Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Saranya_0305
Collaborator

Geo Protection-Exception for Remote VPN Users

Dear Mates,


We are currently operating a Check Point environment with the Management Server and Firewalls running on R82. These firewalls are connected directly to the ISP.

At present, we have implemented Geo-Blocking for all countries except India.

We now have a requirement where remote access VPN users (employees traveling internationally for business) must be allowed connectivity, regardless of the country they are connecting from, while maintaining the existing Geo-Block policy.

Could you please advise if there is a recommended configuration approach, or relevant Check Point community/documentation post that addresses this requirement?

 

Thanks,

Saranya

0 Kudos
5 Replies
simonemantovani
Contributor

Hello

just a question, do you have disabled the option "Accept Remote Access control connections" in the the Global Properties under Firewall section?

To apply Geo proteciont to Remote Access VPN, I think you should uncheck the option above and then configure the policy to permit/block VPN protocols based on geo location. (I never test this solution).

The ports required for VPN are reported in this SK: sk52421.

0 Kudos
PhoneBoy
Admin
Admin

VPN traffic (including Remote Access) should be permitted through Implied Rules already.
Which means you should not need to take an action to meet this requirement.

the_rock
MVP Diamond
MVP Diamond

I agree with @PhoneBoy . If you want to do it another way, check out my post from while ago.

https://community.checkpoint.com/t5/SASE-and-Remote-Access/Geo-VPN-blocking/m-p/214040#M10593

Best,
Andy
0 Kudos
simonemantovani
Contributor

Interesting approach, so you control and appy geo policy only on the port 443 (first port used by the client with visitor mode enabled).

Ok, clear.

0 Kudos
the_rock
MVP Diamond
MVP Diamond

That is 100% right, because thats the port needed for remote access.

Best,
Andy
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 24 Feb 2026 @ 04:30 PM (EST)

    Las Vegas: MDR/XMDR

    Wed 25 Feb 2026 @ 04:30 PM (MST)

    Tempe, AZ: MDR/MXDR

    Wed 11 Mar 2026 @ 12:00 PM (MDT)

    CheckMates Live Denver!
    CheckMates Events