- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I'm looking to finally move to updatable objects off of the legacy geo protection policy. I'm looking for suggestions on the best way to do this. I'm not getting much guidance from support other than general information on updatable objects. The only info I can really find is the below SK. It just doesn't have a ton of info on the transition process. How did you all do this? Did you just use that command in the SK to hide the old shared geo policy and make a new access policy? How do I ensure the old policy isn't on or being enforced? Are you making a separate policy layer for geo protection or just adding rules to the top of your current access policy? Does anyone have any recommended geo policies they are willing to share as an example?
Thats it...just use the sk and use geo updatable objects as source to dst any block and other way around (if needed). I always place geo rules on very top.
Push policy, done.
Thats it...just use the sk and use geo updatable objects as source to dst any block and other way around (if needed). I always place geo rules on very top.
Push policy, done.
I'm guessing instead of the separate exception section, you just make a rule above your geo rules to allow an exception?
YES SIR!
Hey Kevin,
Just wanted to check if you were able to get this sorted out?
Mostly... I set the old geo policy under shared policies to inactive and pushed out some new rules at the top of my rule base to block unwanted countries. Then I tried running $FWDIR/scripts/reload_env_vars.sh -u "disableHiddenGeoPolicy" on my SMS per sk126172 to hide the old geo policy under shared policies. It didn't work. It's still there under shared policies. I'm working with support to figure out why. Nothing yet. Has anyone else run into this?
I think that sk has steps how to hide old geo legacy policy?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY