Hi,
We have Geo policy as below:
The problem is that we still see logs with "Accept" from these countries! for example from China:
What I know is that if the Geo policy is set to drop, no one packet (from countries included) will go through the firewall, or do i miss something?
I tried to use a rule with an updateable object as:
As you can see this rule is not getting any hits! even if there are many rules that accepted traffic from China over this one like rule 25 and 35.
Should these two (Geo policy & a rule with Updateable objects) being used together or only one should be used?
As you can see in the rule i have included Indonesia only to test if I will get some hits from a country that is not included in the Geo policy, but I got nothing.