<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Geo Policy block VPN traffic from blocked countries? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-block-VPN-traffic-from-blocked-countries/m-p/146126#M23154</link>
    <description>&lt;P&gt;For sure, 100%...it would have to be static IP, I agree. If its dynamic IP, there is no way for firewall to differentiate that if the country is say, Egypt, and its blocked in your GEO policy.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 12 Apr 2022 17:08:11 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2022-04-12T17:08:11Z</dc:date>
    <item>
      <title>Geo Policy block VPN traffic from blocked countries?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-block-VPN-traffic-from-blocked-countries/m-p/145920#M23091</link>
      <description>&lt;P&gt;I am configuring Geo policy with updatable objects and am wondering if there will be any impact? If someone from one of the blocked countries, tries to access our VPN...and they are actually authorized, will they be allowed to connect if their country is on the dropped list?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Apr 2022 23:10:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-block-VPN-traffic-from-blocked-countries/m-p/145920#M23091</guid>
      <dc:creator>seanmc12</dc:creator>
      <dc:date>2022-04-10T23:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: Geo Policy block VPN traffic from blocked countries?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-block-VPN-traffic-from-blocked-countries/m-p/145921#M23092</link>
      <description>&lt;P&gt;If it's all enforced / terminating on a single Gateway you will likely find the implied rules allow the remote access traffic without incident. Refer:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Restrict-VPN-access-by-GEO-location/m-p/117288" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Restrict-VPN-access-by-GEO-location/m-p/117288&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;incident.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 00:14:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-block-VPN-traffic-from-blocked-countries/m-p/145921#M23092</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-04-11T00:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: Geo Policy block VPN traffic from blocked countries?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-block-VPN-traffic-from-blocked-countries/m-p/145922#M23093</link>
      <description>&lt;P&gt;I can tell you from my own experience that every time specific country is blocked, it gets enforced 100%, even for VPN.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Apr 2022 23:32:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-block-VPN-traffic-from-blocked-countries/m-p/145922#M23093</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-04-10T23:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: Geo Policy block VPN traffic from blocked countries?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-block-VPN-traffic-from-blocked-countries/m-p/145989#M23117</link>
      <description>&lt;P&gt;If you have a country defined as "block to and from" in Geo Policy (not Geo Updatable Objects) they will not be allowed to connect at all as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;stated.&amp;nbsp; This may have changed in later releases, but last time I looked Geo Policy enforcement is performed just after anti-spoofing enforcement and before any "First" implied rules allowing Remote Access VPN traffic are consulted.&amp;nbsp; However if the newer Geo Updatable Objects are used, that enforcement will not happen until after the implied rules.&amp;nbsp; So they will be able to at least connect in that case.&lt;/P&gt;
&lt;P&gt;However Geo Policy was deprecated in R81 (hidden in some cases but still works) so there really isn't a long-term solution for completely blocking certain countries for Remote Access VPN before the implied rules are enforced.&amp;nbsp; One possibility is using fw samp/fwaccel dos which allows the specification of a country code, then grant them a bandwidth/connection rate of zero (if that is possible).&lt;/P&gt;
&lt;P&gt;The only other way I could think of to do this would be an RFE that allows specified countries to be blocked right on the topology page for any interface designated "External" in the Firewall's topology, along with perhaps a way to add exceptions or a "don't check packets from" to that enforcement on that same screen.&amp;nbsp; Kind of a per interface Geo Policy similar to the per-interface Advanced...Multicast Restrictions feature.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another RFE avenue for this functionality might be the ability to choose countries in a Gaia Policy Based Routing configuration and blackhole them.&amp;nbsp; But the former SmartConsole-based approach would probably be easier to understand and troubleshoot.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 16:30:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-block-VPN-traffic-from-blocked-countries/m-p/145989#M23117</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-04-11T16:30:40Z</dc:date>
    </item>
    <item>
      <title>Re: Geo Policy block VPN traffic from blocked countries?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-block-VPN-traffic-from-blocked-countries/m-p/145990#M23118</link>
      <description>&lt;P&gt;Thanks for the response. I have configured Geo updatable objects. So I was thinking I could put an exception just before the updatable objects rule and the user from say China, would be able to authenticate and use VPN, but any other traffic would be blocked at the GUO policy.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 16:40:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-block-VPN-traffic-from-blocked-countries/m-p/145990#M23118</guid>
      <dc:creator>seanmc12</dc:creator>
      <dc:date>2022-04-11T16:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: Geo Policy block VPN traffic from blocked countries?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-block-VPN-traffic-from-blocked-countries/m-p/145992#M23119</link>
      <description>&lt;P&gt;Thats excellent idea...as long as that rule is BEFORE geo rule blocking the traffic from given country, you are good to go.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 16:43:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-block-VPN-traffic-from-blocked-countries/m-p/145992#M23119</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-04-11T16:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: Geo Policy block VPN traffic from blocked countries?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-block-VPN-traffic-from-blocked-countries/m-p/146123#M23153</link>
      <description>&lt;P&gt;Unfortunately, the only way this will work is if your remote individual comes into your network with a static IP address. With a dynamic IP, the firewall will block all of the data from the applicable country before it ever sees the user creds. I should have known that piece.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 16:33:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-block-VPN-traffic-from-blocked-countries/m-p/146123#M23153</guid>
      <dc:creator>seanmc12</dc:creator>
      <dc:date>2022-04-12T16:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: Geo Policy block VPN traffic from blocked countries?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-block-VPN-traffic-from-blocked-countries/m-p/146126#M23154</link>
      <description>&lt;P&gt;For sure, 100%...it would have to be static IP, I agree. If its dynamic IP, there is no way for firewall to differentiate that if the country is say, Egypt, and its blocked in your GEO policy.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 17:08:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Geo-Policy-block-VPN-traffic-from-blocked-countries/m-p/146126#M23154</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-04-12T17:08:11Z</dc:date>
    </item>
  </channel>
</rss>

