Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

GEO IP location blocking IP (false positive)

Hello All,

 

I am new to Sophos product. On my UTM, it is blocking IP which belongs to USA.Below are the logs:

 

2019:10:23-07:50:56

tci-utm ulogd[24705]: id="2021" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped (GEOIP)" action="drop"
fwrule="60019" initf="vpc2.0"
outitf="eth0" srcmac="12:ca:fa:e1:b3:54"
dstmac="5e:e5:ce:cf:ae:57" srcip="10.103.2.184"
dstip="104.98.167.67" proto="6" length="52" 
tos="0x02" prec="0x00" ttl="127"
srcport="55316" dstport="443"
tcpflags="SYN"

 

 

Kindly suggest 

 

Thank You



This thread was automatically locked due to age.
Parents Reply
  • Hello Morris,

    You can check in the console which country the IP Adrdress belongs

    https://community.sophos.com/kb/en-us/130858

    It looks like Sophos (old and not correct database) thinks the IP belongs to 

    console> show country-host ip2country ipaddress 104.98.167.67
    104.98.167.67 belongs to country Netherlands.

    I had the same problem and created a support ticket, took a few month because they have to create a new firmware 

    (thats what they told me)

    If the IP is important you should also create a ticket and for time being create an exclusion.

     

Children