Prior to the ability to do Country Blocking, one of my clients had a blackhole DNAT with dozens of entries in the "Spammers" Network Group. The most-efficient is Network definitions that use CIDR notation. Small groups of those are usually best. Although Range definitions are possible, they are not efficient and are limited to subnets smaller than a /16.
What problem are you trying to solve?
Cheers - Bob
Sophos UTM Community Moderator Sophos Certified Architect - UTM Sophos Certified Engineer - XG Gold Solution Partner since 2005
Prior to the ability to do Country Blocking, one of my clients had a blackhole DNAT with dozens of entries in the "Spammers" Network Group. The most-efficient is Network definitions that use CIDR notation. Small groups of those are usually best. Although Range definitions are possible, they are not efficient and are limited to subnets smaller than a /16.
What problem are you trying to solve?
Cheers - Bob
Sophos UTM Community Moderator Sophos Certified Architect - UTM Sophos Certified Engineer - XG Gold Solution Partner since 2005