This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

1st Firewall rule has GEO blocks. But I am seeing this rule cause ALLOWS in the log. What is going on?

Hello,

I guess I am confused about the new V18 firewall rules and NAT etc.

I really expect my Firewall rules to be the 1st line of defense against the Internet bad guys.  So I put as my 1st rule country blocks to keep my network safe.

Much of the traffic is blocked.  But in the LOG I am seeing this rule ALLOW some traffic.

I also see there is a Web rule ID.

Can someone explain why this traffic is getting through when the firewall rule says to block it.

Thank You,

Peter Geremia



This thread was automatically locked due to age.
Parents Reply Children
  • I did dig into it and I do not see the traffic on my web server.   So I am sure you are correct.

    It would be nice to be able to allow a firewall RULE not have any other dependencies.

    So if I do a country block I do not want it to go any further.  

    Maybe they should look into supporting this kind of feature?

    Thanks again for your help!

    -Pete

  • Hi Peter,

    the recommended approach is to blackhole the offending countries. This where you create a firewall rule with linked NAT pointing at a non existent IP address on your LAN.

    There is a KBA on how to do this.

    Ian