This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to block access to IPsec for some IP address or country

Hello,

For some time I have seen "peer authentication failed" entries in IPsec logs. How can I block IP address that initiates these connections? - or maybe the whole country? The "block all incoming connections from xxx IP address" rule does not work in this case.

Second question: are you planning to introduce the so-called dynamic blacklist, to which would be automatically added IP addresses notoriously trying to set up an IPsec or SSL connection using incorrect credentials or keys? This would be highly desirable because of a recent passwords and keys leak.



This thread was automatically locked due to age.
Parents Reply Children
  • As I wrote prevoiusly, the "block all incoming connections from xxx IP address" rule does not work in case of IPSec connections. 

  • FormerMember
    0 FormerMember in reply to MichalKawecki

    Hi MichalKawecki,

    Then I don't think there is a way to entirely block non-legitimate connection attempts.

    However, you can configure the local ID and remote ID for a kind of extra layer of authentication for VPN connection - 

  • It's definitely an idea. However, the best solution seems to be adding the ability to pre-filter IPSec traffic in the router's administrative access management panel. I could then apply a rule that allows access to IPSec only from a single selected country.

    I will add that the security of the road-warrior IPSec connection is very questionable when we also use Sophos Connect. The reason lies in the easy access to the file with the Sophos Connect configuration, in which the shared key is saved in plain text - because this key is the same as for the mentioned IPSec...

    Thank you for your answers and ideas.

    Greetings.