Hi,
i started testing with county based blocking, but as soon as i enabled it it started blocking traffic from my own external range so i forsee some problems with this system.
currently i have the following case:
i have set several countries to block, but not the netherlands.
but ip/subnet 77.222.76.140 gets blocked but i cannot find as witch country it is detected, and even if i knew i would need to enable a whole county just for a wrong entry.
i think the following parts are missing:
- a lookup system that lets u lookup a ip -> country
- a exclusion option to allow a single ip or subnet again
- a system to correct wrong entries
- logging in packetfilter log that included the country name
Regards,
Bert