Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Country blocking exception not working

I'm running Firmware version: 9.303-2. I have Country Blocking turned on to some  countries, one of which is Netherlands.

When I try to go to: Yellow Bricks

I get this error:
Content blocked
While trying to retrieve the URL: Yellow Bricks
The content is blocked due to the following condition:
The URL you have requested matches a forbidden Country. If you think this is wrong, please contact your administrator.
Country: Netherlands

I went to "Country Blocking Exceptions" and created a an exception called "Whitelist"

It says its set to:

skip blocking of these countries:
    [Netherlands] Netherlands
for traffic going to these destination networks:
    Whitelist 1
    Whitelist 2
    Whitelist 3
Using these services:
    Any

For the three networks, I've tried three things:

Name: Whitelist 1
Type: DNS Host
Hostname: Yellow Bricks


Name: Whitelist 2
Type: DNS Host
Hostname: yellow-bricks.com


Name: Whitelist 3
Type: Network
IPV4 address: 109.237.219.143 /32


None of them work. 

If I tell the country blocking list to allow Netherlands, it lets me access the site.


Any ideas?

Thanks!

Arch


This thread was automatically locked due to age.
Parents
  • I am wondering if this workaround would work. I will try this later tonight or tomorrow, depending on my schedule. 

    There is a "do not proxy section" in the UTM.

    Web Protection\Filtering Options\Misc\transparent mode skip list.

    If I put that Block Exceptions group in there, is should be forced through the Firewall where I can make a Block Exceptions rule "allow". If the proxy skip list is executed before the country block, this should work. 

    Either way, if I am correct, the order of execution will be determined by testing this...

    -----------Update ------------

    It works! I tried going to another site in that same country and it is blocked, but not my block exception URL! (I only have one in there right now.) I did not even need a rule in the FW, since the FW is not the one blocking the country. W00T!

    Test data:

    Block Norway.
    Try going to https://urlvoid.net - blocked
    Make a definition for https://urlvoid.net. Put in the proxy skiplist. 
    Try going to https://urlvoid.net - Not blocked.
    Try going to www.norway.org - blocked by country block! 

    I hope this helps others.
  • Coder68 - What's your recent experience with Country Blocking Exceptions? We were having heck with malicious botnets scanning our network for RDP connections. We eventually had to purchase RDP guard software (Windows protection is useless) for those few machines we had to have listening all the time, and turn the rest of the listening machine's NAT translations off, and only turn them back on when needed.

    So, I thought we'd just block all the countries in the list, and create specific country blocking exceptions to accept SMTP incoming traffic, which is the only thing we'd be interested in accepting from most foreign countries. However, later one of our suppliers whose email routes through Israel complained that their emails were getting rejected, and sure enough they were right. I had to turn off the country block for Israel to restore functionality for them, even though they were in the country blocking exception rules. I can open a support case, but I know it's going to be difficult for Sophos Techs to test this, and I don't want to make my supplier a guinea pig.

     

    Thanks,

    Steve P

Reply
  • Coder68 - What's your recent experience with Country Blocking Exceptions? We were having heck with malicious botnets scanning our network for RDP connections. We eventually had to purchase RDP guard software (Windows protection is useless) for those few machines we had to have listening all the time, and turn the rest of the listening machine's NAT translations off, and only turn them back on when needed.

    So, I thought we'd just block all the countries in the list, and create specific country blocking exceptions to accept SMTP incoming traffic, which is the only thing we'd be interested in accepting from most foreign countries. However, later one of our suppliers whose email routes through Israel complained that their emails were getting rejected, and sure enough they were right. I had to turn off the country block for Israel to restore functionality for them, even though they were in the country blocking exception rules. I can open a support case, but I know it's going to be difficult for Sophos Techs to test this, and I don't want to make my supplier a guinea pig.

     

    Thanks,

    Steve P

Children
No Data