This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

GeoIP

Is anybody having success in using the GeoIP functionality? I am not and i find it quite frustrating.

What have i done:
1. created a country group within that group f.i. Romania:

2. created a Drop rule based on the country group:

3. Have been checking logs for a couple of weeks, today i saw that there wher entries in the log showing me that traffic was allowed originating from a Romanian IP:

And this is only one example, my log is filled with more similar ones.
Any thoughts on this? Is my thinking wrong, was my execution poor or are my expectations not right?

Grtz, Peter-Paul



This thread was automatically locked due to age.
Parents
  • FormerMember
    0 FormerMember

    Hi Peter-Paul Gras,

    Is traffic from Romanian IP allowed form the same firewall rule that you have configured to block traffic based on GeoIP? or is it allowed by different rule?

    Thanks,

  • This Drop rule is the first FW rule in my firewall.

    I would expect it to block traffic coming form these blocked countries based on the fact that is the first FW rule to be hit.
    BTW, no allow rules defined....

    Grtz

     
    SFVH (SFOS 19.5.1 MR-1-Build278)  - Last (re)boot on Februari 20 2023
    Asus H410i-plus - Pentium 6605 Gold - 250GB M.2 PCIe NVMe SSD - 8GB - 3 ports
    [If any of my posts are helpful to you please use the 'Verify Answer' link]
  • FormerMember
    0 FormerMember in reply to Peter-Paul Gras

    Hi Peter-Paul Gras,

    Could you please share full traffic logs that shows ports involved? What is the UserPortal port configured on the firewall? Do you have HTTPS access allowed over WAN Zone?

    Thanks,

Reply Children
No Data