Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

GEO IP location blocking IP (false positive)

Hello All,

 

I am new to Sophos product. On my UTM, it is blocking IP which belongs to USA.Below are the logs:

 

2019:10:23-07:50:56

tci-utm ulogd[24705]: id="2021" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped (GEOIP)" action="drop"
fwrule="60019" initf="vpc2.0"
outitf="eth0" srcmac="12:ca:fa:e1:b3:54"
dstmac="5e:e5:ce:cf:ae:57" srcip="10.103.2.184"
dstip="104.98.167.67" proto="6" length="52" 
tos="0x02" prec="0x00" ttl="127"
srcport="55316" dstport="443"
tcpflags="SYN"

 

 

Kindly suggest 

 

Thank You



This thread was automatically locked due to age.
Parents Reply Children
  • Hi Morris and welcome to the UTM Community!

    The availability of a geoip update can be checked as often as every 15 minutes.  Check 'Pattern Download/Installation Interval' on the 'Configuration' tab in 'Management > Up2Date'.

    I can't remember at the moment which geoip location service is used, but it is not maxmind.

    If Country Blocking were disabled, there would be no GEOIP blocks in the Firewall log.

    Good job finding that KB article  - that's the best "Band-Aid" you can use.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Sorry I have a XG firewall and there is no Management>Up2Date

    With my Sophos service request they told me to check ip2location website

    https://www.ip2location.com/104.98.167.67

     

    This was there solution for XG box

    This is regarding the service request number  7000724.
    As discussed, we would need to install new Geodb binary into the XG box to resolve the reported issue

     

     do you have the Sophos UTM or XG?

    I know this is the Sophos UTM group but just to be sure.

  • Hoi SGH,

    I don't think IP2Location is used by the UTM.  Good to know that it's used by XG.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA