L2TP GEO block

Options
DanniKool
DanniKool Posts: 23  Freshman Member
First Anniversary 10 Comments
Is it somehow possible to GEO block on L2TP in Remote access VPN?

Accepted Solution

  • Zyxel_Emily
    Zyxel_Emily Posts: 1,296  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Answer ✓
    Options
    You need to create two security policy rules. In the following example, we allow Geo IP "Taiwan" only to establish L2TP VPN.
    In the first policy, action: Allow, source: allowed Geo-IP, destination: Device, dst. port: 1701, 4500, 500
    In the second policy, action: Deny, source: Any, destination: Device, dst. port: 1701, 4500, 500

All Replies

  • Zyxel_Emily
    Zyxel_Emily Posts: 1,296  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    You can add security policy rule as follows.

  • DanniKool
    DanniKool Posts: 23  Freshman Member
    First Anniversary 10 Comments
    Options
    That doesn't work - not even with a NAT rule.....
  • Zyxel_Emily
    Zyxel_Emily Posts: 1,296  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Answer ✓
    Options
    You need to create two security policy rules. In the following example, we allow Geo IP "Taiwan" only to establish L2TP VPN.
    In the first policy, action: Allow, source: allowed Geo-IP, destination: Device, dst. port: 1701, 4500, 500
    In the second policy, action: Deny, source: Any, destination: Device, dst. port: 1701, 4500, 500

  • DanniKool
    DanniKool Posts: 23  Freshman Member
    First Anniversary 10 Comments
    Options
    Thanks Emily

    It's works great!

Nebula Tips & Tricks