Hi all,
(R81.10)
We recently changed over from the legacy way of geo blocking to the recommended use of updatable objects as a rule in the access control policy.
The geo block rule is at the top off our ruleset but I think that the firewall still is allowing any IP to connect to the IKE ports (we use CP VPN) through the implied policy.
![ike.jpg ike.jpg](https://community.checkpoint.com/t5/image/serverpage/image-id/17058i65CAA6A3FA7DD636/image-size/large?v=v2&px=999)
I believe with the legacy geo policy it blocked any geo IP connecting to the firewall (this was proved with the recently issue with classifying UK IP's as Russian).
Is there a way to apply the geo rules to the applied policy?
Many thanks
Rich