- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
need to configure external dynamic lists in Checkpoint
Please elaborate, it is unclear what you are trying to achieve.
Ok, that's clear enough. So you have a list of IP addresses, and you want to block them on your FWs.
You can use the notion of a dynamic object, explained here: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Dynamic object is basically an empty logical box that can be used in the rules and should be filled with IP addresses on the GW side. Mind, you will need to script the population of the dynamic object in use with GW side scripting.
Another option is to use MGMT API and fill in a certain group on the management side, but every time the list is changed, you will have to re-push policy on GWs.
In the link you provided it says that “A Dynamic Object is a "logical" object that will be resolved to an IP address differently on each Security Gateway using the dynamic_objects command. A rule that uses this Dynamic Object will then be enforced on each Security Gateway on different objects.”
I think there is some misunderstanding in the requirement.
Have a look at sk132193 - it describes how to subscribe a gateway to a Custom Intelligence Feed. Sounds like that might be a better match for your requirements?
Thanks,
Ruan
That is also an option
It does not have to be resolved to _different_ IPs on _different_ GWs. It is up to you to decide how you populate your Dynamic Object
Not exactly sure what you expect me to check here.
This SK no longer exists
There are several ways to do this with some assembly required.
This older thread is still applicable and discusses several options: https://community.checkpoint.com/t5/Policy-Management/list-of-different-IP-addresses-to-be-blocked/m...
In R81, we should also have custom Updatable Objects that can be fed from your own JSON file.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 27 | |
| 15 | |
| 14 | |
| 13 | |
| 12 | |
| 7 | |
| 6 | |
| 5 | |
| 5 | |
| 5 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY