This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Country Blocking Not Working for a WAN > LAN Rule

Hi.  It seems like country blocking is not working for WAN -> LAN (or any other protected network behind XG Firewall).

I have tested this with a proxy in the blocked countries.

I have this rule at the top of the list and network traffic still passes even though the rule shouldn't allow it, basically ignoring it.  The rule is never triggered thus always stating in 0 B, out 0 B.  I have tried every combination of Source/Destination/Zone/Network and still it doesn't work.



This thread was automatically locked due to age.
Parents
  • This continues to be an issue in 16.05.2 MR-2.  It's also a little disappointing that it doesn't appear in the known issues list.  Don't have a lot of confidence we're going to see this one fixed any time soon...

  • HI , 

    Could you provide me an instance where you could verify if the issue is with the Country blocking or not . 

    on Console I have tested few sites , (impossible for all) and could verify that the host address points to the country address . 

    Eg: 8.8.8.8 

     show country-host ip2country ipaddres 8.8.8.8

    Result > 8.8.8.8 belongs to country United States.

    Could you verify the results and when you add the country , make sure the session is disconnected or delete the connection . 

  • Hi Aditya,

    the country blocking does not work even after a restart from power off. I am talking about incoming and outgoing. If as I tested earlier you block all countries that works, but specific countries no that does not work. Yes, I have the rule at the top.

Reply
  • Hi Aditya,

    the country blocking does not work even after a restart from power off. I am talking about incoming and outgoing. If as I tested earlier you block all countries that works, but specific countries no that does not work. Yes, I have the rule at the top.

Children
No Data