This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Country Blocking of whitelisted Country

Hi,

I'm have a DNAT Rule to blackhole for country blocking. I'm blocking almost every country except some in the EU. In the past it worked very well, but last weekend I had problems with access. I was using the wifi of a holiday house with a german IP address. Using wifi I was not able to access my server behind my Sophos. Without Wifi it worked. I already checked the IP using different GeoIP provider and also the Sophos Console. I always get the answer: IP belongs to germany. IPs: 194.151.1.8 - 194.151.1.11

Does anyone has an idea what could be wrong?

In the log it even says src_country="DEU".

Thank you all!



This thread was automatically locked due to age.
Parents
  • Hello HerrTim,

    Thank you for contacting the Sophos Community!

    I am not understanding your problem correctly, so please clarify.

    You were trying to access your XG from an IP in Germany, however, you were not able to?

    Or you were expecting the IP from Germany to be blocked?

    Regards,

  • Hello Emmanuel,

    I'm using WAF to protect my Server behind my XG. As country blocking described in https://docs.sophos.com/nsg/sophos-firewall/18.0/Help/en-us/webhelp/onlinehelp/nsg/sfos/tasks/CreateFirewallSecurityRule.html is not working, I'm using a blackhole solution. Forward IP's from countries to a non existing client in my network. Only IP's from Germany and 3 other EU countries are allowed to access my server. That worked fine in the past. But last weekend I used a Wifi in Germany and I was not able to access my server. The XG applied the Blackhole rule although my IP was identified as DEU. Now I'm a bit confused and I want understand the problem and prevent a similar problem in the future.

    To your questions: Yes and no :)

    I hope it is now a little bit clearer.

    Regards,

    Tim

  • Hello Herr,

    Thank you for the follow-up!

    Oh ok I got confused with the Live Log. Not sure why it would have taken the DNAT rule for the black hole instead of the NAT rule for the WAF, my guess is that the Europe Continent still has Germany, I am not sure if you are able to test again but can you go to System >> Hosts and Services >> Country Group >> Europe Continent and remove Germany from here and try accessing again.

    Regards,

  • Hello Emmanuel,

    I think there is still a misunderstanding.

    1. DNAT Rule for Country Blocking, Germany is allowed (not included in Europe Continent). That DNAT rule is used as a blackhole

    2. WAF for my Server

    That works fine. This way only clients with a german Ip address can access my server. But as I already said, I now had the problem that a german IP address, which was also identified as src_country="DEU", was not able to access the server. I have no idea why that happened. If Germany would be part of the EU country list, nobody could access the server. But Germany is not part of the country list EU. 

    Regards

  • Hello Herr,

    Thank you for the follow-up!

    Thank you I thought it was hitting the DNAT rule, but if it hit the WAF rule, I don't see the rule blocked the packet but allow it. I think this might be rather a different module that blocked that request, is there any way you can replicate this? by the con_event="Stop" I think it might have been the IPS. 

    Regards,

Reply
  • Hello Herr,

    Thank you for the follow-up!

    Thank you I thought it was hitting the DNAT rule, but if it hit the WAF rule, I don't see the rule blocked the packet but allow it. I think this might be rather a different module that blocked that request, is there any way you can replicate this? by the con_event="Stop" I think it might have been the IPS. 

    Regards,

Children