- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
We're running R81, and I'm looking to start using the 'Updatable Objects' - particularly the one marked 'Zscaler Services'.
Looking for the below:
Thanks in Advance!
Dan
They are not polled from the management server, they are pulled directly from the gateways once an hour, I believe.
For how Domain Objects work, see: https://support.checkpoint.com/results/sk/sk90401
We list sources for some applications here: https://support.checkpoint.com/results/sk/sk131852
zScaler is specifically listed, and I assume we are pulling the full JSON file they provide: https://config.zscaler.com/api/zscaler.net/cenr/json
All of our Updatable Objects are updated based on vendor-provided JSON/XML.
You should be able to see what's in them: https://community.checkpoint.com/t5/Security-Gateways/AWS-Updateable-Objects/m-p/99010
Or with: https://support.checkpoint.com/results/sk/sk161632
Thanks @PhoneBoy!
Couple follow up questions:
How often are the Vendor JSONs polled/updated by the management server?
Also a quick question while I have you (as I figure it's semi-related):
When using the Domain object (eg. www.checkpoint.com) in a destination, are those resolved IP's cached for some time before being re-polled, or does a resolution happen each time the policy is passed? I'm finding conflicting answers to this.
Thanks again!
They are not polled from the management server, they are pulled directly from the gateways once an hour, I believe.
For how Domain Objects work, see: https://support.checkpoint.com/results/sk/sk90401
Interesting - so each gateway which needs to reference a Updatable Object needs to DNS/Internet or Proxy capability?
I'm quite surprised it's not done from the management server.
Thanks for the SK, will read up on that.
Is there a way to see the URL where the vendor provided json is downloaded from? Then the question of thread opener could be answered.
@dnitskyI guess, ZIA and ZPA are both included as ZEN are used for both. I assume that all necessary targets should be achievable when used in a policy.
We list sources for some applications here: https://support.checkpoint.com/results/sk/sk131852
zScaler is specifically listed, and I assume we are pulling the full JSON file they provide: https://config.zscaler.com/api/zscaler.net/cenr/json
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 24 | |
| 20 | |
| 8 | |
| 7 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY