- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi Guys,
i would like to know is it possible for us to create a rule that only accept connection coming from specific country for speficic services?
i believe the first portion can be done using clean up rule or spefic drop rule but then the most important part is to only allow access specific service from specific country for eg: singapore, as we are not able to list down all malaysia subnets inside this rules.
please advise.
If you have an R80.20+ management and gateway, you can do that easily via Updatable Objects. Updatable Objects representing countries can be used like any other object in your rule base. If you have R80.10 or earlier, you could use the Geo Policy/Protection feature to block all traffic from a particular country then create an exception allowing a particular service from that country. A bit roundabout but will work.
If you have an R80.20+ management and gateway, you can do that easily via Updatable Objects. Updatable Objects representing countries can be used like any other object in your rule base. If you have R80.10 or earlier, you could use the Geo Policy/Protection feature to block all traffic from a particular country then create an exception allowing a particular service from that country. A bit roundabout but will work.
Yes, that is the easiest option and it works perfectly fine.
Be careful with blocking everything else than my own country type of policy. The reason is simple. Today many cloud based services have servers in many countries without you knowing it. Blocking everything else except US for example might lead to connectivity problems if a DNS server happens to be in Germany.
Following this thread, what is the best practice in checkpoint security policies allow the DNS service but securing that service.
We have an autorize server that it should be connect with the others DNS servers (cloudfare DNS, cisco DNS, google DNS, etc), so what can be done?
Are there a configuration more specific for that service that a simple rules as below ?
5 - deny countries (a few countries)
10 - allow our public IP DNS server -> any DNS service
15 - allow any -> our public IP DNS server DNS service
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY