Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Country Blocking WAF

HI there,

in relation to these WAF country blocking threads:

community.sophos.com/.../enable-country-blocking-for-waf-rule
https://community.sophos.com/sophos-xg-firewall/f/discussions/126590/ip-country-block-does-not-work-with-waf

Is this true for now, that Country Blocking can only be done, using Blackhole NAT Rules? Is this just a workaround? Will this be changed again in future? As far as I could find out, this had been implemented with v 18... (with SD-WAN?)

Thanks.



This thread was automatically locked due to age.
Parents Reply Children
  • NAT will redirect the traffic, if the NAT rule hits. 

    Firewall will allow the traffic.

    If NAT hits and firewall rule is not available, it will not forward the traffic (=deny). 

    Your firewall rule for the Blackhole NAT does not hit. Therefore you do not see the packet outgoing to the Blackhole Host. 

    OR: The blackhole Host is not reachable, therefore the ARP will not be resolved and the packet will not be send.