- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: Updateable Objects - Office 365
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Updateable Objects - Office 365
Hello All,
How accurate are the Update Objects for Microsoft
Can we be sure they cover the URLs listed in the Microsoft Documentation
Do they cover the Allow and Optimise categories?
Many thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Check Point pulls directly from Microsoft for this information. sk131852 has more information including limitations.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I will say in general they work well for us - I am sure however that we also in some cases have broad firewall rules somewhere below in the rule base catching any missing IP missed by the Updateable Objects.
Some pitfalls we see, where some are listed directly, and some are implicit demands due to architecture:
- Are your outbound internet firewall using the same dns server as clients? If not, there could be cache/geo issues with lookups.
- Is it even the same firewall, the client and internet firewalls? Updateable Objects often contain wildcard fqdns. This requires DNS passive learning to work. If the firewalls are different there is no way to share Updatable Object information between them. A low key solution is to enable passive learning on both, and hope that your dns servers does not use DoH, DoT, or DNSCrypt. But how is sync between the two firewalls ensured? and how do you measure it? Is FQDN resolved to cache at the same time for the two firewalls?
So in conclusion for clients asking the answer I give is always - It works, (maybe always?). Which is of course not the best answer in the world.
Regards,
Henrik
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
From all I had seen in R81.20 and R82, they are very accurate.
Andy
