<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Geo Policy VS Updateable rules in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Geo-Policy-VS-Updateable-rules/m-p/185402#M30912</link>
    <description>&lt;P&gt;Sometimes some IP addresses are not correctly classified, you have to investigate with TAC. But most common error is an outdated geo location database on the SMS. Use Dannys script &lt;A title="One-liner to update IpToCountry data on Security Managements" href="https://community.checkpoint.com/t5/API-CLI-Discussion/One-liner-to-update-IpToCountry-data-on-Security-Managements/td-p/97922" target="_blank" rel="noopener"&gt;One-liner to update IpToCountry data on Security Managements&lt;/A&gt; &amp;nbsp; to update the database.&amp;nbsp;&lt;A title="Geo Protection logs show the wrong country flag" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120261" target="_blank" rel="noopener"&gt;Geo Protection logs show the wrong country flag&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 02 Jul 2023 20:03:36 GMT</pubDate>
    <dc:creator>Wolfgang</dc:creator>
    <dc:date>2023-07-02T20:03:36Z</dc:date>
    <item>
      <title>Geo Policy VS Updateable rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Geo-Policy-VS-Updateable-rules/m-p/185401#M30911</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have &lt;STRONG&gt;Geo&lt;/STRONG&gt; policy as below:&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="geo.JPG" style="width: 871px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21611i07F26D19C208424E/image-size/large?v=v2&amp;amp;px=999" role="button" title="geo.JPG" alt="geo.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The problem is that we still see logs with "Accept" from these countries! for example from China:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="geo1.JPG" style="width: 532px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21612iD2374ACE85B5C211/image-size/large?v=v2&amp;amp;px=999" role="button" title="geo1.JPG" alt="geo1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="geo3.JPG" style="width: 318px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21614i02C28141C3E7EDD8/image-size/large?v=v2&amp;amp;px=999" role="button" title="geo3.JPG" alt="geo3.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;What I know is that if the Geo policy is set to drop, no one packet (from countries included) will go through the firewall, or do i miss something?&lt;/P&gt;&lt;P&gt;I tried to use a rule with an updateable object as:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="geo2.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21613i7D76085F0D228CF8/image-size/large?v=v2&amp;amp;px=999" role="button" title="geo2.JPG" alt="geo2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As you can see this rule is not getting any hits! even if there are many rules that accepted traffic from China over this one like rule 25 and 35.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should these two (Geo policy &amp;amp; a rule with Updateable objects) being used together or only one should be used?&lt;/P&gt;&lt;P&gt;As you can see in the rule i have included Indonesia only to test if I will get some hits from a country that is not included in the Geo policy, but I got nothing.&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jul 2023 18:33:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Geo-Policy-VS-Updateable-rules/m-p/185401#M30911</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2023-07-02T18:33:27Z</dc:date>
    </item>
    <item>
      <title>Re: Geo Policy VS Updateable rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Geo-Policy-VS-Updateable-rules/m-p/185402#M30912</link>
      <description>&lt;P&gt;Sometimes some IP addresses are not correctly classified, you have to investigate with TAC. But most common error is an outdated geo location database on the SMS. Use Dannys script &lt;A title="One-liner to update IpToCountry data on Security Managements" href="https://community.checkpoint.com/t5/API-CLI-Discussion/One-liner-to-update-IpToCountry-data-on-Security-Managements/td-p/97922" target="_blank" rel="noopener"&gt;One-liner to update IpToCountry data on Security Managements&lt;/A&gt; &amp;nbsp; to update the database.&amp;nbsp;&lt;A title="Geo Protection logs show the wrong country flag" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120261" target="_blank" rel="noopener"&gt;Geo Protection logs show the wrong country flag&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jul 2023 20:03:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Geo-Policy-VS-Updateable-rules/m-p/185402#M30912</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-07-02T20:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: Geo Policy VS Updateable rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Geo-Policy-VS-Updateable-rules/m-p/185428#M30917</link>
      <description>&lt;P&gt;Updatable Objects were introduced in R80.20 to replace Geo Policy. Geo Policy was removed (or hidden) starting R81. Therefore it is advised to use Updatable Objects.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk131852" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk131852&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also please refer to&amp;nbsp;&lt;STRONG&gt;sk120261&amp;nbsp;Geo Protection logs show the wrong country flag&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk120261" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk120261&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2023 08:41:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Geo-Policy-VS-Updateable-rules/m-p/185428#M30917</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2023-07-03T08:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: Geo Policy VS Updateable rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Geo-Policy-VS-Updateable-rules/m-p/185433#M30919</link>
      <description>&lt;P&gt;I have verion 81.10&lt;/P&gt;&lt;P&gt;I have now removed the countries from the Geo policy and added these countries to a rule with updateable objects.&lt;/P&gt;&lt;P&gt;It now shows drops from my rule.&lt;/P&gt;&lt;P&gt;The question now is: Should I create a new rule with updateable objects for every section? Because the rule I created would drop traffic headed only to one section but not other sections.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2023 09:13:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Geo-Policy-VS-Updateable-rules/m-p/185433#M30919</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2023-07-03T09:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: Geo Policy VS Updateable rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Geo-Policy-VS-Updateable-rules/m-p/185503#M30933</link>
      <description>&lt;P&gt;It depends on how you've structured your rulebase and what your precise objectives are.&lt;BR /&gt;But, yes, you may need to add these objects in other rules in other places.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2023 20:05:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Geo-Policy-VS-Updateable-rules/m-p/185503#M30933</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-03T20:05:11Z</dc:date>
    </item>
    <item>
      <title>Re: Geo Policy VS Updateable rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Geo-Policy-VS-Updateable-rules/m-p/188089#M31522</link>
      <description>&lt;P&gt;For awareness. R81.10 JHF T110:&lt;/P&gt;
&lt;TABLE id="filter1Table" class="TableStyle-TP_Table_Jumbo_Fixes" cellspacing="0"&gt;
&lt;TBODY&gt;
&lt;TR class="TableStyle-TP_Table_Jumbo_Fixes-Body-Grey_Background"&gt;
&lt;TD class="TableStyle-TP_Table_Jumbo_Fixes-BodyE-Column_Style_ID-Grey_Background"&gt;
&lt;P&gt;PRJ-44952,&lt;BR /&gt;PRHF-28082&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="TableStyle-TP_Table_Jumbo_Fixes-BodyE-Column_Style_Product-Grey_Background"&gt;
&lt;P&gt;IPS&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="TableStyle-TP_Table_Jumbo_Fixes-BodyD-Column_Style_Description-Grey_Background"&gt;
&lt;P&gt;&lt;STRONG&gt;UPDATE&lt;/STRONG&gt;: Mapping of IPs to country/flag in the Logs &amp;amp; Monitor view &amp;gt; Logs is now automatically updated every day.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Mon, 31 Jul 2023 12:40:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Geo-Policy-VS-Updateable-rules/m-p/188089#M31522</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-07-31T12:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: Geo Policy VS Updateable rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Geo-Policy-VS-Updateable-rules/m-p/188120#M31526</link>
      <description>&lt;P&gt;The way I do this for every customer is like this...regardless if you have inline layers or multiple ordered layers, makes no difference. I create geo block as very FIRST rule in network policy and block whatever needs to be blocked, using updatable objects.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2023 14:22:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Geo-Policy-VS-Updateable-rules/m-p/188120#M31526</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-31T14:22:57Z</dc:date>
    </item>
  </channel>
</rss>

