- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Re: Troubleshoot Geo policy after sk126172
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Troubleshoot Geo policy after sk126172
Hi!
We've recently moved our Geo policy on R81.10 to updatable objects as per sk126172 but as I'm running into what I believe is a false positive, I have a hard time troubleshooting the issue. Basically most Checkpoint SKs don't clarify if the steps are still valid for this new method or only for the old "host" method.
For example, the IP 199.49.20.6 is blocked by our policy. We allow traffic to USA, Canada and most European countries.
I check MaxMind DB and that IP is marked as USA...
I check the IP on my gateway IpToCountry.csv (timestamps March 7) using sk94364 and it comes up within a USA range...
I check SmartConsole and the logs mark the IP as USA...
I proceed with this one-liner to update the management IpToCountry.csv file which now marks the IP as from Bermuda. Not in line with MaxMind but Bermuda would indeed be blocked by our policy.
I download the latest IpToCountry.csv as per sk84801 and now I see that 199.49.20.6 is indeed now from Bermuda in that latest file. I didn't update it on the gateway, just a download on my computer to compare with the file on my gateway.
Clearly something doesn't add up here...
So would I be correct to say that Management still uses the IpToCountry.csv file to assign the flags and that file needs to be manually updated so flags are correctly represented?
And also that the gateway does not use the IpToCountry.csv file anymore? I didn't update the IpToCountry.csv on my gateway so it should be flagged as USA but yet it's flagged as something else since it's being blocked (Bermuda presumably).
If that is true and like stated in sk126172 the information is grabbed from MaxMind instead, why does my gateway not return the same results as that DB? And where is that info stored if not the CSV anymore? Can I force an update?
This is so confusing! Any guidance would be appreciated!
- Labels:
-
IPS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Management is still using the IpToCountry.csv file.
Gateways are blocking per the Updatable Objects for those countries.
It’s a different way to retrieve the same information from a different backend.
See: https://community.checkpoint.com/t5/Management/R80-20-Updatable-Domain-Objects-and-CLI-Commands/m-p/...
Note in both cases, the data comes from MaxMind.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is there any method to check what country and IP is associated to? Similar to how it can be done with IpToCountry.csv
From your referred post all I get from domains_tool is more or less equivalent to nslookup reverse dns lookup.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Let me know please @casgrain if you find that out. I actuallt had customer ask that exact question to TAC person on the phone, but they never gotten back to us if its even possible.
Would be nice if there is a command to do it.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can see the actual definitions downloaded to the gateway in a subdirectory of $CPDIR/database/downloads/ONLINE_SERVICES/1.0/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would check out below:
Never mind, I realized after I posted it you did that already. Maybe get TAC case created and get this sorted out.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'll go down that path to clarify things. Especially if there's a method to check IP/Country association manually and how to verify/trigger updates of those mappings. I'll make sure to share the info afterwards.
