<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: login attacks coming in with geo protection turned on in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/login-attacks-coming-in-with-geo-protection-turned-on/m-p/239400#M10040</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Traffic is allowed on implied rule. You can disable implied rules, then you can first make a drop rule with geo protection and then allow the rest.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 22 Jan 2025 18:54:34 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2025-01-22T18:54:34Z</dc:date>
    <item>
      <title>login attacks coming in with geo protection turned on</title>
      <link>https://community.checkpoint.com/t5/Endpoint/login-attacks-coming-in-with-geo-protection-turned-on/m-p/239392#M10038</link>
      <description>&lt;P&gt;Does MAB / sslvpn not fall under the umbrella of geo protection?&lt;/P&gt;
&lt;P&gt;I'm seeing DoS login failed attacks coming in from countries even though geo protection should be dropping them (NOT accept).&amp;nbsp; However I see Accept.&amp;nbsp; &amp;nbsp;Maybe, sometimes the IPs don't fall under the right countries?&lt;/P&gt;
&lt;P&gt;Also, I was looking for away to white list networks hitting sslvpn but I'm not seeing that as an option.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 17:19:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/login-attacks-coming-in-with-geo-protection-turned-on/m-p/239392#M10038</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2025-01-22T17:19:58Z</dc:date>
    </item>
    <item>
      <title>Re: login attacks coming in with geo protection turned on</title>
      <link>https://community.checkpoint.com/t5/Endpoint/login-attacks-coming-in-with-geo-protection-turned-on/m-p/239399#M10039</link>
      <description>&lt;P&gt;It probably used implied rules that are matched before the other rules in the policy.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 18:30:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/login-attacks-coming-in-with-geo-protection-turned-on/m-p/239399#M10039</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2025-01-22T18:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: login attacks coming in with geo protection turned on</title>
      <link>https://community.checkpoint.com/t5/Endpoint/login-attacks-coming-in-with-geo-protection-turned-on/m-p/239400#M10040</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Traffic is allowed on implied rule. You can disable implied rules, then you can first make a drop rule with geo protection and then allow the rest.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 18:54:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/login-attacks-coming-in-with-geo-protection-turned-on/m-p/239400#M10040</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-01-22T18:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: login attacks coming in with geo protection turned on</title>
      <link>https://community.checkpoint.com/t5/Endpoint/login-attacks-coming-in-with-geo-protection-turned-on/m-p/239405#M10041</link>
      <description>&lt;P&gt;The only Implied rule I see in global properties that looks relevant is:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Remote Access Control Connections&lt;/P&gt;
&lt;P&gt;Is that https traffic to the MAB portal?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 20:27:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/login-attacks-coming-in-with-geo-protection-turned-on/m-p/239405#M10041</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2025-01-22T20:27:18Z</dc:date>
    </item>
    <item>
      <title>Re: login attacks coming in with geo protection turned on</title>
      <link>https://community.checkpoint.com/t5/Endpoint/login-attacks-coming-in-with-geo-protection-turned-on/m-p/239412#M10042</link>
      <description>&lt;P&gt;Im thinking MAB.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 00:58:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/login-attacks-coming-in-with-geo-protection-turned-on/m-p/239412#M10042</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-23T00:58:17Z</dc:date>
    </item>
    <item>
      <title>Re: login attacks coming in with geo protection turned on</title>
      <link>https://community.checkpoint.com/t5/Endpoint/login-attacks-coming-in-with-geo-protection-turned-on/m-p/239464#M10048</link>
      <description>&lt;P&gt;Believe so, yes.&lt;BR /&gt;Are you using legacy Geo Protection or doing this in a policy layer?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 13:39:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/login-attacks-coming-in-with-geo-protection-turned-on/m-p/239464#M10048</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-01-23T13:39:38Z</dc:date>
