- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
I've seen an interesting behavior in our 80.10 infrastructure.
We use GeoBlocking and many times we'll see where the firewall is dropping the traffic due to a GeoBlock. But, it posts the wrong country's flag next to the IP address.
In the attachment, you'll see 13.75.126.169 being marked with an American flag. However, the destination country is marked as HKG.
Checking the MaxMind GeoIP2 City Database does indeed note the IP is registered to Hong Kong.
MSFT is the owner of the IP block.
So, is the firewall log telling me that the IP is owned by a US company, but assigned in another country?
That doesn’t sound like correct behavior.
Have you opened a TAC case?
Yes, spoke with TAC.
They believe that because the netblock is owned by MSFT, the firewall is showing that as owned by an American company while the network is assigned to another country. Hence the 2 flags.
It kinda, sorta makes sense. Just weird to see it like that when you're troubleshooting.
Hi there! I found the same issue here. Maybe it works for you:
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY