Coder68 - What's your recent experience with Country Blocking Exceptions? We were having heck with malicious botnets scanning our network for RDP connections. We eventually had to purchase RDP guard software (Windows protection is useless) for those few machines we had to have listening all the time, and turn the rest of the listening machine's NAT translations off, and only turn them back on when needed.
So, I thought we'd just block all the countries in the list, and create specific country blocking exceptions to accept SMTP incoming traffic, which is the only thing we'd be interested in accepting from most foreign countries. However, later one of our suppliers whose email routes through Israel complained that their emails were getting rejected, and sure enough they were right. I had to turn off the country block for Israel to restore functionality for them, even though they were in the country blocking exception rules. I can open a support case, but I know it's going to be difficult for Sophos Techs to test this, and I don't want to make my supplier a guinea pig.
Thanks,
Steve P