Configure a service access object
This task enables you to configure a service access object, which defines the conditions that traffic must meet to access a service, such as remote access VPN on the Firewall Threat Defense device.
Service access objects allow you to manage access based on geolocations and ensure that only traffic from approved regions can access specified services.
A service access object defines conditions as multiple rules to be executed in order. Each service access rule has an Allow or Deny action and a set of match criteria such as country, continent, or user-defined geolocation objects.
These rules are used to manage access to services, such as remote access VPN, and enforce security policies based on the source location of the traffic. If the traffic does not match any rules, the default action is enforced.
Use this task when you need to enforce or restrict access based on geographic or custom geolocation objects.
Before you begin
-
Configure geolocation objects. For more information, see Geolocation objects.
-
Configure a remote access VPN policy. For more information, see Create a New Remote Access VPN Policy.
Procedure
Step 1 | Choose . | ||
Step 2 | Click Add Service Access Object to create a new object. | ||
Step 3 | In the Add Service Access Object dialog box, configure the following parameters: | ||
Step 4 | From the Default Action drop-down list, choose Allow All Countries or Deny All Countries. | ||
Step 5 | (Optional) Check the Allow Overrides check box and click + to configure overrides for the service access object for devices.
| ||
Step 6 | (Optional) In the Add Service Access Override dialog box, configure these parameters: | ||
Step 7 | Click Save. |
What to do next
Configure the Service Access object in the remote access VPN policy. For more information, see Configure Access Interfaces for Remote Access VPN.