    </item>
    <item>
      <title>Re: login attacks coming in with geo protection turned on</title>
      <link>https://community.checkpoint.com/t5/Endpoint/login-attacks-coming-in-with-geo-protection-turned-on/m-p/239467#M10049</link>
      <description>&lt;P&gt;Ah, that may be the issue.&amp;nbsp; Yeah, legacy.&amp;nbsp;&amp;nbsp; We are switching to a unified policy soon, but right now it's a separate policy in MAB.&amp;nbsp; Actually, we do have a test gw with unified, does anyone see documentation RE: add a source geo location in the src column?&amp;nbsp; &amp;nbsp;I don't see anythin the R81.20 admin guide or TP guide for geo location objects.&amp;nbsp; Ah, I found it&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk126172" target="_blank" rel="noopener"&gt;sk126172 - Configuring Geo Policy using Updatable Objects&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you - the dos mitigation rules are working.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 15:06:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/login-attacks-coming-in-with-geo-protection-turned-on/m-p/239467#M10049</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2025-01-23T15:06:09Z</dc:date>
    </item>
    <item>
      <title>Re: login attacks coming in with geo protection turned on</title>
      <link>https://community.checkpoint.com/t5/Endpoint/login-attacks-coming-in-with-geo-protection-turned-on/m-p/239469#M10051</link>
      <description>&lt;P&gt;Do you think a geo location rule in the access policy will block attacks to sslvpn when using legacy vpn (not unified policy)?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 14:16:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/login-attacks-coming-in-with-geo-protection-turned-on/m-p/239469#M10051</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2025-01-23T14:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: login attacks coming in with geo protection turned on</title>
      <link>https://community.checkpoint.com/t5/Endpoint/login-attacks-coming-in-with-geo-protection-turned-on/m-p/239470#M10052</link>
      <description>&lt;P&gt;No, but you can do it with Dos Mitigation rules, which can be geo-specific (not in R82 currently) and will apply before implied rules.&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk112454" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk112454&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 14:19:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/login-attacks-coming-in-with-geo-protection-turned-on/m-p/239470#M10052</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-01-23T14:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: login attacks coming in with geo protection turned on</title>
      <link>https://community.checkpoint.com/t5/Endpoint/login-attacks-coming-in-with-geo-protection-turned-on/m-p/239475#M10054</link>
      <description>&lt;P&gt;has anyone done it before to save me time? &amp;nbsp; For example, if you want to block IP address 94.154.35.24/32 with a dos mitigation rule.&lt;/P&gt;
&lt;P&gt;I may try this one:&lt;/P&gt;
&lt;P&gt;fwaccel dos rate add source cidr:94.154.35.24/32 https byte-rate 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;smartevent proections aren't stopping it either.&amp;nbsp; Brute force for example .&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Update: the dos mitigation blocks are working.&lt;/STRONG&gt;&amp;nbsp; Thank you.&amp;nbsp; Even the inline geo-location rule wasn't in my unified policy.&lt;/P&gt;
&lt;P&gt;It's like wargames, they are trying other networks now.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 15:03:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/login-attacks-coming-in-with-geo-protection-turned-on/m-p/239475#M10054</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2025-01-28T15:03:17Z</dc:date>
    </item>
    <item>
      <title>Re: login attacks coming in with geo protection turned on</title>
      <link>https://community.checkpoint.com/t5/Endpoint/login-attacks-coming-in-with-geo-protection-turned-on/m-p/242405#M10267</link>
      <description>&lt;P&gt;Check Point came out with a fix for this in R82 and R81.20 JHF96 and it works. &lt;/P&gt;
&lt;P&gt;BTW, I'm implementing a negation rule with US as the update-able geo protection object.&amp;nbsp; So, it should block everything that's NOT from the USA.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 13:03:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/login-attacks-coming-in-with-geo-protection-turned-on/m-p/242405#M10267</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2025-02-26T13:03:18Z</dc:date>
    </item>
  </channel>
</rss>

