Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Ilovecheckpoint
Participant
Jump to solution

updatable objects are a kind of dynamic objects?

I want to create a global domain policy that blocks communications from specific countries.

I've created a group for them and assigned the policy to different domains.

I want to ensure that the objects in each domain are updated dynamically.

For dynamic objects, it is necessary to add the _global suffix, in order to trigger the reference replacement mechanism.

What about updatable objects?

Are they updated dynamically on each domain as well?

Can I check their content or at least their object number to compare a global domain with a specific domain?

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

For Dynamic Objects in MDS in R8x, see: https://community.checkpoint.com/t5/Management/Dynamic-Global-Objects-no-longer-supported/m-p/7654#M...
But, yes, you're correct.
In both cases, the actual content of the object resides on the gateway itself, not on the management.

View solution in original post

8 Replies
PhoneBoy
Admin
Admin

For Dynamic Objects in MDS in R8x, see: https://community.checkpoint.com/t5/Management/Dynamic-Global-Objects-no-longer-supported/m-p/7654#M...
But, yes, you're correct.
In both cases, the actual content of the object resides on the gateway itself, not on the management.

genisis__
Leader Leader
Leader

May sound like a silly question but what is the difference between a dynamic object and domain object?  I ask because when creating a dynamic object example "www.abc.com" rather then ".abc.com" it does not work, yet if I do the same thing with a domain object, it does work.

0 Kudos
_Val_
Admin
Admin

I assume you mean FQDN Domain object. Is so, it is an object that FW resolves into an IP through DNS queries. Dynamic object is a logical container that is filled with IPs from an external source. In your case, if you do not feed an abc.com dynamic object with relevant IPs, it will not be matched to anything in your rulebase, hence the observed behavior. 

Best to read the management admin guide for your version for more details.

0 Kudos
genisis__
Leader Leader
Leader

Great thanks,  I did suspect this when I found some CLI commands to add IPs to dynamic objects, are the same performance issues there related to FQDN objects in R81.x?

 

0 Kudos
PhoneBoy
Admin
Admin

Dynamic Objects were not SecureXL friendly in pre-R80 versions.
In current versions, they are SecureXL friendly, so there should be no performance impact.

0 Kudos
genisis__
Leader Leader
Leader

Great! Thanks for the confirmation.

0 Kudos
jlechuti
Explorer

What are the risks of deploying dynamic objects ?

0 Kudos
genisis__
Leader Leader
Leader

I would say the main things I can think of are:
DNS

Access to the Internet for the appliance to retrieve the databases.

Vendor updating IP addresses and the time it takes for the database to be updated with the new information.

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events