> Source: [sk131852](https://support.checkpoint.com/results/sk/sk131852)

# sk131852 - Updatable Objects

| Property | Value |
|----------|-------|
| Solution ID | sk131852 |
| Date Created | 2018-09-06 |
| Last Modified | 2026-03-12 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Solution

**Table of Contents:**

* Introduction
* Updatable Objects
* Limitations
* Notes
* Usage
* Logging
* Upgrade
* Troubleshooting

Introduction {#Introduction}
----------------------------

> An Updatable Object is a network object that represents an external service, such as Office365, AWS, GEO locations, and more. External service providers publish lists of IP addresses or domains or both, to allow access to their services. These lists are dynamically updated. Updatable Objects derive their contents from these published lists of the providers, which Check Point uploads to the Check Point cloud.
>
> The Updatable Objects are updated automatically on the Security Gateway each time the provider changes a list. There is no need to install policy for the updates to take effect. You can use Updatable Objects in an Access Control policy in the "Source" and "Destination" columns. The traffic is matched based on the TCP \[SYN\] packet based only on an IP address (domains are resolved to IP addresses).
>
> * Starting from R81, Security Gateways support updatable objects in the NAT policy (requires Management Server R81 and higher).
> * Starting from R80.40, Security Gateways support updatable objects in the HTTPS Inspection and Threat Prevention policies (requires Management Server R80.40 and higher).
> * Starting from R80.20, Security Gateways support updatable objects in the Access Control policy (requires Management Server R80.20 and higher).
> * Quantum Spark appliances support updatable objects in R80.20.15 and higher.
>
> New Updatable Objects are added on a monthly basis. Updatable Objects creation relies on common requests from customers to allow access to 3rd-party services. The most common suggestions will get highest priority.
>
> To request an updatable object for an external service that does not appear in the table below, submit a [Request for Enhancement](https://support.checkpoint.com/results/sk/sk71840) and provide these details:
>
> * Service name.
> * Link to public content (IP addresses / Domains) maintained by the vendor.
> * Is it currently used in your policy?

