Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Ilovecheckpoint
Explorer

Block all incoming connections

Hello,

In our organisation, we need external communication only from vpn site to site and remote access ipsec vpn.

We use implied rules, I'm thinking to block all incoming traffic, except from the management servers via Internet.

Normally, vpn site to site and remote access are allowed via default implied rules so it would be fine, isn't it?

0 Kudos
3 Replies
G_W_Albrecht
Legend
Legend

No, vpn site to site and remote access are not allowed via default implied rules except in GAIA Embedded. You still need explicit rules for RA &V S&S VPN ! Same for Stealth and CleanUp rules...

 

 

CCSE CCTE CCSM SMB Specialist
0 Kudos
Ilovecheckpoint
Explorer

Hello, thanks for the quickly answer.

I checked, and ike communication is allowed on implied rules, the remote access one not.

Anyway, my question is more like, after allowing site to site and remote access vpn, since I do not have any other incoming communication, is there any reason to do not block any incoming communication from Internet? 

0 Kudos
the_rock
Legend
Legend

Implied rules generally dont control inbound/outbound access. They delegate CP communication with other entities.

Andy

https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topi...

If you wish to block inbound connections, then you can do it via regular rules.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events