<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restricting vpn user login, Static IP wise in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Restricting-vpn-user-login-Static-IP-wise/m-p/251582#M1885</link>
    <description>&lt;P&gt;"&lt;SPAN&gt;So you only want user X to connect via Remote Access from IP Y, correct?" yes correct&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regarding the geolocation block method (Block VPN Traffic by Country), I guess it makes no sense in my scenario, as all my users will be logging in from the same country. Unfortunately as mentioned I guess this is not possible to implement.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jun 2025 03:30:52 GMT</pubDate>
    <dc:creator>bcmario</dc:creator>
    <dc:date>2025-06-19T03:30:52Z</dc:date>
    <item>
      <title>Restricting vpn user login, Static IP wise</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Restricting-vpn-user-login-Static-IP-wise/m-p/251496#M1882</link>
      <description>&lt;P&gt;Is it possible to restrict checkpoint vpn users login, static IP wise?&lt;/P&gt;&lt;P&gt;I have an environment where 5 vpn users are allowed to log into the office environment via checkpoint vpn. If I provide each of them with a broadband connection with static IPs, could I restrict them from connecting from any other connection?&lt;/P&gt;&lt;P&gt;If the answer is yes, what guide could I follow to configure this?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2025 06:44:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Restricting-vpn-user-login-Static-IP-wise/m-p/251496#M1882</guid>
      <dc:creator>bcmario</dc:creator>
      <dc:date>2025-06-18T06:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting vpn user login, Static IP wise</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Restricting-vpn-user-login-Static-IP-wise/m-p/251567#M1883</link>
      <description>&lt;P&gt;So you only want user X to connect via Remote Access from IP Y, correct?&lt;BR /&gt;As far as I know, this isn't possible.&lt;/P&gt;
&lt;P&gt;You might be able to prevent Remote Access from working AT ALL from all but a few IPs by using dos rules similar to:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Block-VPN-Traffic-by-Country/m-p/172695#M31396" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Block-VPN-Traffic-by-Country/m-p/172695#M31396&lt;/A&gt;&lt;BR /&gt;You'll need to read the SK there to get the exact syntax.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2025 22:04:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Restricting-vpn-user-login-Static-IP-wise/m-p/251567#M1883</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-06-18T22:04:53Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting vpn user login, Static IP wise</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Restricting-vpn-user-login-Static-IP-wise/m-p/251578#M1884</link>
      <description>&lt;P&gt;The only possible way I can think of might be something like below:&lt;/P&gt;
&lt;P&gt;src -&amp;gt; static IP address&lt;/P&gt;
&lt;P&gt;dst -&amp;gt; as needed&lt;/P&gt;
&lt;P&gt;service -&amp;gt; any&lt;/P&gt;
&lt;P&gt;vpn -&amp;gt; remote access community&lt;/P&gt;
&lt;P&gt;action -&amp;gt; drop&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jun 2025 01:44:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Restricting-vpn-user-login-Static-IP-wise/m-p/251578#M1884</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-19T01:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting vpn user login, Static IP wise</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Restricting-vpn-user-login-Static-IP-wise/m-p/251582#M1885</link>
      <description>&lt;P&gt;"&lt;SPAN&gt;So you only want user X to connect via Remote Access from IP Y, correct?" yes correct&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regarding the geolocation block method (Block VPN Traffic by Country), I guess it makes no sense in my scenario, as all my users will be logging in from the same country. Unfortunately as mentioned I guess this is not possible to implement.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jun 2025 03:30:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Restricting-vpn-user-login-Static-IP-wise/m-p/251582#M1885</guid>
      <dc:creator>bcmario</dc:creator>
      <dc:date>2025-06-19T03:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting vpn user login, Static IP wise</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Restricting-vpn-user-login-Static-IP-wise/m-p/251583#M1886</link>
      <description>&lt;P&gt;In this method, I will have to block all public IPs barring the 5 static IPs I will provide my users, correct? Basically, at least all public IPs of my country barring the 5 given ones.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jun 2025 03:34:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Restricting-vpn-user-login-Static-IP-wise/m-p/251583#M1886</guid>
      <dc:creator>bcmario</dc:creator>
      <dc:date>2025-06-19T03:34:17Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting vpn user login, Static IP wise</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Restricting-vpn-user-login-Static-IP-wise/m-p/251603#M1887</link>
      <description>&lt;P&gt;You just block IPs needed to be blocked.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jun 2025 11:01:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Restricting-vpn-user-login-Static-IP-wise/m-p/251603#M1887</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-19T11:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting vpn user login, Static IP wise</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Restricting-vpn-user-login-Static-IP-wise/m-p/251788#M1888</link>
      <description>&lt;P&gt;I said similar to not exactly the same as.&lt;BR /&gt;You wouldn't be allowing access to/from a country, but specific IPs.&amp;nbsp;&lt;BR /&gt;The SK I was referring to was linked in the original:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk112454" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk112454&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;This refers to fwaccel dos commands, which I believe can be used to achieve what you're after.&lt;BR /&gt;More specifically, you'd have to do something like the following: (replace X.X.X.X with external gateway IP and Y.Y.Y.Y with source IPs, repeat for each source IP):&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier"&gt;[Expert@R8120:0]#&amp;nbsp;&lt;STRONG&gt;fwaccel&lt;/STRONG&gt;&lt;/FONT&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt; dos rate add -a d -l a service 17/500 source Y.Y.Y.Y destination cidr:X.X.X.X/32 pkt-rate 100000&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This command sets a rate limit on IKE traffic (UDP 500, needed to start a VPN negotiation) to 100000 IKE packets per second.&lt;BR /&gt;IKE Negotiations happen infrequently and don't require anywhere near this amount of packets.&lt;BR /&gt;However, you can now rate limit everything else IKE related to zero, effectively blocking the traffic:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier"&gt;[Expert@R8120-GA:0]#&amp;nbsp;&lt;STRONG&gt;fwaccel dos rate add -a d -l a service 17/500 source any destination cidr:X.X.X.X/32 pkt-rate 0&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Note the above merely blocks the IKE negotiation, which is needed to establish a VPN connection (Site to Site or Remote Access).&lt;BR /&gt;I believe that is sufficient to achieve your objective.&lt;/P&gt;
&lt;P&gt;The above commands need to be entered in expert mode on each gateway in the cluster.&lt;BR /&gt;Read the SK linked above for more information.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2025 15:41:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Restricting-vpn-user-login-Static-IP-wise/m-p/251788#M1888</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-06-23T15:41:27Z</dc:date>
    </item>
  </channel>
</rss>

