- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
Watch HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hello friends
I have a doubt in the execution of an activity.
I have an SSL VPN and client on my firewall gateway R80.10 Manager R80.30
I want to block Geo Policy and the countries that I release I want some to use the VPN tunnel as a Gateway for all traffic
and other countries use their internet provider to access the internet.
Is it possible to do this someone has this experience and can share how to do it?
I can tell you from my own experience, best way to do this is create rule(s) to allow traffic from certain country (countries) and then create a rule below that to block traffic from that country.
So, say for example you wish to let people in subnet 10.40.30.0/24 access anything in Russia. You would create a rule with that subnet in source, then updatable object country as Russia, put service(s) and allow, but then right below that rule, you would create another rule that says source any to Russia, block.
Does that make sense?
In order to have granular Geo Protection rules, the gateways need to be on R80.20 or above.
Which is highly recommended anyway since R80.10 is soon to be End of Support.
You can configure it so the client can choose whether to route all traffic through the gateway or not.
However, you can't force some users to route all traffic and allow others to split tunnel.
Hey Good afternoon
I understand I understand that on R80.10 I can't force via manager some SSL VPN traffic and client via split tunnel and others using your local provider for external access?
But I can do this on R80.20 or higher.
And it is recommended that the user determine this locally in their Endpoint Security Checkpoin?
The options available are basically: yes, no, and “client decide” where the client can choose whether to route all traffic through the VPN or not.
These options can only be configured globally, not based on location or user group.
Newer versions than R80.10 are the same in this regard.
Hey Good afternoon
Yes it makes sense, I would create a Policy Access Control denying the origin of Russia and China and allowing Japan and USA.
But how do I release Japan using VPN SSL as default for external access such as google and USA use your local internet provider for external access, eg google
Well, as I said, if you need to allow certain countries/services, you just make a rule to reflect that. Message me offline, we can do remote session and Im happy to show you.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Thu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealThu 09 Jul 2026 @ 11:00 AM (CEST)
The Cloud Architects Series: Check Point Edge Protection SD-WAN & SASETue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY