Print Download Complete help as Archive Send Feedback

Previous

Next

Updatable Objects

What can I do here?

Use this window to import objects that will be automatically updated from external cloud services.

Getting Here

Getting Here - Security Policies > Access Control > Policy > Source or Destination column > Add button > Import > Updatable Objects

Updatable Objects

An updatable object is a network object which represents an external service, such as Office 365, AWS, GEO locations and more. External services providers publish lists of IP addresses or Domains or both to allow access to their services. These lists are dynamically updated. Updatable objects derive their contents from these published lists of the providers, which Check Point uploads to the Check Point cloud. The updatable objects are updated automatically on the Security Gateway each time the provider changes a list. There is no need to install policy for the updates to take effect. You can use an updatable object in the Access Control policy as a source or a destination.

Note - This feature is only supported for R80.20 and above gateways.

Adding an Updatable Object to the Security Policy

A customer uses Office365 and wants to allow access to Microsoft Exchange services.

To add the Microsoft Exchange Updatable Object to the Security Gateway:

  1. Make sure the Security Management Server and the Security Gateway have access to the Check Point cloud.
  2. Go to SmartConsole > Security Policies > Access Control > Policy.
  3. Create a new rule.
  4. In the Destination column, click the + sign and select Import > Updatable Objects.

    The Updatable Objects window opens.

  5. Select the objects to add. For this use case, select the Exchange Services object.

    Note - You can also add objects to the Source column.

  6. Click OK.
  7. Install policy.

The Exchange Services object is added to the Rule Base.

No

Name

Source

Destination

VPN

Services & Applications

Action

Track

1

Accept Exchange

WirelessZone

Exchange Services

Any

Any

Accept

Log

2

Accept Exchange

Exchange Services

WirelessZone

Any

Any

Accept

Log

You can monitor the updates in the Logs & Monitor Logs view.

To monitor the updates:

  1. Go to SmartConsole > Logs & Monitor.
  2. From the search bar, enter Updatable Objects.
  3. Double-click the relevant log.

    The Log Details window shows.

  4. Succeeded shows in the Status field when the update is successful.