> Source: [sk135633](https://support.checkpoint.com/results/sk/sk135633)

# sk135633 - AWS objects as Network Objects in R80.20

| Property | Value |
|----------|-------|
| Solution ID | sk135633 |
| Date Created | 2018-09-06 |
| Last Modified | 2018-10-04 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Solution

**Background**

Amazon publishes a list of ranges of AWS services, which is dynamically updated.

**Till R80.20**, customers who wish to restrict access to the AWS services based on IP Addresses need to maintain a Network Group object that contains the relevant Network objects provided by Amazon. The customers keep updating this object manually upon Amazon updates and have to install policy after every change.

**Check Point Solution for R80.20**

* For each published AWS service, Check Point provides a Network Object that can be imported to SmartConsole as an Updatable Object.
* Each AWS Updatable Object matches a list of IP addresses according to the feed published by Amazon.
* On every update in AWS database, these Objects are updated automatically on the gateway (no need to run policy installation).
* When the source or destination IP address matches an object, the action is selected according to the policy.

**Usage**

Click the '+' button under the Source/Destination column, choose import 'Updatable Objects', and then choose the relevant AWS Service from the AWS Services section.

Below is an example of adding AWS updatable objects to Source and Destination columns in Access Policy:

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk135633/AWS1809160031.PNG)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
