On 9.408 and it is still broken. The wirkaround I was given was to disable url filtering for the desired site. Of course, thst makes it impossible to limit access to a few users only, based on category. Another case is being escalated.
this did the trick for me, though i dont agree as asserted that it is "definitely not a bug" ... my logic dictates it is most CERTAINLY a bug, as you would think that you would only unblock certain countries which housed the website (discernible by the IP once the dns host is looked up)
so, for example, i would expect to "not block afghanistan" for all requests going to yellow-brick.com, meaning if yellow-brick ever housed the site elsewhere, or mirrored it with redundant servers etc, then the exception would fail to work.
you dont want to unblock all countries for 1 web url, if for example dns poisoning was used to redirect traffic for ...say ...google.com to a country they otherwise dont have a server in, for the purpose of infecting machines, then leaving all countries unchecked seems like it would allow traffic to all countries where google.com dns lookup said it lived
The trick is that the country blocking excdpfion needs to include "http cache" service in addition to http and https. Juxt finishex a case on this with support.
An alternative is to disable url checking in a web filtering exception.
You are not unblocking a Country, just skipping country check for the desired request that are coming from your internal network.
As you can see in attached print-screen government.nl is still blocked.
And keep in mind, I only allow port 53 only for google dns service in Firewall rule. (if the user don't want the dns from DHCP)
Hello Bob,
Do you have a link that will show the security features available for the Sophos SG 230s, when purchasing only the 'network protection' license.
I understand I will have GEO Country blocking available to be me. What else? Do you have a Sophos link I could get from you?
I think this is what you want, Timothy: Sophos UTM Network Protection Factsheet.
Just a comment about your initial configuration - I've seen very clunky, difficult-to-maintain UTM configurations done by a talented CCIE. WebAdmin is an elegant, powerful tool, but it works differently than other brands. Sophos Sales can provide you with names of experienced Solution Partners in your area (as a moderator, I can see the IP from which you posted).
Cheers - Bob