This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Block GeoIP rule - DNAT Blackhole - WAF no longer working

I found an earlier thread that GeoIP blocking was not working as the system take precedence over firewall rules and therfore are never hit. The Sophos advice was to create a DNAT Blackhole rule to a non existing IP adress.  

So I tried creating a DNAT rules with source zones network any and exclusions the countries allowed.

It creates a DNAT rule under firewall rules and a NAT plus reflexive NAT rules under NAT rules. 

However when I do this the allowed WAF calls also end up in the blackhole as the exclusion is not picked up by the NAT rule. The wizard does not create a linked NAT rule. 

IS there a way to get this working?

TIA,

Fred



This thread was automatically locked due to age.
Parents Reply Children
No Data