Guidelines and limitations for managing remote access VPN users based on geolocation

Guidelines

  • In a service access object, if you use a geolocation object (country, continent, or geolocation object), use it only in one rule.

  • Configure the service access rules in the correct order because you cannot reorder these rules.

Limitations

  • Clustering is not supported.

  • Geolocation-based unclassified IP addresses are not categorized by geographic origin; the default service access policy action is enforced for such IP addresses.

  • Connections from IETF RFC1918 addresses are allowed for geolocation-based remote access VPN regardless of service-access policy settings.