Modify the Engine template policy to restrict remote VPN client sessions based on location, time, and day.
Following points are to be noted:
- You can specify when access rules are enforced.
- You specify rule validity times using Rule Validity Time elements.
- You can use the same Rule Validity Time element in multiple rules and policies.
- You can also create several Rule Validity Time elements and use the elements in one rule.
- You can use Source match to block access based on IP address.
Steps
-
Select
Engine
Configuration.
-
Browse to Other Elements.
-
Right-click Rule Validity Time, then select New Rule Validity Time.
-
Configure the settings. Specify using the Active option when VPN client sessions are denied. Select either Between These Times of the
Day, or On These Days of the Week.
-
Click OK.
-
Open the Engine cPP Template for editing.
-
Before the
Automatic Rules Insert Point, add the following rule:
Source: Networks or hosts are denied locations
Destination: $$ Local Cluster
Service: ISAKMP (UDP), NAT-T (Destination)
Action: Discard
Time: The Rule Validity Time elements
-
Save the template policy.
-
Refresh the policies of all firewalls involved in the VPN to activate the new configuration.