- Products
- Learn
- Local User Groups
- Partners
- More
Scaling Check Point Automation with Arodonata
7 October @ 5pm CET / 11am EDT
What's New in Check Point SASE
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
AI Security Masters
Implementing the AI Security Trifecta
CheckMates Go:
Half is Not Enough
Hi mates,
I have an issue that the Geo Policy is not able to block a particular country, ie Ukraine, see below logs
See below, I have a geo policy configured to block Ukraine
And no exception for Ukraine
But almost all other blocked countries are blocked successfully, ie
I have also explicitly blocking it using Updatable Objects but no luck
Any thoughts guys?
Regards,
Bill.
Version in use, details about FW appliances, configuration, policy, other than Geo protection?
Which rule is matching? Is it not matching any of the policies above that rule? What Gaia version are you running (R81, R81.10, R82)? And what hotfix/JHF version is installed on your firewall?
Hi,
Traffic matches implied rule. You can start with this SK if you want to move away from implied rules.
https://support.checkpoint.com/results/sk/sk179346
I would get rid of legacy geo policy and use updatable objects, which has been fully supported since R80.20, I believe.
Did not notice this! Indeed move away from legacy geo. If you open TAC case it will be first thing that is pointed out
100%, no doubt.
I would suggest checking "fw ctl int get geo_max_ip_ranges". If it is at its default 300k that is too small for the current amount of IPs in the list (IpToCountry.csv currently at 346063). This will cause the gateway to not read the last addresses in the file. Even though the management can resolve them in the logs.
The correct answer is to change away from legacy geo protection though.
EDIT: Should ofcourse be "fw ctl get int geo_max_ip_ranges"
hi all
@_Val_ my bad forgot to mention i'm running r81.20 take 119
@the_rock yes, I am aware legacy geo policy has to be get rid of. so i created a network policy with updatable objects for pilot as shown but no luck
@WiliRGasparetto from the log detail it's saying "Default Geo Policy" which my gateways associated
@Lesley cant find any rules related to Geo in Impied rules
@Lau yes i'm with default value 300k while the csv has 346063. I found a post replied by @the_rock few months back https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-GeoProtection-Maximum-Ra... , reconfigured it to 500k see if it helps. Do you think those Updatable Country Objects are referencing to IPToCountry.csv as well?
Regards,
Bill.
Hey Bill,
Shows policy rule has 8k hits, so it defintely does work. Did you deactivate legacy one?
oh yes you got it, let me get rid of geo policy completely
Regards,
Bill.
That would be best thing to do, Bill.
Hey Bill,
I recall while ago, customer had same situation, they added updatable object policy for specific country and it was still not working right, but as soon as they deactivated legacy geo policy and installed, all worked fine afterwards.
Hi,
The traffic that now is allowed it has as destination the firewall itself correct? (it is blurred out).
yes, thats one of my public IP
Traffic towards the firewall itself mostly is allowed by rule 0 (implied rule). Geo protection kicks in after that. I think that is what happens here.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 6 | |
| 6 | |
| 6 | |
| 6 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 |
Tue 15 Sep 2026 @ 12:00 PM (MDT)
Lone Tree, CO: Workspace Security and Exposure ManagementThu 17 Sep 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall Architectures - AWS, Azure & GCPThu 17 Sep 2026 @ 05:00 PM (CEST)
Under the Hood: Unified Hybrid Mesh Management across AWS Firewalls, SASE and SD-WANThu 17 Sep 2026 @ 03:00 PM (EDT)
Americas Deep Dive: Troubleshooting 101 for Check Point FirewallsThu 17 Sep 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall Architectures - AWS, Azure & GCPThu 17 Sep 2026 @ 05:00 PM (CEST)
Under the Hood: Unified Hybrid Mesh Management across AWS Firewalls, SASE and SD-WANThu 17 Sep 2026 @ 03:00 PM (EDT)
Americas Deep Dive: Troubleshooting 101 for Check Point FirewallsMon 28 Sep 2026 @ 03:00 PM (CEST)
La nouvelle réalité des attaques DDoS: autonomie, échelle et avenir de la défenseTue 15 Sep 2026 @ 12:00 PM (MDT)
Lone Tree, CO: Workspace Security and Exposure ManagementWed 23 Sep 2026 @ 06:00 PM (EDT)
Santo Domingo: Workspace Security and SASE Live: Protección Total del Usuario Email, Endpoint y SASEAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY