Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Country Blocking WAF

HI there,

in relation to these WAF country blocking threads:

community.sophos.com/.../enable-country-blocking-for-waf-rule
https://community.sophos.com/sophos-xg-firewall/f/discussions/126590/ip-country-block-does-not-work-with-waf

Is this true for now, that Country Blocking can only be done, using Blackhole NAT Rules? Is this just a workaround? Will this be changed again in future? As far as I could find out, this had been implemented with v 18... (with SD-WAN?)

Thanks.



This thread was automatically locked due to age.
Parents Reply
  • The only difference between the settings (country blocking active/country blocking active) is, that I enable or disable DNAT to make countryblock work. So without the activated NAT, the firewall rules are matching. So why shouldn´t they match with NAT activated?

Children