- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello everyone,
Is it possible to block *any source to access/create a site in Remote Access VPN? I'm only wanting to allow some source/device from outside (src: IP-Public) can remote access.
I'm create a stealth rule, block all source access to external ip of Gateway:
now from my computer I can't ping/ssh to gateway, but still access webUI (443) and remote access to Gateway successfully.
Is there other rule that I miss? Please help me.
Purpose: only allow some devices to connect to remote access vpn (whitelist using IP-Public of device)
Thank you so much and have a great day!
Best regards,
Kha
I'm curious about this too. You can specify this on a country basis on one of other firewall vendor. For example, you can tell me to only connect via VPN from China.
I think it is related Implied Rules
There are two elements of Implied Rules here:
Hello PhoneBoy,
I'm follow the sk105740: set according to the Firewall policy (SmartConsole > Platform Portal > Accessibility > Edit), now I can control access WebUI on port 443 with Access Rule.
But for the Remote Access VPN, it didn't affect, I tried with rule: block *any source to external IP -> still remote access successfully.
For The actual VPN connection (starts with IKE on UDP 500). Short of hacking .def files: I didn't find any sk, document related, can you explain more about it, please?
Thanks & Best regards,
Kha
I had copy/pasted the wrong link above.
Should be: https://community.checkpoint.com/t5/Security-Gateways/Block-VPN-Traffic-by-Country/m-p/172695#M31396
Now fixed in the original post also.
Three ways to achive this:
- Why not define RA VPN using certificates only ?
- use IA Roles in Access Rule so only a few can connect to the network
- use Legacy SecuRemote client without Office Mode that needs the source IP used in the rule base
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY