Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Networks_Team_B
Participant

Updateable Objects - Office 365

Hello All,

How accurate are the Update Objects for Microsoft 

Can we be sure they cover the URLs listed in the Microsoft Documentation

Do they cover the  Allow and Optimise categories?

Many thanks 

0 Kudos
3 Replies
masher
Employee
Employee

Check Point pulls directly from Microsoft for this information. sk131852 has more information including limitations.

Henrik_Noerr1
Advisor

I will say in general they work well for us - I am sure however that we also in some cases have broad firewall rules somewhere below in the rule base catching any missing IP missed by the Updateable Objects.

Some pitfalls we see, where some are listed directly, and some are implicit demands due to architecture:

- Are your outbound internet firewall using the same dns server as clients? If not, there could be cache/geo issues with lookups.

- Is it even the same firewall, the client and internet firewalls? Updateable Objects often contain wildcard fqdns. This requires DNS passive learning to work. If the firewalls are different there is no way to share Updatable Object information between them. A low key solution is to enable passive learning on both, and hope that your dns servers does not use DoH, DoT, or DNSCrypt. But how is sync between the two firewalls ensured? and how do you measure it? Is FQDN resolved to cache at the same time for the two firewalls?

 

So in conclusion for clients asking the answer I give is always - It works, (maybe always?). Which is of course not the best answer in the world.

Regards,

Henrik

 

 

 

0 Kudos
the_rock
Legend
Legend

From all I had seen in R81.20 and R82, they are very accurate.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events