- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
The last Geo Location update on Quantum Security Gateways appears to have an error.
[Expert@fw:0]# ls -la $CPDIR/database/downloads/ONLINE_SERVICES/1.0/150622030521/geo_location.C
Jun 14 17:02 /opt/CPshrd-R81/database/downloads/ONLINE_SERVICES/1.0/150622030521/geo_location.C
A newer update for updatable objects (sk121877) is currently not available.
Multiple customers report that regional IP addresses are blocked as they are wrongly located in Russia.
MaxMind correcty shows them as regional IP addresses in Germany but Check Point Quantum Security Gateways do not.
Example: 92.217.8.19
MaxMind shows: Munich, Germany
Check Point shows the IP within a big block for Russia within geo_location.C:
:CP_GEO_RU (
:parent ()
:uuid ("909383a0-c34b-49ef-b423-c0168a37c37d")
:display_name ("Russia")
:icon ("@app/cp_geo_ru")
:IPV4 (
: (
:from ("91.228.62.0")
:to ("92.228.64.255")
:type (ip_range)
)
[Expert@fw:0]# dynamic_objects -lo CP_GEO_RU | grep 92.228.
range : 91.228.62.0 - 92.228.64.255
Hello CheckMates,
We are working on a solution for this issue, and aiming for releasing it today. sorry for the inconvenience.
thanks
Eitan
I would like to share an update on the ongoing Geo enforcement issue
For any customers who are using IPS Geo Protection, and not Geo Updateable Objects (R80.30 and above)
Customers that applied the manual workaround, should revert the change to get the new update.
Please follow the steps below to manually deploy the change on demand, if waiting for the auto-update cycle is not an option
Per sk131852 > Troubleshooting: Run on your Gateway machine:
# unified_dl UPDATE ONLINE_SERVICES
Thank you for your understanding and cooperation, we appreciate the patience
Hey @Danny,
We're having the exact same issue. Our gateway last updated the iptocountry.csv file at 10pm UK time last night. It seems that the URL referenced in SK120261 is no longer available (https://sc1.checkpoint.com/freud2/IpToCountry.csv.gz). I wonder if Check Point have pulled the file?
Do you know if it's possible to revert to a previous version of this file on the gateway? Our support provider have a ticket raised with TAC, but have said they're starting to get a lot of other customers reporting this issue.
Thanks,
Aaron.
It should be possible to revert to a previous revision by extracting it from a backup.
Example: tar -tzvf /var/log/CPbackup/backups/backup_filename.tgz | grep geo_location.C
Simply copy and paste the revision folder to $CPDIR/database/downloads/ONLINE_SERVICES/1.0/
and adjust $CPDIR/database/downloads/ONLINE_SERVICES/1.0/last_revision.xml
to point to that revision.
Alternatively you can temp. unblock Russia in your security policy or configure Allow rules for the affected network ranges.
@Danny please raise a TAC case for this, thanks
🙂 This is the first thing we did.
Thank you
Put that subject on top. This affect several clients in France too. TAC cases opened too.
MaxMind updates it daily, CP weekly only - so false positives happen every couple of weeks, i had three such cases with CP in the last 2 month...
But i am very suspicious concerning GeoIP.
Hello CheckMates,
We are working on a solution for this issue, and aiming for releasing it today. sorry for the inconvenience.
thanks
Eitan
Customers from UK reporting it as well.
Geo-Policy affected too. I suppose it feeds from the same as updateable objects.
I would like to share an update on the ongoing Geo enforcement issue
For any customers who are using IPS Geo Protection, and not Geo Updateable Objects (R80.30 and above)
Customers that applied the manual workaround, should revert the change to get the new update.
Please follow the steps below to manually deploy the change on demand, if waiting for the auto-update cycle is not an option
Per sk131852 > Troubleshooting: Run on your Gateway machine:
# unified_dl UPDATE ONLINE_SERVICES
Thank you for your understanding and cooperation, we appreciate the patience
Thanks Mate!
Yep im seeing the same issue today
Today I’m seeing danish ip addresses from Telia showing us as Swedish ip adresses.. even ripe has them
shown as danish
Please report via TAC case
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
17 | |
11 | |
6 | |
6 | |
6 | |
5 | |
5 | |
5 | |
4 | |
4 |
Tue 23 Sep 2025 @ 06:00 PM (IDT)
Under the Hood: CloudGuard Network Security for Nutanix - Overview, Onboarding, and Best PracticesWed 24 Sep 2025 @ 03:00 PM (CEST)
Bereit für NIS2: Strategische Werkzeuge für Ihre Compliance-Reise 2025Wed 24 Sep 2025 @ 03:00 PM (CEST)
Bereit für NIS2: Strategische Werkzeuge für Ihre Compliance-Reise 2025Thu 25 Sep 2025 @ 03:00 PM (IDT)
NIS2 Compliance in 2025: Tactical Tools to Assess, Secure, and ComplyThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY