Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Moudar
Advisor

Drop, updateable objects

Hi

I wonder why some traffic from China can cross my rules even if a rule that would drop the traffic is there!

 

china.JPG

The goal of the 8th rule is to drop any traffic from these countries

but looking at the logs:

china1.JPG

What do I miss here?

0 Kudos
5 Replies
the_rock
Legend
Legend

That is a bit odd. When did you notice this happen first? Rule order is 100% correct, so as long as Geo block rule comes first, no reason why it would not work.

Andy

0 Kudos
the_rock
Legend
Legend

Ok, now I know 100% why it works...look at below. Based on maxmind site, (which is what CP uses officially for geo location), that IP shows as belonging to Singapore, NOT China and thats why its allowed. Also, all the other IPs from same range belong to exact same ISP provider.

I would open TAC case and ask them to sort this out.

Andy

Screenshot_1.png

Moudar
Advisor

You are right, I will keep an eye on this and see if more flag errors are there

0 Kudos
the_rock
Legend
Legend

I think what @Timothy_Hall posted is perfect, maybe you should folllow that and see if it works for you.

Andy

0 Kudos
Timothy_Hall
Legend Legend
Legend

The gateways and the SMS have their own separate update mechanisms for the MaxMind geo database, and when they get out of sync with each other things like this can happen.  This situation was covered in my updated R81.20 IPS/AV/ABOT Immersion Course:

geo_updates.png

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
(1)

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events