Hi Jerry, maybe my question appears to be complicated, but is as easy as you said in your last paragraph. I think the problem is the rule I need needs to much granularity.
Like you said, I know how to drop traffic from specific countries... And I know how to drop traffic from specific RA users... But as you said, I need both aspects in place and enforced in the same rule.
Maybe with an example the issue will be simpler to understand: need to drop RA connections from USA for certain users (or user groups), but other RA users still have to be able to connect from USA.
If I do a drop rule for USA above the MAB/RA access rule, it will drop *all* RA connections incoming from USA, regardless which user is the one trying to connect.
The granularity is the issue here: I need the cake, eat it and have it