Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Paschoal
Participant

VPN Access

Hello friends

I have a doubt in the execution of an activity.
I have an SSL VPN and client on my firewall gateway R80.10 Manager R80.30
I want to block Geo Policy and the countries that I release I want some to use the VPN tunnel as a Gateway for all traffic
and other countries use their internet provider to access the internet.

Is it possible to do this someone has this experience and can share how to do it?

0 Kudos
6 Replies
the_rock
Authority
Authority

I can tell you from my own experience, best way to do this is create rule(s) to allow traffic from certain country (countries) and then create a rule below that to block traffic from that country.

So, say for example you wish to let people in subnet 10.40.30.0/24 access anything in Russia. You would create a rule with that subnet in source, then updatable object country as Russia, put service(s) and allow, but then right below that rule, you would create another rule that says source any to Russia, block.

Does that make sense?

0 Kudos
PhoneBoy
Admin
Admin

In order to have granular Geo Protection rules, the gateways need to be on R80.20 or above.
Which is highly recommended anyway since R80.10 is soon to be End of Support.

You can configure it so the client can choose whether to route all traffic through the gateway or not.
However, you can't force some users to route all traffic and allow others to split tunnel.

0 Kudos
Paschoal
Participant

Hey Good afternoon

I understand I understand that on R80.10 I can't force via manager some SSL VPN traffic and client via split tunnel and others using your local provider for external access?

But I can do this on R80.20 or higher.

And it is recommended that the user determine this locally in their Endpoint Security Checkpoin?

0 Kudos
PhoneBoy
Admin
Admin

The options available are basically: yes, no, and “client decide” where the client can choose whether to route all traffic through the VPN or not.
These options can only be configured globally, not based on location or user group.
Newer versions than R80.10 are the same in this regard.

0 Kudos
Paschoal
Participant

Hey Good afternoon

Yes it makes sense, I would create a Policy Access Control denying the origin of Russia and China and allowing Japan and USA.

But how do I release Japan using VPN SSL as default for external access such as google and USA use your local internet provider for external access, eg google

0 Kudos
the_rock
Authority
Authority

Well, as I said, if you need to allow certain countries/services, you just make a rule to reflect that. Message me offline, we can do remote session and Im happy to show you.

0 Kudos