Skip to main content
mwkirk
New Member
February 6, 2019
Question

Local-in policy to block VPN requests

  • February 6, 2019
  • 2 replies
  • 4624 views

So there is a certain IP that is filling up the logs trying to establish a site-to-site VPN.  I trying out how to figure out how to block it I came across Local-In Policies.  I set the below rule but still the logs are getting filled with these request:

 

config firewall local-in-policy     edit 1         set intf "wan1"         set srcaddr "BadGuy"         set dstaddr "WAN1-IP"         set service "any"         set schedule "always"     next end

 

Is there anything else I need to do or should this work?  Doesn't look like it is though. 

    2 replies

    Dave_Hall
    New Member
    February 6, 2019

    Assuming you really do not want the baddy addy to connect to your fgt or anything behind it you likely want to set the dest address to all or any. 

    mwkirk
    mwkirkAuthor
    New Member
    February 20, 2019

    Yeah I did that and still the logs fill up with this address trying to establish an IPSEC tunnel. So changed policy to:

     

    config firewall local-in-policy

    edit 1 set intf "any" set srcaddr "Bad-Guy" set dstaddr "any" set service "any" set schedule "always" next end

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!