[ATP/FLEX] How to block GeoIP to establish IPsec VPN connection with your firewall?
Options
![Zyxel_Jeff](https://us.v-cdn.net/6029482/uploads/defaultavatar/nN4PAQRO7TCNP.jpg)
Zyxel_Jeff
Posts: 1,139
Zyxel Employee
![](https://us.v-cdn.net/6029482/uploads/userpics/FN0BI9T10CTX/n6O940IZ5DEW6.png)
![First Anniversary](https://us.v-cdn.net/6029482/uploads/badges/SJKCAIG91R5S.png)
![10 Comments](https://us.v-cdn.net/6029482/uploads/badges/818CA6MI9BTU.png)
![Friend Collector](https://us.v-cdn.net/6029482/uploads/badges/HNJASEUSC535.png)
![First Answer](https://us.v-cdn.net/6029482/uploads/badges/OV6XOPPO8V59.png)
in VPN
Scenario :
If you want to block specific GeoIP addresses from establishing an IPsec VPN connection with your firewall to enhance the security of your network services, how can you configure this?
Answer :
Please navigate to Site-wide> Configure > Firewall > Security policy and add a security policy to deny UDP 500, and UDP 4500 from the specified GeoIP as shown below:
Share yours now!
0
Categories
- All Categories
- 413 Beta Program
- 2.3K Nebula
- 192 Nebula Ideas
- 87 Nebula Status and Incidents
- 5.3K Security
- 142 USG FLEX H Series
- 253 Security Ideas
- 1.3K Switch
- 75 Switch Ideas
- 993 Wireless
- 51 Wireless Ideas
- 6.1K Consumer Product
- 231 Service & License
- 362 News and Release
- 74 Security Advisories
- 23 Education Center
- 5 [Campaign] Zyxel Network Detective
- 2.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 101 About Community
- 67 Security Highlight