Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
lluner
Advisor

Geoip Protection outubound Enforcement

hi

Could someone explain why this is happening

geoip2.png

0 Kudos
10 Replies
the_rock
Legend
Legend

Appears its related to default geo policy. You definitely should be using updatable objects for geo policy starting R80.20 version. I would examine current policy and see how Brazil is configured.

Andy

0 Kudos
lluner
Advisor

@the_rock 

When I do the application with the updated objects it gives the same error shown above, I believe it is something in the base of the checkpoint that inserted this ips incorrectly

0 Kudos
the_rock
Legend
Legend

So if you try using geo updata ble objects and I assume you disabled legacy geo policy, you get same error?

Andy

0 Kudos
lluner
Advisor

hi @the_rock 

I didn't disable the default policy of GEO, I created a rule on the layer network with the update objets. Even so, the error happened, the access to the Brazilian continent was blocked

0 Kudos
the_rock
Legend
Legend

Right, but whole point of using updatable objects for countries is to disable legacy geo policy.

Andy

0 Kudos
lluner
Advisor

Hi @the_rock 

Even applying the rule does not work with the update objects. I believe that the problem is at the base?

0 Kudos
the_rock
Legend
Legend

K, just to make sure we are on the same page here..are you trying to block/allow given country or specific IP from that country or what exactly?

Andy

0 Kudos
Timothy_Hall
Legend Legend
Legend

The legacy Geo Policy is enforced well before Geo Updatable Objects, at roughly the same time as antispoofing enforcement.  So if traffic is dropped by the legacy Geo Policy it will be dropped regardless of how your main policy layers are configured with Geo Updatable Objects.  To disable the legacy Geo Policy:

1) Under Shared Policies...Geo Policy...select Policy

2) Make sure "Default Geo Policy" is selected in the dropdown at the top of the screen

3) Select Inactive or "Monitor Only", your choice

4) Using Geo Updatable objects, ban any countries you want using Geo Updatable Objects in the first layer of your policy package

5) Publish and install policy.

 

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
(1)
the_rock
Legend
Legend

I guess I thought I mentioned to disable it previously, but my bad, I did not. @lluner , thats what you have to do first.

Andy

0 Kudos
Lesley
Mentor Mentor
Mentor

I assume you wonder why it is blocked? Maybe this SK helps https://support.checkpoint.com/results/sk/sk126172

Or something else is wrong? 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events