Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Cathy_Cheng
Participant

Harmony Endpoint Firewall- block internet when VPN is disconnected

Is it possible to use Harmony Endpoint Firewall to achieve the following: block a client’s internet access (except for a few specific websites) when the Endpoint VPN is disconnected?

0 Kudos
4 Replies
Alex-
MVP Silver
MVP Silver

Yes, with location awareness. It's defined by pinging or HTTP'ing defined targets, ideally completely inside the network, and then you can make a Connected/Disconnected policy.

(1)
Cathy_Cheng
Participant

Thanks Alex.  @Alex- 

 So if I define it to ping a few internal hosts, and they are all reachable, that indicates the VPN is connected—correct?

For the connected/disconnected firewall policy, can we allow a few specific websites and block the rest when the VPN is not connected?

 

Is this the location awareness setting?

 
 

firefox_rZgKAPPlBm.png

 

0 Kudos
Alex-
MVP Silver
MVP Silver

Yes. But what you want to achieve is only truly effective if you tunnel all remote VPN traffic through the gateways.

As soon as the VPN is connected, the monitored systems will be reachable so the policy will switch in "Connected" mode.

0 Kudos
Cathy_Cheng
Participant

@Alex- We tunnel all traffic (no Split tunnling) . 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events