Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPsec connection attempt

Hi to all,

I have a lot of connections attempts for the IPsec service:

Always from the same two or three IPs.

Is there any way to block all for IPsec except the remote IP of the tunnel?

Thanks in advance.

Best regards.



This thread was automatically locked due to age.
Parents Reply
  • Hello there,

    To avoid seeing this, you could create a DNAT rule to send this ip to a black hole (A fake Internal IP).

    In the Firewall rule change the Source for the IPs you want to drop and select IKE services, as shown in the image above.

    Then, for the NAT Rule, do the same for the Original Source; under DNAT, add a Fake IP.

    After this, connections from these IPs shouldn't appear in the Log Viewer or in the charon.log.

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
Children