- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Re: Hi Experts ,Any one can guide
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Experts ,Any one can guide
May I know how to block IPS based for Countries to block outside access to Particular segment .
My scope is I need to block for VPN segment ,for example lets say my user are in UK ,I need to block access from china ,In IPS based ...how to apply this ..
3 Replies
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
You mean talking about the Geo Policy?
If you use Geo Policy, you can block connection from any specific Country.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
To create a new Geo Policy:
- In R80 SmartConsole, go to the Security Policies page.
- In the Shared Policies section, click Geo Policy.
- From the drop-down Edited Policy menu, select New.
- In the Object Name window that opens, enter a name for the new Geo Policy.
- Click OK.
- Select an Activation Mode:
- Active - Policy is enabled
- Monitory Only - Traffic that matches the policy is allowed and logged
- Inactive - Policy is disabled
- In Policy for specific countries section, click the plus sign.
The Geo Policy - Add new rule window opens.
- Configure the Rule Settings:
- Country - Select or search for a country on the list
- Action - Select Accept to allow the traffic or Drop to reject it
- Direction - From and To Country for bidirectional traffic, or To Country or From Country for traffic only in a specific direction
- Track - Select to Log, send Alerts, send Mail, send SNMP Traps, or to send one of possible three custom User Alerts (you can also choose to not do any tracking)
- Comment - optional comment
- Set the default Action and Track option for the Policy for other countries.
- Optional - Select Aggregate logs by country.
- Publish the Session to save the configuration changes.
Firewall Pre-R80 Security Gateways with R80 Security Management
