Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Ryan_St__Germai
Advisor

Geo Protection based on X-Forwarded headers

Is there a way to have IPS Geo Protection block based on the IP address in the X-Forwarded header? It appears R77.30 CloudGuard edition is capable of this but I cannot find out whether this option is available on regular gateways.

Thanks!

Ryan

4 Replies
PhoneBoy
Admin
Admin

As far as I know, this isn't supported for CloudGuard gateways either.

It's possible this will be supported in R80.20 since you will be able to use countries in the regular rulebase--will have to check.

0 Kudos
Ryan_St__Germai
Advisor

Checkout this SK: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk115532&t=1535401279208

Describes what I am talking about but for the cloudguard image.

Ryan

Ryan St. Germain

- From Mobile

0 Kudos
PhoneBoy
Admin
Admin

Ah, so it is supported there Smiley Happy

As far as I know, this is specific to the CloudGuard images in AWS and Azure, but will confirm.

0 Kudos
Ryan_St__Germai
Advisor

Thanks for checking it out. We have several websites fronted by cloudflare so we never see the original source address. CloudFlare has geo protection like feature but is is based on blacklisting not white AND it only challenges users not outright blocks them.

Ryan

Ryan St. Germain

- From Mobile

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events