Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

ip / country block does not work with waf

SFVH (SFOS 18.0.4 MR-4) 

hello

the block rule only works with dnat

I have created the "block country" rule and blocked my cell phone for testing purposes

the dnat rule is blocked correctly

but all waf rules are not blocked

do firewall rules not apply to waf?
how to set ip / country block for waf?



This thread was automatically locked due to age.
Parents
  • Hello,

    Drop/Reject Firewall Rules doesn't work with WAF since v18 EAP 1, I've reported it back then but they never fixed It; In v17.5 It used to work as expected.

    If you want to open a support case for It, you can use the NC-51857 as reference.

    (Read post below.)

    Now you should create a DNAT Blackhole in order to do country filtering for WAF.

    Thanks!

Reply
  • Hello,

    Drop/Reject Firewall Rules doesn't work with WAF since v18 EAP 1, I've reported it back then but they never fixed It; In v17.5 It used to work as expected.

    If you want to open a support case for It, you can use the NC-51857 as reference.

    (Read post below.)

    Now you should create a DNAT Blackhole in order to do country filtering for WAF.

    Thanks!

Children