- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello Guys ,
We are going to use Updatable Objects for Office 365. Some questions that arises and i would like to hear some suggestions from people that tested it.
Thanks in advanced!
Hi @Geomix7 , I tend to agree with @G_W_Albrecht that most of your questions are actually answered in the quoted solutions. Nevertheless, let me answer to those questions directly:
Q: Those services is a combination of IP addresses & domains .How an IP address (mechanism) is checked to verify if match for a domain which is included in Office 365? How this Mechanism works?
A: List of IPs and domains is pulled from the source. Domain objects are also resolved into IP addresses.
Q: Where to position this rule in rule base and why?
A: Updatable objects can be used in the rulebase at will. As they are SXL-friendly, position does not matter.
Q: Any performance impact?
A: Practically no impact.
Q: Known issues ?
A: Specifically for O365, sometimes resolution of MS wild card objects can be incomplete, for certain sub-domains. These occurrences are very rare, but if you experience one, feel free to address it with a support ticket.
Q: Any impact in DNS server?
A: Some unfrequent periodical DNS requests are being sent by FW, but the amount of those is not high at all, and will not affect DNS servers much.
I hope this helps.
Hi Frank-Yao1
This is a known issue that was solved in newer releases, and we are currently working on porting the fix To JHF of other versions.
Meanwhile please use the following Workaround on your management server:
cloudguard stop
cloudguard start
can you please verify if this solves your issue?
Thanks
Fadi
Please consult the following:
sk131852: Updatable Objects in R80.20 and above
sk135572: Microsoft Office 365 objects as Network Objects in R80.20 and above
sk122636: How to troubleshoot Updatable Objects in R80.20 and higher
Hello Albrecht ,
I already read those SKs and still my questions not answered.
Thanks
Hi @Geomix7 , I tend to agree with @G_W_Albrecht that most of your questions are actually answered in the quoted solutions. Nevertheless, let me answer to those questions directly:
Q: Those services is a combination of IP addresses & domains .How an IP address (mechanism) is checked to verify if match for a domain which is included in Office 365? How this Mechanism works?
A: List of IPs and domains is pulled from the source. Domain objects are also resolved into IP addresses.
Q: Where to position this rule in rule base and why?
A: Updatable objects can be used in the rulebase at will. As they are SXL-friendly, position does not matter.
Q: Any performance impact?
A: Practically no impact.
Q: Known issues ?
A: Specifically for O365, sometimes resolution of MS wild card objects can be incomplete, for certain sub-domains. These occurrences are very rare, but if you experience one, feel free to address it with a support ticket.
Q: Any impact in DNS server?
A: Some unfrequent periodical DNS requests are being sent by FW, but the amount of those is not high at all, and will not affect DNS servers much.
I hope this helps.
Anyone experience issue with updatable objects? I notice in the management dashboard under Validation tab it's showing several objects "is no longer supported". I've seen Microsoft Dynamic CRM Service, Amazon Web Services, Webex Services....even location object United States and Canada.
Is it trying to tell us to upgrade from R80.20 to R80.40?
Hi Frank-Yao1
This is a known issue that was solved in newer releases, and we are currently working on porting the fix To JHF of other versions.
Meanwhile please use the following Workaround on your management server:
cloudguard stop
cloudguard start
can you please verify if this solves your issue?
Thanks
Fadi
Hi,
In the Updatable Object rule for O365 we are receiving logs accepted to Yahoo domain and crosschecked those IP. Those IP are mapped to Yahoo domain.
But the ports are SMTP, TCP 587, IMAP, POP3.
I had attached the screenshot of the logs. Please verify.
Regards,
sajin
Hi,
Updatable Objects can be used in Source and Destination columns only, so it matched only according to IPs (and domains which resolved to IPs).
Updatable Objects are not including ports information.
As part of Office365 Services we have an object called "Office365 Third Party Domains" which includes domains as Yahoo which are derived from MS feed.
Customers would like to avoid getting matches on 3rd party domains, should use the child object called “O365 worldwide services” and not the parent object.
Thanks,
Micky
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 13 | |
| 9 | |
| 8 | |
| 8 | |
| 8 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 3 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY