      <description>&lt;P&gt;We will try of course! To upgrade..&lt;/P&gt;
&lt;P&gt;One last Q Tomer - Network Feeds, will they be available as Global objects in MDS?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jun 2022 08:27:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/5-Year-celebration-hangover-Q-regarding-dynamic-network-object/m-p/150095#M26003</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2022-06-03T08:27:09Z</dc:date>
    </item>
    <item>
      <title>Re: 5 Year celebration hangover - Q regarding dynamic network object in R81.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/5-Year-celebration-hangover-Q-regarding-dynamic-network-object/m-p/151205#M26094</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11456"&gt;@Kaspars_Zibarts&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;It took me a little while to get a verified answer, but you'll be happy to hear that: Yes, Network Feeds can be defined as global objects in MDS environments&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jun 2022 14:34:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/5-Year-celebration-hangover-Q-regarding-dynamic-network-object/m-p/151205#M26094</guid>
      <dc:creator>Tomer_Noy</dc:creator>
      <dc:date>2022-06-19T14:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: 5 Year celebration hangover - Q regarding dynamic network object in R81.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/5-Year-celebration-hangover-Q-regarding-dynamic-network-object/m-p/152182#M26172</link>
      <description>&lt;P&gt;Awesome! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; really good news! Time to plan to upgrade MDS then!&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2022 11:36:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/5-Year-celebration-hangover-Q-regarding-dynamic-network-object/m-p/152182#M26172</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2022-07-01T11:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: 5 Year celebration hangover - Q regarding dynamic network object in R81.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/5-Year-celebration-hangover-Q-regarding-dynamic-network-object/m-p/162426#M27080</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9372"&gt;@Tomer_Noy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the information.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Discovered this post linked from the&amp;nbsp;&lt;SPAN&gt;What's New in R81.20 TechTalk webinar this week.&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a few questions re the Network Feeds object.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What file type is the file the Network Feeds object?&lt;/P&gt;
&lt;P&gt;If there is no strict formatting;&lt;/P&gt;
&lt;UL class="lia-list-style-type-square"&gt;
&lt;LI&gt;How can you trust the data input is valid data?&lt;/LI&gt;
&lt;LI&gt;Is there a built-in validation process to ensure the data is valid?&lt;/LI&gt;
&lt;LI&gt;Also is there a constraints mechanism i.e. restrict what values can will be accepted ion the file e.g. a specific IP range?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;We just started using generic data center objects block malicious IPs from verified threat intelligence feeds. As you stated, the generic data center object references a JSON file with strict formatting requirements. However, there is still no built-in protection for data validation.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To mitigate input errors i.e. input data that doesn't conform to the strict formatting, we validate the JSON against a schema before copying the file to a web or the management server.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In terms of scalability,&amp;nbsp; the JSON should be able to handle a lot of IPs. Can you explain the advantage of the new object in further detail here?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would be interested to look at any additional information you're able to provide on the Network Feeds object.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Simon&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2022 07:43:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/5-Year-celebration-hangover-Q-regarding-dynamic-network-object/m-p/162426#M27080</guid>
      <dc:creator>Simon_Macpherso</dc:creator>
      <dc:date>2022-11-18T07:43:40Z</dc:date>
    </item>
  </channel>
</rss>

