- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: With updatable objects do you still need to Ge...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
With updatable objects do you still need to Geo Policy?
Now that since R80.20 there have been Updatable Objects, do we still need to deploy Geo Policy? Although Geo Policy is more on the NIC or ACL level BlockList vs processed by FW workers, what is the Check Point recommendation? Use both for a granular approach? Use Updatable Objects only? Use Geo Policy Only? Does the use of both have any implications on each other? Please Check Point Let me know what you recommend. Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
From a performance perspective, they should operate identically.
From a flexibility perspective, the Dynamic Objects approach is the clear winner.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you have an existing Geo Policy setup you can continue using it. However for any new R80.20+ policies I would strongly advise using Geo Updatable Objects instead. There is a very slight performance edge for Geo Policy as it is checked just after antispoofing long before reaching the security policy where Geo Updatable Objects are located. However Geo Updatable Objects are so much more flexible and easier to use and understand, that I'd advise against using Geo Policy going forward despite its very slight performance edge.
Exclusively at CPX 2025 Las Vegas Tuesday Feb 25th @ 1:00pm
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If our intent was to block these foreign countries sources from externally sourced coming in would this be correct?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
