- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
An updatable object (new in R80.20 and above) is a network object that represents an external service, such as Office 365, AWS, GEO locations and more. External services providers publish lists of IP addresses, or Domains, or both, to allow access to their services. These lists are dynamically updated. Updatable objects derive their contents from these published lists of the providers, which Check Point uploads to the Check Point cloud. The updatable objects are updated automatically on the Security Gateway each time the provider changes a list. There is no need to install policy for the updates to take effect. You can use an updatable object in the Access Control policy as a source, or a destination.
I didn't find anything on the CLI commands in the documentation. Here my knowledge from the reverse engineering.
In 80.20 and above you can run the tool "domains_tool" to show domain object informations.
# domains_tool -d update.microsoft.com => show which IP is associated to a domain object
# domains_tool -ip 1.2.3.4 => search and privide a list of domains for IP
For more informations about updatable object see sk131852.
see sk161632 for further details.
the flag -uo allows to check if the <updatable object name> is in the policy and returns a list of the domains it holds
domains_tool -uo "Office365 Services" Domain tool looking for domains for 'Office365 Services' and its children object s: Domains name list for 'Exchange Services': [1] admin.protection.outlook.com ..... |
domains_tool -d admin.protection.outlook.com ... Wait for the next chunk... --------------------------------------------------------------------------------------------------- |
👍
Now two SK's:
sk131852 -> Updatable Objects in R80.20 and above
and
sk161632 -> Domains Tool (domains_tool)
We are using updateable objects to allow traffic to certain services that exist outside the US, since we use geo blocking. We also have Cisco Umbrella for DNS security, and the updateable objects seem to be creating a rather large amount of Umbrella DNS queries that are driving up the cost of the Umbrella service. Is there a way to limit this or force them to query a public DNS instead of our Umbrella service?
We use whatever DNS server is configured in Gaia OS to query for Updateable Objects.
It is not possible to set a different DNS server just for Updatable Object queries.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY