Updatable Objects
An updatable object is a network object which represents an external service, such as Office 365, AWS, GEO locations and more. External services providers publish lists of IP addresses or Domains or both to allow access to their services. These lists are dynamically updated. Updatable objects derive their contents from these published lists of the providers, which Check Point uploads to the Check Point cloud. The updatable objects are updated automatically on the Security Gateway Dedicated Check Point server that runs Check Point software to inspect traffic and enforce Security Policies for connected network resources. each time the provider changes a list. There is no need to install policy for the updates to take effect. You can use updatable objects in all three types of policies: Access Control, Threat Prevention and HTTPS Inspection Feature on a Security Gateway that inspects traffic encrypted by the Secure Sockets Layer (SSL) protocol for malware or suspicious patterns. Synonym: SSL Inspection. Acronyms: HTTPSI, HTTPSi.. You can use an updatable object in the Access Control, Threat Prevention or the HTTPS Inspection policy as a source or a destination. In the Threat Prevention policy, you can also use an updatable object as the protected scope.
Notes:
-
For Access Control, this feature is supported for R80.20 and above gateways. For Threat Prevention and HTTPS Inspection, this feature is supported for R80.40 and above gateways.
-
Updatable Objects cannot be added to a network group.
Adding an Updatable Object to the Security Policy
A customer uses Office365 and wants to allow access to Microsoft Exchange services.
To add the Microsoft Exchange Updatable Object to the Security Gateway
-
Make sure the Security Management Server Dedicated Check Point server that runs Check Point software to manage the objects and policies in a Check Point environment within a single management Domain. Synonym: Single-Domain Security Management Server. and the Security Gateway have access to the Check Point cloud.
-
Go to SmartConsole Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on. > Security Policies Collection of rules that control network traffic and enforce organization guidelines for data protection and access to resources with packet inspection. > Access Control > Policy.
-
In the Destination column, click the + sign and select Import > Updatable Objects.
The Updatable Objects window opens.
-
Select the objects to add. For this use case, select the Exchange Services object.
Note - You can also add objects to the Source column.
-
Click OK.
-
Install policy.
The Exchange Services object is added to the Rule Base All rules configured in a given Security Policy. Synonym: Rulebase..
You can monitor the updates in the Logs & Monitor > Logs view.
To monitor the updates
-
Go to SmartConsole > Logs & Monitor.
-
From the search bar, enter Updatable Objects.
-
Double-click the relevant log.
The Log Details window shows.
-
Succeeded
shows in the Status field when the update is successful.