- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hello,
We're new in the CheckPoint world and had a question about limiting access.
We use a client based VPN that uses a TCP High Port to allow external connections to come in. We have cert based deployment to allow/deny connections, but we are looking to take that one step further and block all connections from outside of the USA to the external address and port that our client-based VPN uses.
Is there a way to do this in checkpoint - we're running a HA Pair of 6400 currently in our environment.
You can use an updatable object to select United States as source of your rule then block the rest.
Something like Source: United States - Destination: your VPN public IP - Service: VPN Service - Action: Accept - Log
followed by Source: Any - Destination: Your VPN public IP - Service: Any - Action: Drop - Log
Desktop Security Policy does not support updatable objects.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY