<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IP Country of Origin Inconsistent - Chekpoint Firewall in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/IP-Country-of-Origin-Inconsistent-Chekpoint-Firewall/m-p/193306#M32346</link>
    <description>&lt;P&gt;Good evening. I'm having a little bit of confusion with some of the data on my firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the GUI, it shows an attempted connection from the source 193.37.69.203 over port 3389 with a Russian Federation flag.&lt;/P&gt;&lt;P&gt;There are two things I found a bit confusing.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;1.) One of my analysts colleagues at markup related to that IP, and it reads as:&lt;BR /&gt;&lt;BR /&gt;"ip": 193.37.69.203&lt;BR /&gt;"country_name": Netherlands.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2.) Looking up the IP in arin.net, shows it as having a registration in London.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://search.arin.net/rdap/?query=193.37.69.203" target="_blank"&gt;https://search.arin.net/rdap/?query=193.37.69.203&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone tell me what might be the source of the inconsistency? One thing we did look at was the IP in RiskIQ, and it appears that a few Russian Federation related URLs are associated with it, so I'm not sure if I'm not understanding what goes into the data that we're being presented.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you!&lt;/P&gt;</description>
    <pubDate>Fri, 22 Sep 2023 02:08:41 GMT</pubDate>
    <dc:creator>mikegemini</dc:creator>
    <dc:date>2023-09-22T02:08:41Z</dc:date>
    <item>
      <title>IP Country of Origin Inconsistent - Chekpoint Firewall</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IP-Country-of-Origin-Inconsistent-Chekpoint-Firewall/m-p/193306#M32346</link>
      <description>&lt;P&gt;Good evening. I'm having a little bit of confusion with some of the data on my firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the GUI, it shows an attempted connection from the source 193.37.69.203 over port 3389 with a Russian Federation flag.&lt;/P&gt;&lt;P&gt;There are two things I found a bit confusing.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;1.) One of my analysts colleagues at markup related to that IP, and it reads as:&lt;BR /&gt;&lt;BR /&gt;"ip": 193.37.69.203&lt;BR /&gt;"country_name": Netherlands.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2.) Looking up the IP in arin.net, shows it as having a registration in London.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://search.arin.net/rdap/?query=193.37.69.203" target="_blank"&gt;https://search.arin.net/rdap/?query=193.37.69.203&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone tell me what might be the source of the inconsistency? One thing we did look at was the IP in RiskIQ, and it appears that a few Russian Federation related URLs are associated with it, so I'm not sure if I'm not understanding what goes into the data that we're being presented.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2023 02:08:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IP-Country-of-Origin-Inconsistent-Chekpoint-Firewall/m-p/193306#M32346</guid>
      <dc:creator>mikegemini</dc:creator>
      <dc:date>2023-09-22T02:08:41Z</dc:date>
    </item>
    <item>
      <title>Re: IP Country of Origin Inconsistent - Chekpoint Firewall</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IP-Country-of-Origin-Inconsistent-Chekpoint-Firewall/m-p/193342#M32354</link>
      <description>&lt;P&gt;CP uses maxmind for those things, so if something is not consistent, maybe best to open TAC case to have it sorted out.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2023 12:26:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IP-Country-of-Origin-Inconsistent-Chekpoint-Firewall/m-p/193342#M32354</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-22T12:26:18Z</dc:date>
    </item>
    <item>
      <title>Re: IP Country of Origin Inconsistent - Chekpoint Firewall</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IP-Country-of-Origin-Inconsistent-Chekpoint-Firewall/m-p/193349#M32355</link>
      <description>&lt;P&gt;Are you running R81.10 JHF T110 or higher?&lt;/P&gt;
&lt;P&gt;PRJ-44952,&lt;SPAN&gt;PRHF-28082 -&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;IPS -&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;UPDATE: Mapping of IPs to country/flag in the Logs &amp;amp; Monitor view &amp;gt; Logs is now automatically updated every day.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2023 13:01:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IP-Country-of-Origin-Inconsistent-Chekpoint-Firewall/m-p/193349#M32355</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-09-22T13:01:27Z</dc:date>
    </item>
    <item>
      <title>Re: IP Country of Origin Inconsistent - Chekpoint Firewall</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IP-Country-of-Origin-Inconsistent-Chekpoint-Firewall/m-p/193395#M32358</link>
      <description>&lt;P&gt;Even if not, you can update it manually using:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/API-CLI-Discussion/One-liner-to-update-IpToCountry-data-on-Security-Managements/m-p/97922" target="_blank"&gt;https://community.checkpoint.com/t5/API-CLI-Discussion/One-liner-to-update-IpToCountry-data-on-Security-Managements/m-p/97922&lt;/A&gt;&lt;BR /&gt;You can troubleshoot the data with:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk114216" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk114216&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;If an IP is incorrectly classified, you'll need to open a TAC case: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2023 23:14:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IP-Country-of-Origin-Inconsistent-Chekpoint-Firewall/m-p/193395#M32358</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-22T23:14:31Z</dc:date>
    </item>
  </channel>
</rss>

