Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Does country blocking work for 'from' only?

With my old firewall, my mail server in particular gets bombarded from china and russia in particular, so I'd like to switch to UTM9.  I wanted to allow LAN to go to blocked countries, but not allow unsolicited inbound traffic.  It seems like if I block, say, Russian Federation for 'from' only, 'iptables -L -n' shows the exact same output as 'off'.  If I set 'to' or 'all' those seem to be identical to each other as well.  Am I missing something?  Thanks!



This thread was automatically locked due to age.
Parents Reply Children
  • I'm just surprised that 'to' or 'all' DO generate iptables rules.  Well, I'm deploying this in a day or two, so I can test it out.  My email server gets scanned a *lot* from Russia in particular, so awhile back I had added geoip blocking to it, and can see the iptables hits increment in real time :)  So, the plan would be to set RU to 'from', and then watch the iptables stats on the mailserver.  If they keep going up, there's a bug in UTM, and I can open a support case.

  • I guess I can close this then.  Been running with 'from' on the various countries/regions, and iptables in the mailserver confirms no changes in hits.  Thanks for the info!

  • Argo, I don't think it's done in conntrack.  It does happen right after that and before everything else.  See #2 in Rulz.

    Cheers - Bob

  • Hi Bob,

    you may be right, although I thought i remember speaking to one of the techs at Sophos and they said it was, but this was along time ago when I was still new to the Sophos.