L2TP GEO block

Posts: 46  Freshman Member
First Answer First Comment Sixth Anniversary
Is it somehow possible to GEO block on L2TP in Remote access VPN?

Welcome!

It looks like you're new here. If you want to get involved, click on this button!

Accepted Solution

  • Posts: 1,413  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments
    Answer ✓
    You need to create two security policy rules. In the following example, we allow Geo IP "Taiwan" only to establish L2TP VPN.
    In the first policy, action: Allow, source: allowed Geo-IP, destination: Device, dst. port: 1701, 4500, 500
    In the second policy, action: Deny, source: Any, destination: Device, dst. port: 1701, 4500, 500

All Replies

  • Posts: 1,413  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments
    You can add security policy rule as follows.

  • Posts: 46  Freshman Member
    First Answer First Comment Sixth Anniversary
    That doesn't work - not even with a NAT rule.....
  • Posts: 1,413  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments
    Answer ✓
    You need to create two security policy rules. In the following example, we allow Geo IP "Taiwan" only to establish L2TP VPN.
    In the first policy, action: Allow, source: allowed Geo-IP, destination: Device, dst. port: 1701, 4500, 500
    In the second policy, action: Deny, source: Any, destination: Device, dst. port: 1701, 4500, 500

  • Posts: 46  Freshman Member
    First Answer First Comment Sixth Anniversary
    Thanks Emily

    It's works great!

Welcome!

It looks like you're new here. If you want to get involved, click on this button!

Welcome!

It looks like you're new here. If you want to get involved, click on this button!