Updatable Objects {#Updatable_Objects}
--------------------------------------

> The table below shows the currently supported external services for updatable objects.
>
> Enter the string to filter this table:
>
> |---------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
> | Feed                      | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
> | Akamai                    | Origin IP Access Control List (Origin IP ACL) offers some protection for your origin server by restricting traffic to Akamai-controlled IP addresses. <https://techdocs.akamai.com/origin-ip-acl/docs/welcome>                                                                                                                                                                                                                                                                                                                                                                                                                         |
> | Amazon Web Services (AWS) | Amazon Web Services (abbreviated AWS) is a collection of remote computing services (also called web services) that together make up a cloud computing platform, offered over the Internet by Amazon. <https://docs.aws.amazon.com/general/latest/gr/aws-ip-ranges.html>                                                                                                                                                                                                                                                                                                                                                                |
> | Apple                     | Apple Inc is a technology company known for designing and manufacturing consumer electronics, software and services. <https://support.apple.com/en-ph/HT210060>                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
> | Azure                     | Microsoft Azure is a collection of cloud computing services created by Microsoft, services like Azure SQL, Storage, Traffic Manager, Cloud, Cosmos DB, Event Hub, Key Vault and Service Bus. Azure is divided into three areas: Public: <https://www.microsoft.com/en-us/download/details.aspx?id=56519> China: <https://www.microsoft.com/en-us/download/details.aspx?id=57062> US Government: <https://www.microsoft.com/en-us/download/details.aspx?id=57063> Germany:<https://www.microsoft.com/en-us/download/details.aspx?id=57064>                                                                                              |
> | Azure Virtual Desktop     | Azure Virtual Desktop is a desktop and app virtualization service that runs on the cloud. <https://learn.microsoft.com/en-us/azure/virtual-desktop/required-fqdn-endpoint?tabs=azure>                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
> | Box                       | Box focuses on cloud content management and file sharing service for businesses. Official clients and apps are available for Windows, macOS, and several mobile platforms. <https://support.box.com/hc/en-us/articles/360043696434-Configuring-A-Firewall-For-Box-Applications>                                                                                                                                                                                                                                                                                                                                                        |
> | Broadcom WSS              | Symantec Web Security Service protects your organization from cyber attacks using an advanced proxy architecture that terminates, inspects, and controls high volumes of web and cloud traffic, even when it's SSL/TLS encrypted. <https://www.broadcom.com/products/cybersecurity/network/web-protection/cloud-secure-web-gateway>                                                                                                                                                                                                                                                                                                    |
> | Check Point               | Provides list of Check Point's online security services domains. See [sk83520](https://support.checkpoint.com/results/sk/sk83520).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
> | CircleCI                  | CircleCI is a continuous integration and delivery (CI/CD) platform used to automate development workflows, run tests, and deploy code. <https://circleci.com/docs/ip-ranges/>                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
> | Citrix Cloud              | Citrix contains allowed FQDNs for cloud connector Citrix Cloud Government: [System and Connectivity Requirements \| Citrix Cloud](https://docs.citrix.com/en-us/citrix-cloud-government/system-requirements/cloud-connector-requirements.html) Citrix Cloud Commercial: [System and Connectivity Requirements \| Citrix Cloud](https://docs.citrix.com/en-us/citrix-cloud/overview/requirements/internet-connectivity-requirements.html)                                                                                                                                                                                               |
> | Cloudflare                | Cloudflare is a large network of servers that can improve the security, performance, and reliability of anything connected to the Internet. <https://www.cloudflare.com/ips/>                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
> | Datadog                   | Datadog is a cloud-based monitoring and analytics platform for infrastructure, applications, and logs. This updatable object includes the IPs used by Datadog agents and services. <https://docs.datadoghq.com/tests/network/>                                                                                                                                                                                                                                                                                                                                                                                                         |
> | DigiCert                  | DigiCert is a certificate authority (CA) that provides TLS/SSL certificates and public key infrastructure (PKI) services. This updatable object includes IPs used for certificate validation, including OCSP and CRL services. <https://knowledge.digicert.com/alerts/digicert-certificate-status-ip-address>                                                                                                                                                                                                                                                                                                                          |
> | Dropbox                   | Dropbox is a file hosting service, offers cloud storage, file synchronization, personal cloud and client software. <https://help.dropbox.com/accounts-billing/security/official-domains>                                                                                                                                                                                                                                                                                                                                                                                                                                               |
> | Duo                       | Duo is a secure access solution that provides multi-factor authentication (MFA). This updatable object includes IPs used by Duo applications. <https://help.duo.com/s/article/1337>                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
> | GEO Locations             | The Geo database is created using information from various internal and external information. See [sk126172](https://support.checkpoint.com/results/sk/sk126172).                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
> | GitHub                    | GitHub is a provider of Internet hosting for software development and version control using Git. <https://docs.github.com/en/github/authenticating-to-github/keeping-your-account-and-data-secure/about-githubs-ip-addresses>                                                                                                                                                                                                                                                                                                                                                                                                          |
> | Google                    | Google Cloud Platform and Google G-Suite services publish their IP addresses on Google's SPF records, which can be dynamically updated. <https://support.google.com/a/answer/10026322> <https://cloud.google.com/compute/docs/faq#networking>                                                                                                                                                                                                                                                                                                                                                                                          |
> | Grafana                   | Grafana is a multi-platform open source analytics and interactive visualization web application. It provides charts, graphs, and alerts for the web when connected to supported data sources. <https://grafana.com/docs/grafana-cloud/reference/allow-list/>                                                                                                                                                                                                                                                                                                                                                                           |
> | HTTPS                     | In some well-known HTTPS services, HTTPS Inspection is unable to establish the trust between the client and the Security Gateway and is therefore unable to inspect the traffic. If you choose to bypass specific HTTPS services to avoid connectivity issues, they will not perform HTTPS Inspection. See [sk163595](https://support.checkpoint.com/results/sk/sk163595).                                                                                                                                                                                                                                                             |
> | IBM MQ                    | IBM MQ is enterprise-grade messaging middleware enabling secure, reliable communication through point-to-point and publish/subscribe models. <https://cloud.ibm.com/docs/mqcloud>                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
> | Imperva                   | Imperva provides cybersecurity solutions designed to protect web applications, APIs, and data assets. Its services include Web Application Firewall (WAF), DDoS protection, bot mitigation, API security, and cloud data protection. <https://docs.imperva.com/bundle/z-kb-articles-knowledgebase-support/page/290228110.html>                                                                                                                                                                                                                                                                                                         |
> | Intune                    | Microsoft Intune is a cloud-based service that focuses on mobile device management and mobile application management. <https://docs.microsoft.com/en-us/mem/intune/fundamentals/intune-endpoints>                                                                                                                                                                                                                                                                                                                                                                                                                                      |
> | Microsoft Defender        | This is a Microsoft Defender object and all its content is subject to Microsoft Defender IPs and Domains. The Microsoft Defender for Endpoint delivers preventative protection, post-breach detection, automated investigation, and response. <https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/?view=o365-worldwide>                                                                                                                                                                                                                                                                                         |
