- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
When checking the logs of my Harmony Connect VPN service I can see that there is a couple of IPs address coming from Ukraine that are generating 75% of my logs.
Are you experiencing the same?
Last week I reported the same incident but from two different IPs as well from Ukraine and looks to me that the TAC people helped me out to block them. last IP: 109.207.200.44
If you check your Harmony Connect VPN logs, can you see them too?
I understand the part of: they do not have the keys, or certificate and etc to break in, yeah, but those IPS are saturating Check Point logs and probably even degrading the service.
Does anyone know how to block them with involving TAC? I already added a policy that blocks any access from those IPs and nothing actually happened because I think it only applies to the valid traffic inside the VPN.
An email was sent today to the organization in Ukraine that are in charge of those IPs. nothing might happen!
Thoughts?
This (before encryption) traffic is accepted through implied rules.
Short of changing the implied rules, the best way to block this traffic is using fwaccel dos rules: https://community.checkpoint.com/t5/Security-Gateways/Block-VPN-Traffic-by-Country/m-p/172695#M31396
I believe this is a result of bots/vulnarebility_scaneers activities.
Based on topic you're using Harmony Connect Network Access client. Please raise ticket with TAC to block traffic from countries you don't want get traffic.
I would suggest using GEO policy to block the country, if you do not expect any connections coming from there.
Same, GEO protection and block the unwanted countries.
Here is the SK:
https://support.checkpoint.com/results/sk/sk126172
This (before encryption) traffic is accepted through implied rules.
Short of changing the implied rules, the best way to block this traffic is using fwaccel dos rules: https://community.checkpoint.com/t5/Security-Gateways/Block-VPN-Traffic-by-Country/m-p/172695#M31396
I believe this is a result of bots/vulnarebility_scaneers activities.
Based on topic you're using Harmony Connect Network Access client. Please raise ticket with TAC to block traffic from countries you don't want get traffic.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY