Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Country blocking exception still not working ?

Hi all,

After experience with the Microsoft support scam (fake) it caused me to dive into regio/country blocking.

I block entire regio, e.g. Asia and want to allow traffic from my PC for DNS host nexus.officeapps.live.com.

No matter if I choose 'All Regions' or a specific country combined with the DNS host (and any service) traffic is still blocked.

Am I right that if I choose 'All Regions' and do not select any country, the skip action would effectively only look at DNS host (and service)?

 

Thanx Jaap



This thread was automatically locked due to age.
Parents
  • Please advise what software you are referring too?

    Doesn't sound like UTM to me.

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • Hi,

    Sorry. Forget to mention it:

    Sophos UTM Home Edition

    Version 9.411-3

     

    Greetz Jaap

  • The main problem with country blocking and the UTM version does work is that the scamming countries can have a .ru or .vn suffix but be using a US based server so country blocking will fail every time.

    Country blocking is really only good for that play fair which does not describe the bad guys. So you also need to look at suffix blocking for your mail and websites.

    These are the trade offs if you want to implement real security.

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • Hi, thanx again :)

    I 'm fully aware of the limitations of country blocking. It is just one in a row of security measures

    But I am just surprised that this option doesn't work properly.

    And, searching the forum on this subject, already for several years.

    Greetz Jaap

  • Country blocking works as designed, using the assigned ip address ranges.

    What you are looking for is country blocking based on suffix (wrong term but it will do) which you can setup your self, but requires it to be done for each proxy eg mail, web, etc.

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

Reply
  • Country blocking works as designed, using the assigned ip address ranges.

    What you are looking for is country blocking based on suffix (wrong term but it will do) which you can setup your self, but requires it to be done for each proxy eg mail, web, etc.

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

Children