> | Microsoft Dynamics CRM    | The Dynamics Customer Relationship Management (CRM) is a system for managing a company's interactions with current and future customers, using technology to organize, automate, and synchronize sales, marketing, customer service, and technical support. <https://learn.microsoft.com/en-US/previous-versions/troubleshoot/dynamics/crm/internet-accessible-urls>                                                                                                                                                                                                                                                                   |
> | Microsoft Graph           | Microsoft Graph is the gateway to data and intelligence in Microsoft 365. It provides a unified programmability model that you can use to access the tremendous amount of data in Microsoft 365, Windows, and Enterprise Mobility + Security. <https://learn.microsoft.com/en-us/graph/overview>                                                                                                                                                                                                                                                                                                                                       |
> | Netskope                  | Netskope is a cloud-native security platform offering Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), Zero Trust Network Access (ZTNA), and data protection services. This updatable object includes the IPs required for connection to Netskope services. <https://docs.netskope.com/en/newedge-ip-ranges-for-allowlisting/>                                                                                                                                                                                                                                                                                           |
> | Office365                 | Microsoft Office 365 cloud services, such as Skype for Business Online, Exchange Online and more, are commonly used by organizations. Office365 is divided into 4 areas: US Government DoD Services, GCC High Services, China Services and Worldwide Services. <https://docs.microsoft.com/en-us/microsoft-365/enterprise/microsoft-365-ip-web-service?view=o365-worldwide>                                                                                                                                                                                                                                                            |
> | Okta                      | Okta is an identity management service, runs in the cloud and connects any person with any application on any device. <https://help.okta.com/en-us/Content/Topics/Security/ip-address-allow-listing.htm>                                                                                                                                                                                                                                                                                                                                                                                                                               |
> | Oracle                    | Oracle is a computer technology corporation that provides cloud-based and on-premises software and hardware solutions. This object contains Oracle Cloud Infrastructure IPs <https://docs.oracle.com/en-us/iaas/Content/General/Concepts/addressranges.htm>                                                                                                                                                                                                                                                                                                                                                                            |
> | PingOne                   | PingOne is an identity-as-a-service (IDaaS) solution by Ping Identity, providing cloud-based identity management, SSO and MFA. <https://docs.pingidentity.com/pingone/developer_tools/p1_ip_address_domain_reference.html>                                                                                                                                                                                                                                                                                                                                                                                                             |
> | Quantum Spark Smart Accel | Improves connectivity and optimizes the load on the Quantum Spark Security Gateway. Once enabled, traffic enforcement is accelerated for selected services. Note: Firewall and logging activity is not affected. Smart Accel is currently in EA and is only supported in locally managed Gaia Embedded appliances / Quantum Spark Security Gateways running version R81.10 and higher.                                                                                                                                                                                                                                                 |
> | Red Hat                   | Red Hat is providing open source software solutions and enterprise Linux operating systems <https://access.redhat.com/articles/1525183>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
> | Salesforce                | This is a Salesforce object and all its content is subject to Salesforce IPs. Salesforce provides customer relationship management service and also provides enterprise applications focused on customer service, marketing automation, analytics, and application development. [https://help.salesforce.com/s/articleView?id=000321501\&type=1](https://help.salesforce.com/s/articleView?id=000321501&type=1)                                                                                                                                                                                                                        |
> | SAP                       | This is a SAP object and all its content is subject to SAP. SAP develops enterprise software to manage business operations and customer relations and especially known for its ERP software. <https://help.sap.com/docs/btp/sap-business-technology-platform/regions-and-api-endpoints-available-for-cloud-foundry-environment> <https://help.sap.com/docs/btp/sap-business-technology-platform/regions-and-api-endpoints-for-abap-environment> <https://help.sap.com/docs/btp/sap-btp-neo-environment/regions-and-hosts-available-for-neo-environment> <https://help.sap.com/docs/connectivity/sap-btp-connectivity-cf/prerequisites> |
> | Skyhigh Security (McAfee) | McAfee is an American global computer security software company. <https://status.skyhighsecurity.com/swg/>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
> | TOR Exit Nodes            | This updatable object includes IP addresses identified as participating in the Tor network. See [sk103154](https://support.checkpoint.com/results/sk/sk103154).                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
> | UserZoom                  | UserZoom is a provider of user experience (UX) insights solution for quick design iteration, user-focused product decisions, and measuring UX performance <https://help.userzoom.com/hc/en-us/articles/360001494237-UserZoom-on-restricted-networks>                                                                                                                                                                                                                                                                                                                                                                                   |
> | WatchGuard                | WatchGuard offers advanced threat prevention and detection solutions. [https://techsearch.watchguard.com/KB?type=Article\&SFDCID=kA10H000000kCQ1SAM](https://techsearch.watchguard.com/KB?type=Article&SFDCID=kA10H000000kCQ1SAM)                                                                                                                                                                                                                                                                                                                                                                                                      |
> | Webex                     | Webex provides on-demand collaboration, online meeting, web conferencing and videoconferencing applications. Webex object is divided into two objects: Third Party Services: contains third party domains used by Webex Main Services: contains Cisco-owned domains and IPs used by Webex <https://help.webex.com/en-us/article/WBX000028782/Network-Requirements-for-Webex-Services>                                                                                                                                                                                                                                                  |
> | Windows 365               | Windows 365 is a cloud service that streams a personalized Windows operating system to any device. <https://learn.microsoft.com/en-us/windows-365/enterprise/requirements-network?tabs=enterprise>                                                                                                                                                                                                                                                                                                                                                                                                                                     |
> | Zendesk                   | Zendesk is a customer service platform offering ticketing, live chat, and support tools for businesses. <https://developer.zendesk.com/api-reference/ticketing/account-configuration/public_ips/>                                                                                                                                                                                                                                                                                                                                                                                                                                      |
> | Zero Phishing Bypass      | To skip unnecessary scans on popular sites, we highly recommend to configure the Zero-Phishing blade to bypass specific popular sites. This object should be configured only in Threat Prevention policy as latest rule. See [sk179726](https://support.checkpoint.com/results/sk/sk179726).                                                                                                                                                                                                                                                                                                                                           |
> | Zoom                      | Zoom is an enterprise video communications, provides a cloud platform for video and audio conferencing across mobile devices, desktops, telephones and room systems. <https://support.zoom.us/hc/en-us/articles/201362683-Network-Firewall-or-Proxy-Server-Settings-for-Zoom>                                                                                                                                                                                                                                                                                                                                                          |
> | Zscaler                   | Zscaler is a cloud-based information security company which provides secure access to locally hosted and external applications. <https://config.zscaler.com/zscaler.net/cenr>                                                                                                                                                                                                                                                                                                                                                                                                                                                          |

