Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Mark_Edwards
Contributor

Location Awareness for desktop firewall issue

Hi CheckMates

I am trying to configure Location-Based policies for RAS users.

As per the Remote-Access VPN R81.10 Admin guide (page 86/87) I have configured Location Awareness for desktop firewall and the Location Based policy.

Location Awareness is set to "true" and Location Based policy is set to "encrypt_to_allow". 

Network Location Awareness in Global Properties has been set to "Yes" and the internal network set in "The clients connects from this network or group". The firewall's interface topology has also been configured correctly. 

The issue is that it seems the disconnected policy is been applied when I am on the internal network as I can only only connect to same allowed destinations in the desktop policy as when I connect from external. 

When I connect externally everything works as configured in that I can only connect to what is allowed in the desktop firewall.

When I VPN in from external everything works as configured (access control VPN ules are applied).

I'm not sure if Location-Awareness or if the Desktop policy is mis-configured although I'm beginning to suspect that it is the Desktop policy.

I have attached the simple Desktop policy I'm using for testing. 

The last rule is source:all users destination: Any and Action: Encrypt.

My understanding is that connected policy will be enforced.

 As per the guide. 

encrypt_to_allow - Connected policy will be enforced, based on last connected user. Encrypt
rules will be transformed to Allow rules (default).

 

Thanks. 

0 Kudos
0 Replies

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 08:00 AM (CDT)

    South US: HTTPS Inspection Best Practices

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Tue 23 Apr 2024 @ 08:00 AM (CDT)

    South US: HTTPS Inspection Best Practices

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events