- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
can we block non-Hong Kong IP to connection using Endpoint Security VPN?
i know that would be controlled by implied rules but i have tested disable in the global policy, which is no help. those traffic still can be access the gateway
but according to sk43401 that state that "enabling certain features (e.g., Clientless VPN) will enable certain Implied Rules that cannot be disabled in SmartConsole / SmartDashboard."
do anyone know a method to solve it ?
So many thanks
Regards,
JJ
What about using Access Control Policy with Updatable Object (Negate Hong Kong):
To disable specific geo locations before explicit and implied rules you would have to use SAM rules and catch the specific Geo location data from Check Point's IP2Country.csv file. So you'll have to create a little Bash script to catch the location file, grep the IP adresses from Hong Kong and block Endpoint Security VPN connections for all others.
Hi Danny,
Thanks for your suggestion seems will be work, but using Bash script to catch the location file is too difficult to me to setup.
Anyway thanks for your reply.
Regards,
JJ
because of the implied rule will accepted the connection before the policy.
What about changing the order of the Implied Rules in Global Properties?
actually the global properties is in grey on the accept remote access control connections, and after disable the connection still accepted by the implied rule.
so that no help.
Hi All,
i had disable the implied rule as below
and setup the access policy as below, all problem is solved.
so many thanks with all you guy.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY