Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
ICSI
Collaborator
Jump to solution

Ukraine IP address filling 75% of my VPN Logs

When checking the logs of my Harmony Connect VPN service I can see that there is a couple of IPs address coming from Ukraine that are generating 75% of my logs.

Are you experiencing the same?

Last week I reported the same incident but from two different IPs as well from Ukraine and looks to me that the TAC people helped me out to block them. last IP: 109.207.200.44 

If you check your Harmony Connect VPN logs, can you see them too?  

I understand the part of: they do not have the keys, or certificate and etc to break in, yeah, but those IPS are saturating Check Point logs and probably even degrading the service. 

Does anyone know how to block them with involving TAC? I already added a policy that blocks any access from those IPs and nothing actually happened because I think it only applies to the valid traffic inside the VPN. 

An email was sent today to the organization in Ukraine that are in charge of those IPs. nothing might happen! 

Thoughts? 

 

Regards,

Oscar Catana
https://ipthub.com

Cyber Sec Passionate!
0 Kudos
2 Solutions

Accepted Solutions
PhoneBoy
Admin
Admin

This (before encryption) traffic is accepted through implied rules.
Short of changing the implied rules, the best way to block this traffic is using fwaccel dos rules: https://community.checkpoint.com/t5/Security-Gateways/Block-VPN-Traffic-by-Country/m-p/172695#M31396

View solution in original post

Andy_P
Employee
Employee

I believe this is a result of bots/vulnarebility_scaneers  activities.

Based on topic you're using Harmony Connect Network Access client. Please raise ticket with TAC to block  traffic  from countries you don't want get traffic.

 

View solution in original post

4 Replies
_Val_
Admin
Admin

I would suggest using GEO policy to block the country, if you do not expect any connections coming from there.

0 Kudos
Lesley
Leader Leader
Leader

Same, GEO protection and block the unwanted countries. 

Here is the SK:

https://support.checkpoint.com/results/sk/sk126172

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
PhoneBoy
Admin
Admin

This (before encryption) traffic is accepted through implied rules.
Short of changing the implied rules, the best way to block this traffic is using fwaccel dos rules: https://community.checkpoint.com/t5/Security-Gateways/Block-VPN-Traffic-by-Country/m-p/172695#M31396

Andy_P
Employee
Employee

I believe this is a result of bots/vulnarebility_scaneers  activities.

Based on topic you're using Harmony Connect Network Access client. Please raise ticket with TAC to block  traffic  from countries you don't want get traffic.

 

Upcoming Events

    CheckMates Events