> {#Unique_IDTable}

Limitations {#Limitations}
--------------------------

> * Updatable Objects are supported only for Security Gateways R80.20 and higher (requires Management Server R80.20 and higher).
> * Updatable Objects are supported in HTTPS Inspection and Threat Prevention policies for only Security Gateways R80.40 and higher.
> * Updatable Objects are supported in NAT policy only for Security Gateways R81 and higher (requires Management Server R81 and higher).  
>   NAT policy does not support Group objects that contain Updatable Objects.
> * Updatable Objects are supported on Quantum Spark appliances only for R80.20.15 and higher.
> * To work well, the DNS configured on the Security Gateways must be the same as that used by the endpoints. Otherwise, the IP-to-Domain mapping will not match.
> * In case of a change in DNS servers, the process WSDNSD on the Security Gateways must be restarted to use the new DNS servers.
> * The Security Gateway and Management Server must have connectivity to Check Point servers `updates.checkpoint.com` and `dl3.checkpoint.com`. These servers send updates that are necessary to use Updatable Objects. The Security Gateway and Management Server also must have connectivity to other servers, such as `crl.globalsign.com`, to receive updates. For more information, see [sk83520](https://support.checkpoint.com/results/sk/sk83520).  
>   On VSX Gateways - each Virtual System (that must use Updatable Objects) must have connectivity to these Check Point servers.  
>   There are different packages for the Security Gateway and for the Management Server.  
>   To check the connectivity to the `updates.checkpoint.com` server, run this command in the Expert mode (see [sk83520](https://support.checkpoint.com/results/sk/sk83520)):  
>   `curl_cli --cacert $CPDIR/conf/ca-bundle.crt https://updates.checkpoint.com/WebService/services/DownloadMetaDataService?wsdl`

