- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello friends
I have a doubt in the execution of an activity.
I have an SSL VPN and client on my firewall gateway R80.10 Manager R80.30
I want to block Geo Policy and the countries that I release I want some to use the VPN tunnel as a Gateway for all traffic
and other countries use their internet provider to access the internet.
Is it possible to do this someone has this experience and can share how to do it?
I can tell you from my own experience, best way to do this is create rule(s) to allow traffic from certain country (countries) and then create a rule below that to block traffic from that country.
So, say for example you wish to let people in subnet 10.40.30.0/24 access anything in Russia. You would create a rule with that subnet in source, then updatable object country as Russia, put service(s) and allow, but then right below that rule, you would create another rule that says source any to Russia, block.
Does that make sense?
In order to have granular Geo Protection rules, the gateways need to be on R80.20 or above.
Which is highly recommended anyway since R80.10 is soon to be End of Support.
You can configure it so the client can choose whether to route all traffic through the gateway or not.
However, you can't force some users to route all traffic and allow others to split tunnel.
Hey Good afternoon
I understand I understand that on R80.10 I can't force via manager some SSL VPN traffic and client via split tunnel and others using your local provider for external access?
But I can do this on R80.20 or higher.
And it is recommended that the user determine this locally in their Endpoint Security Checkpoin?
The options available are basically: yes, no, and “client decide” where the client can choose whether to route all traffic through the VPN or not.
These options can only be configured globally, not based on location or user group.
Newer versions than R80.10 are the same in this regard.
Hey Good afternoon
Yes it makes sense, I would create a Policy Access Control denying the origin of Russia and China and allowing Japan and USA.
But how do I release Japan using VPN SSL as default for external access such as google and USA use your local internet provider for external access, eg google
Well, as I said, if you need to allow certain countries/services, you just make a rule to reflect that. Message me offline, we can do remote session and Im happy to show you.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY