Guidelines and limitations for managing remote access VPN users based on geolocation
Guidelines
-
In a service access object, if you use a geolocation object (country, continent, or geolocation object), use it only in one rule.
-
Configure the service access rules in the correct order because you cannot reorder these rules.
Limitations
-
Clustering is not supported.
-
Geolocation-based unclassified IP addresses are not categorized by geographic origin; the default service access policy action is enforced for such IP addresses.
-
Connections from IETF RFC1918 addresses are allowed for geolocation-based remote access VPN regardless of service-access policy settings.