This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Country Blocking Not Working for a WAN > LAN Rule

Hi.  It seems like country blocking is not working for WAN -> LAN (or any other protected network behind XG Firewall).

I have tested this with a proxy in the blocked countries.

I have this rule at the top of the list and network traffic still passes even though the rule shouldn't allow it, basically ignoring it.  The rule is never triggered thus always stating in 0 B, out 0 B.  I have tried every combination of Source/Destination/Zone/Network and still it doesn't work.



This thread was automatically locked due to age.
  • Just to add a vote to this - I am getting hammered on ports 23 / 2323 / 1900 from a bunch of countries that we have no dealings with and I would like to block all of them and using a simple WAN to LAN rule with the countries seems easy - but like others say it doesnt work.

    I am also on v17 MR3

    Really need this as it gives us a much larger attack surface.

    Have any of you managed a work around?

  • This fix was released in MR3, and I just double-checked my firewall, to confirm it's working. Check your zones in the block rule, as there's probably a mistake there. Test with zones set to ANY/ANY. You're defining the network source in the rule by specifying the country, so defining the zones also, is a bit redundant anyway. 

  • AlanT said:

    This fix was released in MR3, and I just double-checked my firewall, to confirm it's working. Check your zones in the block rule, as there's probably a mistake there. Test with zones set to ANY/ANY. You're defining the network source in the rule by specifying the country, so defining the zones also, is a bit redundant anyway. 

     

    It seems for me the trick is it has to be set to Any/Any for the zones, once doing that it started working.  Thanks Alan!

     

    You may want to update this KB article here https://community.sophos.com/kb/en-us/123007, the settings show selecting WAN and LAN zones. 

  • Hi folks,

    just added the country blocking into the firewall rules for the IPv4 rule set. Tried to add the same rules to the IPv6 rule set and there is no country selection available, minor bug?

    Ian

     

    And just to add my further 10c again, does not work. Try this site https://saharokstore.ru/

    Now while I understand some of these sites might not actually have an RU IP assigned address, they are still part of the blocked group.

     

    So as well as adding firewall rules we also must add country blocking exceptions in WEB access to block web sites with ru etc suffixes?

  • Any update on this issue?

    We're running 16.05.8 MR-8 and have no desire to move to v17 yet due to issues with IPSec and many other bugs that the community have reported.

    Could someone also explain the sending-traffic-to-black-hole method in more detail so I can replicate this instead for now?

    Thanks

  • Same with SFOS 18.0.0 GA-Build354.

    Should it be solved?

  • We are having the same issue at the moment. Support is involved but so far it seems to go nowhere.

    When we have a WAF-Rule present the drop rule at the top does not work at all.

     

    It is a mystery to me why the "Access Permission" or "Blocked sources" tabs do not let you use country blocking there. We want to be able to restrict access to the hosted site to only clients from the DACH region (germany, austria, switzerland).

  • Hi folks,

    please build one of these firewall rules at the top of your rule list, I have and the amount of junk it blocks surprising.

    https://community.sophos.com/kb/en-us/134380

    I di d it slightly differently as per the screenshot below.

    I forgot the NAT rule that is showing most hits, there are three of them created by the business rule.

     

    Ian