- Products
- Learn
- Local User Groups
- Partners
- More
Call For Papers
Your Expertise, Our Stage
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
The Great Exposure Reset
AI Security Masters E4:
Introducing Cyata, Securing the Agentic AI Era
CheckMates Go:
CheckMates Fest
Hi,
This evening I upgraded one of our FW's to R82 from R81.20
All went well, but then I noticed it was getting an odd message about couldn't contact Checkpoint and could not then find updates.
After various head scratching I looked in the logs and for some reason the Geo Policy now thinks my IP address is registered in BGR which is on our risk database, so blocked.
Long story short I have had to add an exception in the policy, but what on earth would cause this, and is there a reasonable fix or do i just leave me exception in place?
Thanks
Wayne - confused 🙂
Here is what I always do with all customers.
Create whatever country exceptions you need on the top of the rulebase, then just below that, add all other countries as source (group them so it looks nicer), then dst as any, service any, action block, install policy, thats it. And you can also delete old legacy geo policy.
Andy
Hey Wayne,
I hate assuming things, but let me take a wild guess...did you by any chance have old legacy geo policy in place? If so, this behavior would not surprise me. Since R80.20, updatable objects are recommended to use for geo blocking.
Andy
Hi Andy,
Yes I use the old Geo policy, I checked my IP on MaxMind and that says UK based.
Still a bit confused?
Cheers
Wayne
Please refer to https://support.checkpoint.com/results/sk/sk126172 and use Updatable Objects instead of the Geo Policy.
Hi Tal,
I will try converting to UO and see what happens
Cheers
Wayne
Quick question, if I do use UO for Geo policy, what is the best way to have exceptions?
Here is what I always do with all customers.
Create whatever country exceptions you need on the top of the rulebase, then just below that, add all other countries as source (group them so it looks nicer), then dst as any, service any, action block, install policy, thats it. And you can also delete old legacy geo policy.
Andy
I get it, but I had seen it happen many times before with old geo policy, specially in new versions. As @Tal_Paz-Fridman suggested, that sk is best to follow.
Andy
Thanks to both of you !!
Forgot to add something else, though this obviously will not apply to everyone out there, but I want to mention it to you Wayne. While back, I was working with a hospital and we determined they were having bunch of issues due to geo policy, until we addeed Israel and Japan as exceptions. Mind you, that should be easy to tell from the logs if you ever encounter such an issue.
Best,
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 7 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 17 Mar 2026 @ 03:00 PM (CET)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - EMEATue 17 Mar 2026 @ 02:00 PM (EDT)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - AMERWed 18 Mar 2026 @ 10:00 AM (CET)
The Cloud Architects Series: An introduction to Check Point Hybrid Mesh in 2026 - In Seven LanguagesThu 19 Mar 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #2: AI Security Challenges and SolutionsTue 17 Mar 2026 @ 03:00 PM (CET)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - EMEATue 17 Mar 2026 @ 02:00 PM (EDT)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - AMERWed 18 Mar 2026 @ 10:00 AM (CET)
The Cloud Architects Series: An introduction to Check Point Hybrid Mesh in 2026 - In Seven LanguagesThu 19 Mar 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #2: AI Security Challenges and SolutionsTue 24 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 06:00 PM (COT)
San Pedro Sula: Spark Firewall y AI-Powered Security ManagementThu 26 Mar 2026 @ 06:00 PM (COT)
Tegucigalpa: Spark Firewall y AI-Powered Security ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY