Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
zumbi
Explorer

GEO VPN policy

Colleagues,

I need some advice about my current small task. We have a two device in cluster and we are using them only for vpn connections from remote users via Checkpoint Mobile for Windows and sometime using SNX SSL VPN for vendors. In general it is pretty simply setup with Radius authentication for all users and groups/role assignment via attribute 26. We have all users in the office mode. Now I need to add some flexibility to our gateways and make access policy more clever. In general I have to provide a custom access to our users based on their country. For example if user has started his VPN connection from Russia it should have an access to the server1. But in case any other county all connections to the server1 should be declined. Meanwhile both these users should have access to our common resources for all countries. 

I tried to disable IKE and NATT inside implied rules on my lab gateway and I can now handle all VPN connection from outside by my policy. When as next step I have put below inline layer with my role and access to the server1 and it does not work at all. It work only if I will put office mode subnet inside these rules. Why I cannot use access role in this case? Maybe someone will be able to recommend better way how I can solve my puzzle with geo vpn?

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

When the Access Policy is being evaluated for traffic from Remote Access users, it is based on their Office Mode IP, which of course has no geography associated with it.
Which means: RFE.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events