[ATP/FLEX] Why the firewall rule set to WAN to Any,but cannot block Geo IP to establish VPN?

Zyxel_Jeff
Zyxel_Jeff Posts: 1,206  Zyxel Employee
100 Answers 500 Comments Friend Collector Third Anniversary

Question :

Why is the firewall rule set to WAN to Any, but it cannot block Geo IP from establishing a VPN, as shown below?

Answer :

Because the direction 'Any' doesn't include 'Device', the VPN traffic (UDP 500 and 4500) will still be passed to the firewall normally and won't be dropped by the security. To avoid this, please modify 'Any' to 'Device' and it will drop VPN traffic toward the firewall, as shown below:


Don't miss this great chance to upgrade your Nebula org. for free! https://bit.ly/4g2pS9L