- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hi mates,
I have an issue that the Geo Policy is not able to block a particular country, ie Ukraine, see below logs
See below, I have a geo policy configured to block Ukraine
And no exception for Ukraine
But almost all other blocked countries are blocked successfully, ie
I have also explicitly blocking it using Updatable Objects but no luck
Any thoughts guys?
Regards,
Bill.
Version in use, details about FW appliances, configuration, policy, other than Geo protection?
Which rule is matching? Is it not matching any of the policies above that rule? What Gaia version are you running (R81, R81.10, R82)? And what hotfix/JHF version is installed on your firewall?
Hi,
Traffic matches implied rule. You can start with this SK if you want to move away from implied rules.
https://support.checkpoint.com/results/sk/sk179346
I would get rid of legacy geo policy and use updatable objects, which has been fully supported since R80.20, I believe.
Did not notice this! Indeed move away from legacy geo. If you open TAC case it will be first thing that is pointed out
100%, no doubt.
I would suggest checking "fw ctl int get geo_max_ip_ranges". If it is at its default 300k that is too small for the current amount of IPs in the list (IpToCountry.csv currently at 346063). This will cause the gateway to not read the last addresses in the file. Even though the management can resolve them in the logs.
The correct answer is to change away from legacy geo protection though.
EDIT: Should ofcourse be "fw ctl get int geo_max_ip_ranges"
hi all
@_Val_ my bad forgot to mention i'm running r81.20 take 119
@the_rock yes, I am aware legacy geo policy has to be get rid of. so i created a network policy with updatable objects for pilot as shown but no luck
@WiliRGasparetto from the log detail it's saying "Default Geo Policy" which my gateways associated
@Lesley cant find any rules related to Geo in Impied rules
@Lau yes i'm with default value 300k while the csv has 346063. I found a post replied by @the_rock few months back https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-GeoProtection-Maximum-Ra... , reconfigured it to 500k see if it helps. Do you think those Updatable Country Objects are referencing to IPToCountry.csv as well?
Regards,
Bill.
Hey Bill,
Shows policy rule has 8k hits, so it defintely does work. Did you deactivate legacy one?
oh yes you got it, let me get rid of geo policy completely
Regards,
Bill.
That would be best thing to do, Bill.
Hey Bill,
I recall while ago, customer had same situation, they added updatable object policy for specific country and it was still not working right, but as soon as they deactivated legacy geo policy and installed, all worked fine afterwards.
Hi,
The traffic that now is allowed it has as destination the firewall itself correct? (it is blurred out).
yes, thats one of my public IP
Traffic towards the firewall itself mostly is allowed by rule 0 (implied rule). Geo protection kicks in after that. I think that is what happens here.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 36 | |
| 11 | |
| 10 | |
| 10 | |
| 9 | |
| 8 | |
| 7 | |
| 7 | |
| 6 | |
| 6 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY