<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ukraine IP address filling 75% of my VPN Logs in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Ukraine-IP-address-filling-75-of-my-VPN-Logs/m-p/187294#M1016</link>
    <description>&lt;P&gt;I would suggest using GEO policy to block the country, if you do not expect any connections coming from there.&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jul 2023 07:37:54 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2023-07-24T07:37:54Z</dc:date>
    <item>
      <title>Ukraine IP address filling 75% of my VPN Logs</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Ukraine-IP-address-filling-75-of-my-VPN-Logs/m-p/187281#M1015</link>
      <description>&lt;P&gt;When checking the logs of my Harmony Connect VPN service I can see that there is a couple of IPs address coming from Ukraine that are generating 75% of my logs.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face="inherit"&gt;Are you &lt;/FONT&gt;experiencing&lt;FONT face="inherit"&gt;&amp;nbsp;the same?&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Last week I reported the same incident but from two different IPs as well from Ukraine and looks to me that the TAC people helped me out to block them. last IP:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;109.207.200.44&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If you check your Harmony Connect VPN logs, can you see them too?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand the part of: they do not have the keys, or certificate and etc to break in, yeah, but those IPS are saturating Check Point logs and probably even degrading the service.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know how to block them with involving TAC? I already added a policy that blocks any access from those IPs and nothing actually happened because I think it only applies to the valid traffic inside the VPN.&amp;nbsp;&lt;/P&gt;&lt;P&gt;An email was sent today to the organization in Ukraine that are in charge of those IPs. nothing might happen!&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thoughts?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 05:34:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Ukraine-IP-address-filling-75-of-my-VPN-Logs/m-p/187281#M1015</guid>
      <dc:creator>ICSI</dc:creator>
      <dc:date>2023-07-24T05:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: Ukraine IP address filling 75% of my VPN Logs</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Ukraine-IP-address-filling-75-of-my-VPN-Logs/m-p/187294#M1016</link>
      <description>&lt;P&gt;I would suggest using GEO policy to block the country, if you do not expect any connections coming from there.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 07:37:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Ukraine-IP-address-filling-75-of-my-VPN-Logs/m-p/187294#M1016</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-07-24T07:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: Ukraine IP address filling 75% of my VPN Logs</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Ukraine-IP-address-filling-75-of-my-VPN-Logs/m-p/187307#M1017</link>
      <description>&lt;P&gt;Same, GEO protection and block the unwanted countries.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the SK:&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk126172" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk126172&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 08:53:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Ukraine-IP-address-filling-75-of-my-VPN-Logs/m-p/187307#M1017</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2023-07-24T08:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: Ukraine IP address filling 75% of my VPN Logs</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Ukraine-IP-address-filling-75-of-my-VPN-Logs/m-p/187344#M1018</link>
      <description>&lt;P&gt;This (before encryption) traffic is accepted through implied rules.&lt;BR /&gt;Short of changing the implied rules, the best way to block this traffic is using fwaccel dos rules:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Block-VPN-Traffic-by-Country/m-p/172695#M31396" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Block-VPN-Traffic-by-Country/m-p/172695#M31396&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 13:02:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Ukraine-IP-address-filling-75-of-my-VPN-Logs/m-p/187344#M1018</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-24T13:02:23Z</dc:date>
    </item>
    <item>
      <title>Re: Ukraine IP address filling 75% of my VPN Logs</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Ukraine-IP-address-filling-75-of-my-VPN-Logs/m-p/187440#M1019</link>
      <description>&lt;P&gt;I believe this is a result of bots/vulnarebility_scaneers&amp;nbsp; activities.&lt;/P&gt;
&lt;P&gt;Based on topic you're using Harmony Connect Network Access client. Please raise ticket with TAC to block&amp;nbsp; traffic&amp;nbsp; from countries you don't want get traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 07:23:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Ukraine-IP-address-filling-75-of-my-VPN-Logs/m-p/187440#M1019</guid>
      <dc:creator>Andy_P</dc:creator>
      <dc:date>2023-07-25T07:23:59Z</dc:date>
    </item>
  </channel>
</rss>

