- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
I want to create a global domain policy that blocks communications from specific countries.
I've created a group for them and assigned the policy to different domains.
I want to ensure that the objects in each domain are updated dynamically.
For dynamic objects, it is necessary to add the _global suffix, in order to trigger the reference replacement mechanism.
What about updatable objects?
Are they updated dynamically on each domain as well?
Can I check their content or at least their object number to compare a global domain with a specific domain?
For Dynamic Objects in MDS in R8x, see: https://community.checkpoint.com/t5/Management/Dynamic-Global-Objects-no-longer-supported/m-p/7654#M...
But, yes, you're correct.
In both cases, the actual content of the object resides on the gateway itself, not on the management.
For Dynamic Objects in MDS in R8x, see: https://community.checkpoint.com/t5/Management/Dynamic-Global-Objects-no-longer-supported/m-p/7654#M...
But, yes, you're correct.
In both cases, the actual content of the object resides on the gateway itself, not on the management.
May sound like a silly question but what is the difference between a dynamic object and domain object? I ask because when creating a dynamic object example "www.abc.com" rather then ".abc.com" it does not work, yet if I do the same thing with a domain object, it does work.
I assume you mean FQDN Domain object. Is so, it is an object that FW resolves into an IP through DNS queries. Dynamic object is a logical container that is filled with IPs from an external source. In your case, if you do not feed an abc.com dynamic object with relevant IPs, it will not be matched to anything in your rulebase, hence the observed behavior.
Best to read the management admin guide for your version for more details.
Great thanks, I did suspect this when I found some CLI commands to add IPs to dynamic objects, are the same performance issues there related to FQDN objects in R81.x?
Dynamic Objects were not SecureXL friendly in pre-R80 versions.
In current versions, they are SecureXL friendly, so there should be no performance impact.
Great! Thanks for the confirmation.
What are the risks of deploying dynamic objects ?
I would say the main things I can think of are:
DNS
Access to the Internet for the appliance to retrieve the databases.
Vendor updating IP addresses and the time it takes for the database to be updated with the new information.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 23 | |
| 19 | |
| 10 | |
| 9 | |
| 8 | |
| 7 | |
| 6 | |
| 4 | |
| 4 | |
| 4 |
Fri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY