- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi All,
Following some broad reading of SK documents we now have some questions relating to the use of the Updatable Objects.
Currently our gateways are on R81.10 and the SMS is on R81.20.
The questions are as follows:
1. The Use of the updatable object in the rule base : does the Updatable object get its objects from the updates on SMS or the gateway or both?
2. How do you check the "contents" of the allowable/ contained addresses in a group in the Updatable Object : e.g. "United Kingdom" or Google Services ( two listed)?
3. What is the frequency of the updates : ( again does this get updated on gateway or SMS : ( in 1 above) ? How is it checked.
4. In reference to item 2. and the "Google Services" we have found the URL that identifies the "Ip ranges that Google makes available to users on the internet" : Would it be this ( or similar) that Checkpoint uses for the updates in the first instance.
5. Currently we are the stages of infancy with the use of these Updatable Objects, there are some SK's that provide some very good information but again there is some missing info to describe its baseline operation.
6. Does the use of these or the Updates / frequency/ timeline have any load implications on any CPU on Gateway or SMS?
All the best JED.
Hi think you saw this sk: https://support.checkpoint.com/results/sk/sk131852
The Time-to-Live (TTL) for FQDN cache is 60 minutes. When using FQDN mode, all Domain Objects are refreshed once per minute. To refresh the Domain Object resolution, the Security Gateway queries all defined DNS servers for both "domain.com" and "www.domain.com" from the Domain Object.
Hi JED,
I can answer few of your questions.
1. Information will be fetched by firewall
3. It fetches information when it is updated from vendor side.
You can check sk131852 for more information
To answer number 2, see: https://community.checkpoint.com/t5/Security-Gateways/Updatable-Objects-Audit-changes-and-contents/m...
I believe updates are fetched once an hour.
The load on the gateway is minimal, though I believe there is also a limit to the number of Updatable Objects allowed in the policy.
Let me take "crack" at it, though someone will correct me, Im sure 🙂
Andy
1. The Use of the updatable object in the rule base : does the Updatable object get its objects from the updates on SMS or the gateway or both? I believe management
2. How do you check the "contents" of the allowable/ contained addresses in a group in the Updatable Object : e.g. "United Kingdom" or Google Services ( two listed)? Im only aware ofm domains_tool command for this
3. What is the frequency of the updates : ( again does this get updated on gateway or SMS : ( in 1 above) ? How is it checked. every 60 mins
4. In reference to item 2. and the "Google Services" we have found the URL that identifies the "Ip ranges that Google makes available to users on the internet" : Would it be this ( or similar) that Checkpoint uses for the updates in the first instance. yes
5. Currently we are the stages of infancy with the use of these Updatable Objects, there are some SK's that provide some very good information but again there is some missing info to describe its baseline operation.
https://support.checkpoint.com/results/sk/sk131852
6. Does the use of these or the Updates / frequency/ timeline have any load implications on any CPU on Gateway or SMS? I had never seen any impact myself at all
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY