<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: can we block non-Hong Kong IP to connection using Endpoint Security VPN? in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/can-we-block-non-Hong-Kong-IP-to-connection-using-Endpoint/m-p/151895#M6537</link>
    <description>&lt;P&gt;actually the global properties is in grey on the accept remote access control connections, and after disable the connection still accepted by the implied rule.&lt;/P&gt;&lt;P&gt;so that no help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jun 2022 07:37:56 GMT</pubDate>
    <dc:creator>JJ</dc:creator>
    <dc:date>2022-06-28T07:37:56Z</dc:date>
    <item>
      <title>can we block non-Hong Kong IP to connection using Endpoint Security VPN?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/can-we-block-non-Hong-Kong-IP-to-connection-using-Endpoint/m-p/151885#M6532</link>
      <description>&lt;P&gt;can we block non-Hong Kong IP to connection using Endpoint Security VPN?&lt;/P&gt;&lt;P&gt;i know that would be controlled by implied rules but i have tested disable in the global policy, which is no help. those traffic still can be access the gateway&amp;nbsp;&lt;/P&gt;&lt;P&gt;but according to&amp;nbsp;&lt;SPAN&gt;sk43401 that state that "enabling certain features (e.g., Clientless VPN) will enable certain Implied Rules that cannot be disabled in SmartConsole / SmartDashboard."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;do anyone know a method to solve it ?&lt;/P&gt;&lt;P&gt;So many thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;JJ&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2022 05:17:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/can-we-block-non-Hong-Kong-IP-to-connection-using-Endpoint/m-p/151885#M6532</guid>
      <dc:creator>JJ</dc:creator>
      <dc:date>2022-06-28T05:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: can we block non-Hong Kong IP to connection using Endpoint Security VPN?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/can-we-block-non-Hong-Kong-IP-to-connection-using-Endpoint/m-p/151887#M6533</link>
      <description>&lt;P&gt;What about using Access Control Policy with Updatable Object (Negate Hong Kong):&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Hong Kong Updatable Object.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17057i4270C37C432F780B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Hong Kong Updatable Object.jpg" alt="Hong Kong Updatable Object.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditor_32d70a4f03fc38Tal_PazFridman_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2022 06:49:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/can-we-block-non-Hong-Kong-IP-to-connection-using-Endpoint/m-p/151887#M6533</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2022-06-28T06:49:09Z</dc:date>
    </item>
    <item>
      <title>Re: can we block non-Hong Kong IP to connection using Endpoint Security VPN?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/can-we-block-non-Hong-Kong-IP-to-connection-using-Endpoint/m-p/151889#M6534</link>
      <description>&lt;P&gt;To disable specific geo locations &lt;STRONG&gt;before&lt;/STRONG&gt; explicit and implied rules you would have to use &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103154" target="_self"&gt;SAM rules&lt;/A&gt; and catch the specific Geo location data from Check Point's &lt;A href="https://sc1.checkpoint.com/freud2/IpToCountry.csv.gz" target="_self"&gt;IP2Country.csv&lt;/A&gt; file. So you'll have to create a little Bash script to catch the location file, grep the IP adresses from Hong Kong and block Endpoint Security VPN connections for all others.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2022 06:56:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/can-we-block-non-Hong-Kong-IP-to-connection-using-Endpoint/m-p/151889#M6534</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2022-06-28T06:56:12Z</dc:date>
    </item>
    <item>
      <title>Re: can we block non-Hong Kong IP to connection using Endpoint Security VPN?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/can-we-block-non-Hong-Kong-IP-to-connection-using-Endpoint/m-p/151892#M6535</link>
      <description>&lt;P&gt;because of the implied rule will accepted the connection before the policy.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2022 07:09:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/can-we-block-non-Hong-Kong-IP-to-connection-using-Endpoint/m-p/151892#M6535</guid>
      <dc:creator>JJ</dc:creator>
      <dc:date>2022-06-28T07:09:07Z</dc:date>
    </item>
    <item>
      <title>Re: can we block non-Hong Kong IP to connection using Endpoint Security VPN?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/can-we-block-non-Hong-Kong-IP-to-connection-using-Endpoint/m-p/151893#M6536</link>
      <description>&lt;P&gt;What about changing the order of the Implied Rules in Global Properties?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2022 07:19:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/can-we-block-non-Hong-Kong-IP-to-connection-using-Endpoint/m-p/151893#M6536</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2022-06-28T07:19:10Z</dc:date>
    </item>
    <item>
      <title>Re: can we block non-Hong Kong IP to connection using Endpoint Security VPN?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/can-we-block-non-Hong-Kong-IP-to-connection-using-Endpoint/m-p/151895#M6537</link>
      <description>&lt;P&gt;actually the global properties is in grey on the accept remote access control connections, and after disable the connection still accepted by the implied rule.&lt;/P&gt;&lt;P&gt;so that no help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2022 07:37:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/can-we-block-non-Hong-Kong-IP-to-connection-using-Endpoint/m-p/151895#M6537</guid>
      <dc:creator>JJ</dc:creator>
      <dc:date>2022-06-28T07:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: can we block non-Hong Kong IP to connection using Endpoint Security VPN?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/can-we-block-non-Hong-Kong-IP-to-connection-using-Endpoint/m-p/151897#M6538</link>
      <description>&lt;P&gt;Hi Danny,&lt;/P&gt;&lt;P&gt;Thanks for your suggestion seems will be work, but using Bash script to catch the location file is too difficult to me to setup.&lt;/P&gt;&lt;P&gt;Anyway thanks for your reply.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;JJ&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2022 07:39:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/can-we-block-non-Hong-Kong-IP-to-connection-using-Endpoint/m-p/151897#M6538</guid>
      <dc:creator>JJ</dc:creator>
      <dc:date>2022-06-28T07:39:37Z</dc:date>
    </item>
    <item>
      <title>Re: can we block non-Hong Kong IP to connection using Endpoint Security VPN?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/can-we-block-non-Hong-Kong-IP-to-connection-using-Endpoint/m-p/151905#M6539</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;i had disable the implied rule as below&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="impliedrule.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17059i798E3B640852137D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="impliedrule.JPG" alt="impliedrule.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; and setup the access policy as below, all problem is solved.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="accesspolicy.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17060i2712F91D84F20A86/image-size/medium?v=v2&amp;amp;px=400" role="button" title="accesspolicy.JPG" alt="accesspolicy.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; so many thanks with all you guy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2022 08:38:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/can-we-block-non-Hong-Kong-IP-to-connection-using-Endpoint/m-p/151905#M6539</guid>
      <dc:creator>JJ</dc:creator>
      <dc:date>2022-06-28T08:38:49Z</dc:date>
    </item>
  </channel>
</rss>