Notes {#Notes}
--------------

> * Each domain received from an external vendor feed is considered a Domain Object as described in [sk90401: How do Domain Objects work?](https://support.checkpoint.com/results/sk/sk90401)
> * Updatable Objects are matched based on the TCP \[SYN\] packet - based only on the IP address.  
>   If you have a domain that resolved to an IP address that is part of an Updatable Object, then it can be matched on the rule that contains this Updatable Object.
> * We recommend to review the IP addresses / Domains inside the Updatable Objects before you use other domains with same IP addresses (so the traffic is not matched to those domains).
> * To enforce differently and distinguish between several domains that resolved to same IP address, use the "Service/Application" column in the rules.

Usage {#Usage}
--------------

> Click the '+' button under the Source/Destination column, choose import 'Updatable Objects', and then you can choose the relevant Service (as shown below):
>
> ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk131852/UO1809042357.png)
>
Logging {#Logging}
------------------

> <br />
>
> The log details of the applicable connection show the updatable object in the Source and Destination IP addresses fields.  
> To filter logs that match an updatable object, enter the updatable object display name in the search box, wrapped by double quotes, without specifying a specific column.

Upgrade {#Upgrade}
------------------

> <br />
>
> Starting from the Jumbo Hotfixes below, policy installation fails if the policy contains Updatable Objects but there is no package on the Security Gateway:  
>
> * R80.40 Jumbo Hotfix Take 211
> * R81 Jumbo Hotfix Take 99
> * R81.10 Jumbo Hotfix Take 131
> * R81.20 Jumbo Hotfix Take 43
>
> Because of this behavior, if you upgrade a Security Gateway that does not have a package to one of the Jumbo Hotfix Takes listed above, the Security Gateway does not fetch the policy after boot, and subsequent policy installations fail until a package is downloaded successfully.  
>
> To resolve this issue, refer to the "Troubleshooting" section below (to resolve the package download issues) or remove all Updatable Objects from the policy.

