> Source: [sk180527](https://support.checkpoint.com/results/sk/sk180527)

# sk180527 - Cannot enforce GEO protections on VSX Gateway

| Property | Value |
|----------|-------|
| Solution ID | sk180527 |
| Date Created | 2023-01-18 |
| Last Modified | 2023-01-19 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * When you enforce GEO protections on VSX Gateway, the *geo.d* process is not up after installing the policy.

* You cannot find the *$FWDIR/tmp/geo_location_tmp/updates/IpToCountry.csv* file on the VSX Gateway, and if you set it manually, it enforces the geo protection, but it does not update itself because geo.d process is not up.

* The file *$FWDIR/tmp/geo_location_tmp/updates* is empty.

* Running `cpstop;cpstart`, or reboot does not solve this issue.

## Cause

Per [sk106496 - Software Blades updates on VSX - FAQ](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106496):

In R80.10 and higher versions, IPS blade does not have to be enabled (Geo policy is installed as a part of the Access Policy). For R80.10 and higher VSX gateways, the activation mode of Geo policy assigned to VSX gateway (Context of VS0) has to be in "Monitor Only" or in "Active." This is required for the IPS Geo Protection updates to work on Virtual Systems (VS).

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
