Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
jennyado
Collaborator
Jump to solution

“Legacy GeoProtection Maximum Ranges” alert

Hi,

While reviewing the latest HCP report, I noticed the following alert:

Legacy GeoProtection Maximum Ranges
Description:
This test verifies if legacy GeoProtection will be able to update successfully based on the geo_max_ip_ranges kernel parameter.
Finding:
The number of ranges in the current IpToCountry.csv exceeds the maximum allowed value in kernel parameter: geo_max_ip_ranges.
Suggested Solution:
Increase the value of kernel parameter geo_max_ip_ranges to be higher than the current number of ranges in IpToCountry.csv (341359).

I’m curious about this alert because it references a kernel-level parameter that seems to have a defined limit, and I’m not sure what the implications might be of modifying it.

So, I wanted to ask:

  • How safe is it to increase the value of the geo_max_ip_ranges parameter?

  • Would there be any noticeable performance or memory impact if we modify it?

  • Is there an alternative way to handle or suppress this alert?

Any guidance or experience with this specific HCP finding would be greatly appreciated.

Thanks in advance!

1 Solution

Accepted Solutions
the_rock
MVP Platinum
MVP Platinum

Hi Jenn,

I verified this with TAC and they confirmed that all that message says is that gateway's IPToCountry.csv file contains more ranges that what kernel parameter sllows, so its totally safe to change it to something higher, no issues.

Here is an example in my lab:

[Expert@CP-GW:0]# fw ctl get int geo_max_ip_ranges
geo_max_ip_ranges = 300000
[Expert@CP-GW:0]# fw ctl set -f int geo_max_ip_ranges 500000
"fwkern.conf" was updated successfully
[Expert@CP-GW:0]# more /opt/CPsuite-R82/fw1/boot/modules/fwkern.conf
sip_forward_if_needed=1
geo_max_ip_ranges=500000
[Expert@CP-GW:0]#

Best,
Andy

View solution in original post

0 Kudos
2 Replies
the_rock
MVP Platinum
MVP Platinum

Personally, and this is just me, I would not bother with any of that. Its simply refers to ip ranges, but truth be told, literally 99% of customers would simply add countries they wish to block, which you can use updatable objects for, thats it.

Best,
Andy
0 Kudos
the_rock
MVP Platinum
MVP Platinum

Hi Jenn,

I verified this with TAC and they confirmed that all that message says is that gateway's IPToCountry.csv file contains more ranges that what kernel parameter sllows, so its totally safe to change it to something higher, no issues.

Here is an example in my lab:

[Expert@CP-GW:0]# fw ctl get int geo_max_ip_ranges
geo_max_ip_ranges = 300000
[Expert@CP-GW:0]# fw ctl set -f int geo_max_ip_ranges 500000
"fwkern.conf" was updated successfully
[Expert@CP-GW:0]# more /opt/CPsuite-R82/fw1/boot/modules/fwkern.conf
sip_forward_if_needed=1
geo_max_ip_ranges=500000
[Expert@CP-GW:0]#

Best,
Andy
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events