Do InControl2 inbound firewall / Geo-IP policies remain active after PrimeCare expires?

Hi everyone,

I would like to confirm what happens to existing InControl2-pushed firewall policies after PrimeCare expires.

Scenario:

We have Peplink devices that were previously managed by InControl2. Some inbound firewall policies were configured from InControl2, including country / Geo-IP based restrictions for inbound access.

I understand that when PrimeCare expires, the device may lose InControl2 management, SpeedFusion licensing, and warranty/support depending on the model/license.

However, I would like to confirm the behavior of the existing configuration:

  1. If inbound firewall policies were already pushed from InControl2 to the device before PrimeCare expired, will those existing policies remain stored on the local device?

  2. Will those existing inbound firewall rules continue to take effect after PrimeCare expires?

  3. For country / Geo-IP based blocking rules, do they continue to work after PrimeCare expires, or do they require an active PrimeCare subscription?

  4. After PrimeCare expires, can these existing inbound firewall policies still be viewed or modified from the local Web Admin interface?

  5. If the device drops out of InControl2 after PrimeCare expires, will the last pushed configuration remain active on the device?

We are trying to confirm this before deciding whether renewal is required for some remote devices.

Thanks in advance.

@Heisenberg.pian ,

Thank you for your questions.

In general, when the PrimeCare subscription expires, the last configuration that was successfully applied to the device remains on the device and continues to operate. Existing firewall rules and policies that have already been pushed from InControl 2 are not automatically removed simply because the PrimeCare subscription has expired.

For your specific questions:

  • Existing inbound firewall policies that were previously pushed from InControl 2 will generally remain stored on the device and continue to be enforced after PrimeCare expires.
  • The last configuration pushed from InControl 2 will remain active on the device even if it is no longer managed by InControl 2.
  • However, after the device is no longer managed by InControl 2, those InControl-managed policies can no longer be synchronized or updated from InControl 2.

Regarding Country / Geo-IP based firewall rules, while the existing rules are generally expected to continue functioning after PrimeCare expires, we cannot guarantee their long-term effectiveness. Geo-IP filtering relies on an IP geolocation database, which is periodically updated. Without an active Care Plan, the device may no longer receive future database or firmware updates, which could eventually result in outdated Geo-IP information and potentially cause false positives or false negatives when matching traffic.

For this reason, we recommend maintaining an active PrimeCare subscription so that the device continues to receive firmware, security, and database updates, ensuring the Geo-IP filtering remains accurate and up to date.

If you do not plan to renew the PrimeCare subscription and have concerns about the long-term behavior of Geo-IP filtering, we recommend disabling or removing the Geo-IP-based firewall rules before or shortly after the subscription expires. This helps avoid unexpected access issues that could arise from an outdated Geo-IP database over time.

If local configuration changes are supported on your device model, you may also review and manage the locally stored configuration through the Web Admin interface. However, InControl 2-managed features and policies will no longer be centrally managed once the device is no longer under an active PrimeCare subscription.

3 Likes

Thank you for the clear and detailed explanation.

This answers my questions about how the existing InControl 2 pushed policies behave after PrimeCare expires, and also clarifies the possible long-term impact on Geo-IP based firewall rules.

I appreciate your help.

Some changes are not possible to edit once pushed from IC2. Or, if you can change them, they revert within seconds to the IC2 managed settings. How will this behave after expiration? Can you edit settings without it going back? Or do you need to factory reset the unit to be able to push local settings?