Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Country blocking exception not working

I'm running Firmware version: 9.303-2. I have Country Blocking turned on to some  countries, one of which is Netherlands.

When I try to go to: Yellow Bricks

I get this error:
Content blocked
While trying to retrieve the URL: Yellow Bricks
The content is blocked due to the following condition:
The URL you have requested matches a forbidden Country. If you think this is wrong, please contact your administrator.
Country: Netherlands

I went to "Country Blocking Exceptions" and created a an exception called "Whitelist"

It says its set to:

skip blocking of these countries:
    [Netherlands] Netherlands
for traffic going to these destination networks:
    Whitelist 1
    Whitelist 2
    Whitelist 3
Using these services:
    Any

For the three networks, I've tried three things:

Name: Whitelist 1
Type: DNS Host
Hostname: Yellow Bricks


Name: Whitelist 2
Type: DNS Host
Hostname: yellow-bricks.com


Name: Whitelist 3
Type: Network
IPV4 address: 109.237.219.143 /32


None of them work. 

If I tell the country blocking list to allow Netherlands, it lets me access the site.


Any ideas?

Thanks!

Arch


This thread was automatically locked due to age.
Parents
  • Don't CHECK anything, since the request is not coming......
    It is definitely not a bug

  • this did the trick for me, though i dont agree as asserted that it is "definitely not a bug" ... my logic dictates it is most CERTAINLY a bug, as you would think that you would only unblock certain countries which housed the website (discernible by the IP once the dns host is looked up)

     

    so, for example, i would expect to "not block afghanistan" for all requests going to yellow-brick.com, meaning if yellow-brick ever housed the site elsewhere, or mirrored it with redundant servers etc, then the exception would fail to work.

     

    you dont want to unblock all countries for 1 web url, if for example dns poisoning was used to redirect traffic for ...say ...google.com to a country they otherwise dont have a server in, for the purpose of infecting machines, then leaving all countries unchecked seems like it would allow traffic to all countries where google.com dns lookup said it lived

Reply
  • this did the trick for me, though i dont agree as asserted that it is "definitely not a bug" ... my logic dictates it is most CERTAINLY a bug, as you would think that you would only unblock certain countries which housed the website (discernible by the IP once the dns host is looked up)

     

    so, for example, i would expect to "not block afghanistan" for all requests going to yellow-brick.com, meaning if yellow-brick ever housed the site elsewhere, or mirrored it with redundant servers etc, then the exception would fail to work.

     

    you dont want to unblock all countries for 1 web url, if for example dns poisoning was used to redirect traffic for ...say ...google.com to a country they otherwise dont have a server in, for the purpose of infecting machines, then leaving all countries unchecked seems like it would allow traffic to all countries where google.com dns lookup said it lived

Children
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?