This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Countries restriction on Ipsec remote acess

Hi,

Do you know how can I protect my Ipsec remote acces (XGV18 and XG V17.5) by Countries Ip restrictions?

Thanks for you to enlighten me.



This thread was automatically locked due to age.
Parents
  • FormerMember
    0 FormerMember

    Hi ,

    Thank you for reaching out to the Community! 

    Create a black hole DNAT rule with required(blocked) source countries as "Original Source" and UDP 500/4500 in "Original Services." 

    Check out the following document for more information: 

    The same concept applies to firmware v17.5; for the local services, you'd need to create a black hole DNAT rule and forward the traffic from specific countries to a dummy internal host(a host that does not exist).

    Thanks,

  • Thanks Harsh. It's working fine.

    Is there any way to block all contries except ones i select?

    Thanks,

Reply Children