Troubleshooting {#Troubleshooting}
----------------------------------

> For issues with importing Updatable Objects in SmartConsole - refer to [sk122636](https://support.checkpoint.com/results/sk/sk122636).  
>
> Show All Scenarions  
>
> <br />
>
> ### Scenario 1 - The Updatable Objects package is missing on the Security Gateway
>
> Show / Hide this section  
>
> 1. Make sure DNS server(s) are configured and reachable from the Security Gateway.
> 2. If you use a Proxy Server, make sure that it is configured (in SmartConsole) and that it is reachable from the Security Gateway.
> 3. Run on the Security Gateway (in the Expert mode):  
>    `unified_dl UPDATE ONLINE_SERVICES`  
>    Example output:  
>    `Got response : Request was completed successfully`
> 4. Check if this file exists:  
>    `ls -l $CPDIR/database/downloads/ONLINE_SERVICES/1.0/last_revision.xml`
>    * If the file exists, then you now have the Online Services package on your Security Gateway and you can install the policy.
>    * If the file does not exist, and you have another Security Gateway that can access the internet, follow the procedure below, "Copying Updatable Objects from a Security Gateway".
>    * If the file does not exist and you do **not** have another Security Gateway that can access the internet, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/).
> 5. Reboot the Security Gateway.
>
> **Copying Updatable Objects Files from a Security Gateway**   
> You can copy updatable objects from a Security Gateway that has internet access. You can use a Security Gateway of any supported version.  
>
> ****Procedure****
>
> 1. In the CLI of the Security Gateway from which you want to copy updatable objects, enter the Expert Mode.  
>
> 2. Make sure that updatable objects exist on the Security Gateway. Run:
>
>    ```
>    unified_dl UPDATE ONLINE_SERVICES
>    ```
>
>    Example output:
>
>    ```
>    [Expert@SomeHostname:0]# cd $CPDIR/database/downloads/ONLINE_SERVICES/1.0/
>
>    [Expert@SomeHostname:0]# ls -al
>
>    total 28
>
>    drwx------ 5 admin root �176 Jun 17 11:38 .
>
>    drwx------ 3 admin root � 17 Jun �5 15:00 ..
>
>    drwx------ 2 admin root 4096 Jun �6 01:19 050624211202
>
>    drwx------ 2 admin root 4096 Jun �6 07:19 060624031147
>
>    drwx------ 2 admin root 4096 Jun 17 11:38 170624091150
>
>    -rw-rw---- 1 admin root �113 Jun 17 11:38 Update_Status.dat
>
>    -rw-rw---- 1 admin root �111 Jun 17 11:38 last_revision.xml
>
>    -rw-rw---- 1 admin root �111 Jun 17 11:38 last_revision_old.xml
>
>    -rw-rw---- 1 admin root � 41 Jun 17 11:38 tmp_revisions_order.txt
>
>    [Expert@SomeHostname:0]# cat Update_Status.dat
>
>    (
>
>    � � � � :Last_Update_Status (2)
>
>    � � � � :Last_Update_Time (1718617115)
>
>    � � � � :Last_Update_Reason ()
>
>    � � � � :Success_Time (1718617115)
>
>    )
>
>    [Expert@SomeHostname:0]# cat last_revision.xml ; echo
>
>    <?xml version='1.0' encoding='utf-8'?>
>
>    <RevisionInfo><Last_Revision>170624091150</Last_Revision></RevisionInfo>
>
>    [Expert@SomeHostname:0]#
>    ```
>
> 3. Make sure that these files exist:
>
>    * *Update_Status.dat* file, which contains Unix epoch values (a long string of numbers representing the date/time).
>    * *Last_Update_Time* file
>    * *Success_Time* file
>    * *last_revision.xml* file  
>
> 4. Create a backup copy of the entire directory and verify the file. In these examples, the "`~/`" characters mean that the file is stored in the home directory of the user who runs these commands.
>    1. Show the directory you are currently in:  
>       `[Expert@SomeHostname:0]# pwd`  
>       Example directory:  
>       `/opt/CPshrd-R81.20/database/downloads/ONLINE_SERVICES/1.0`
>    2. Create the backup file. Example for R81.20:  
>       `[Expert@SomeHostname:0]# tar cvzf ~/dynamic_objects_backup.tgz -C $CPDIR/database/downloads/ONLINE_SERVICES/1.0 . `
> 5. Copy the resulting file from the source Security Gateway and then transfer it to the destination Security Gateway.   
>
> 6. On the destination Security Gateway, go to the relevant directory and extract the files.  
>    **Note:** In a VSX environment, do this step for every Security Gateway instance that does not have the Updatable Objects files.   
>    1. Go to the directory:
>
>           [Expert@Somehostname:0]# cd $CPDIR/database/downloads/ONLINE_SERVICES/1.0
>
>    2. Extract the file:  
>       `[Expert@Somehostname:0]# tar xzf ~/dynamic_objects_backup.tgz`
>
>    The destination Security Gateway now has the Updatable Objects files that are required for policy installation,
>
> ### Scenario 2 - Cannot Add Some Updatable Objects
>
> Show / Hide this section  
> > **Symptoms** :  
> >
> > * You cannot add some updatable objects.
> > * Some updatable objects are greyed out.
> > * In SmartConsole, updatable objects show a bar (**-**) for cloud services, not the actual icon.
> > * The SmartConsole computer has connectivity to the Security Management Server.
> > * The Security Management Server has access to the internet and to `https://updates.checkpoint.com/`.   
> >   Run this command to make sure there is connectivity:  
> >   `# curl_cli -vk https://updates.checkpoint.com`
> > * The PC has access to the internet and to `http://secureupdates.checkpoint.com/appi/v1_0_0/icons/`.
