Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Ilovecheckpoint
Participant

Block all incoming connections

Hello,

In our organisation, we need external communication only from vpn site to site and remote access ipsec vpn.

We use implied rules, I'm thinking to block all incoming traffic, except from the management servers via Internet.

Normally, vpn site to site and remote access are allowed via default implied rules so it would be fine, isn't it?

0 Kudos
3 Replies
G_W_Albrecht
Legend Legend
Legend

No, vpn site to site and remote access are not allowed via default implied rules except in GAIA Embedded. You still need explicit rules for RA &V S&S VPN ! Same for Stealth and CleanUp rules...

 

 

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Ilovecheckpoint
Participant

Hello, thanks for the quickly answer.

I checked, and ike communication is allowed on implied rules, the remote access one not.

Anyway, my question is more like, after allowing site to site and remote access vpn, since I do not have any other incoming communication, is there any reason to do not block any incoming communication from Internet? 

0 Kudos
the_rock
Legend
Legend

Implied rules generally dont control inbound/outbound access. They delegate CP communication with other entities.

Andy

https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topi...

If you wish to block inbound connections, then you can do it via regular rules.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 20 May 2025 @ 11:30 AM (PDT)

    Las Vegas: Check Point Hybrid Mesh

    Wed 21 May 2025 @ 11:30 AM (MST)

    Tempe, AZ: Check Point Hybrid Mesh

    Tue 03 Jun 2025 @ 06:00 PM (EDT)

    Montreal: CPX Recap

    Tue 10 Jun 2025 @ 06:00 PM (EDT)

    Quebec City: CPX Recap
    CheckMates Events