I would like to share an update on the ongoing Geo enforcement issue
For any customers who are using IPS Geo Protection, and not Geo Updateable Objects (R80.30 and above)
Customers that applied the manual workaround, should revert the change to get the new update.
Please follow the steps below to manually deploy the change on demand, if waiting for the auto-update cycle is not an option
- Updatable Objects - a new release will be sent out at 1900 IL time today, while FWs update frequency is every 2 hours. that means without any manual intervention, all FWs should get the new update by 2100 IL time.
- To enforce an update on demand for Updatable; objects:
Per sk131852 > Troubleshooting: Run on your Gateway machine:
# unified_dl UPDATE ONLINE_SERVICES
- IPS Geo Protection ( IP2country)- fixed release was uploaded and the FWs should get this on their next update that happens every 24 hours, without any manual intervention. (maximum by tomorrow 1600 IL time)
- Check Point recommendation is to use only Updatable Objects from FW R80.20 upwards instead of IPS Geo.
- To enforce an update on demand for IPS Geo Policy:
- Download the latest IpToCountry.csv file from this URL:
- http://downloads.checkpoint.com/fileserver/ID/11901/FILE/IpToCountry.csv.gz
- Transfer the IpToCountry.csv.gz file to the Security Gateway / each Cluster Member to some directory.
- Connect to the command line on the Security Gateway / each Cluster Member.
- Log in to the Expert mode.
- Go to the directory with the IpToCountry.csv.gz file.
- Unpack the IpToCountry.csv.gz file:
$CPDIR/util/gzip -df IpToCountry.csv.gz
- Copy the file IpToCountry.csv to $FWDIR/tmp/geo_location_tmp/updates/ directory:
cp -v IpToCountry.csv $FWDIR/tmp/geo_location_tmp/updates/
- In SmartConsole, install the Access Control policy on the Security Gateway / Cluster object.
Thank you for your understanding and cooperation, we appreciate the patience