> > * Replacing the updatable objects manually with this procedure does not resolve the issue:   
> >   1. Upload a file called `online_services_mgmt.tgz` (contact TAC for this step):   
> >      `# mv $MDS_FWDIR/conf/SMC_Files/uo $MDS_FWDIR/conf/SMC_Files/uo_backup1`
> >   2. Extract the `online_services_mgmt.tgz` to `$FWDIR/conf $MDS_FWDIR/conf/SMC_Files/uo`.
> >   3. Run this command in the Expert mode:   
> >      `# cloudguard off; cloudguard on`   
> >      or  
> >      `# cpstop;cpstart`
> >   4. Deleting the objects and updating from the cloud with this procedure does not resolve the issue:  
> >      1. Open an SSH connection to the Security Management Server.
> >      2. Move or delete this directory:  
> >         `# mv $MDS_FWDIR/conf/SMC_Files/uo $MDS_FWDIR/conf/SMC_Files/uo_backup1`
> >      3. Run this command:  
> >         `# cpstop;cpstart`
> >      4. After the Security Management Server is backed up, log in to SmartConsole.
> >      5. Open the updatable objects picker (go to Security Policies \> \<Policy_Package\> \> Access Control \> click the rule's source or destination column to add an object \> click Import \> Updatable Objects and add the required object.
> >
> > **Procedure:**   
> >
> > Use the latest SmartConsole:
> >
> > * [R81.20 SmartConsole](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20_SC/Default.htm)
> > * [R81.10 SmartConsole](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10_SC/Default.htm)
> > * [R81 SmartConsole](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81_SC/Default.htm)
> > * [R80.40 SmartConsole](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40_SC/Default.htm)
> >
> > If the issue continues to occur, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/).
> >
> > For faster resolution, collect these files and command outputs and attach them to your Service request:
> >
> > 1. In SmartConsole, replicate the issue:
> >    1. From the left navigation panel, click **Security Policies**.
> >    2. Open the applicable Policy Package.
> >    3. At the top, click **Access Control**.
> >    4. In the applicable rule, in the **Source** or the **Destination** column, click **\[+\]** to add an object \> click **Import** \> click **Updatable Objects** \> add the required object.
> > 2. Collect the [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server.
> > 3. From the Management Server, collect these files and command outputs:
> >    1. All files in this directory:  
> >       `$MDS_FWDIR/conf/SMC_Files/uo`
> >    2. All files in this directory:  
> >       `$MDS_FWDIR/conf/SMC_Files/debug_uo`
> >    3. All files in this directory:  
> >       `$CPDIR/database/downloads/ONLINE_SERVICES/`
> >    4. These files:  
> >       `$MDS_FWDIR/log/cloud_proxy.elg*`
> >    5. These files:  
> >       `$FWDIR/log/cpm.elg*`
> >    6. These files:  
> >       `$MDS_FWDIR/log/fwm.elg*`
> >    7. This file:  
> >       `$CPDIR/database/downloads/ONLINE_SERVICES/1.0/last_revision.xml`
> >    8. Output of this command in the Expert mode (copy and paste the text from the SSH session):  
> >       `unified_dl UPDATE ONLINE_SERVICES`
> > 4. A Support Engineer will provide you with the latest CPM Doctor script to collect additional information from the Management Server.
>
> ### Scenario 3 - Updatable Objects for Dropbox Services
>
> Show / Hide this section  
> > Dropbox publishes a list of domains that are dynamically updated.Before R80.20, if you wanted to restrict access to Dropbox services, based on domains, it was necessary to maintain a Domain objects that contained URLs of Dropbox. You had to keep updating these objects manually upon Dropbox updates and had to install policy after each change.
> >
> > **Solution:**
> >
> > * Check Point provides a Network Object that can be imported to SmartConsole as an Updatable Object for Dropbox services.
> > * This Dropbox Updatable Object matches a list of domains based on the web page published by Dropbox.
> > * On each update in the Dropbox web page, these Objects are updated automatically on the gateway (it is not necessary to run policy installation).
> > * When the source or destination IP address matches an object, the action is selected according to the policy.
> >
> > **How to:**
> >
> > 1. In the Source/Destination column, click the plus button and select **import Updatable Objects.**
> > 2. Select **Dropbox Services**.
> >
> > Below is an example of adding the Dropbox services updatable object to the Destination column in Access Policy:
> >
> > ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk131852/dropbox-updatable-object202305181658071.png)
>
> ### Scenario 4 - Zoom unable to connect to Video Conferencing with Zoom Updatable Objects in Rule
>
> Show / Hide this section  
> > IP address connect to subnets related to Google, AWS, and more.  
> > When the user runs `netstat -ab`, the IP address do not show in `Zoom.exe`.
> >
> > **Cause:**
> >
> > Zoom IP addresses are hosted by multiple vendors.
> >
> > **Solution:**
> >
> > 1. Add the relevant updatable objects to the rules to allow Zoom.
> > 2. Below the **Source/Destination** column, click the plus button \> select **Import Updatable Objects**.
> > 3. Select the applicable Object.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
