Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

GeoIP

Is anybody having success in using the GeoIP functionality? I am not and i find it quite frustrating.

What have i done:
1. created a country group within that group f.i. Romania:

2. created a Drop rule based on the country group:

3. Have been checking logs for a couple of weeks, today i saw that there wher entries in the log showing me that traffic was allowed originating from a Romanian IP:

And this is only one example, my log is filled with more similar ones.
Any thoughts on this? Is my thinking wrong, was my execution poor or are my expectations not right?

Grtz, Peter-Paul



This thread was automatically locked due to age.
Parents Reply
  • Just for the notes, I tested v18 GA and v17.5.9 on console and it shows the same lookup as Romania.

    What I do see is the GeoLite2 MaxMind database, if the XG is still using it somewhere, doesn't list the 185.100.87.x subnet.

    Wonder if IP address lookup and Country group matching are using different data stores?

Children
No Data