Which SK, SK105740 ? I did follow that one up to changing the GUI settings. I did not play with the fw_ignore_before_drop_rules mentioned near the bottom.
On SK180808 I ran the two commands on the Mgmt and installed policy afterwards.
$MDS_FWDIR/scripts/reload_env_vars.sh -e "IMPLIED_RULES_SET_BEFORE_LAST=1"
$MDS_FWDIR/scripts/override_server_setting.sh -e IMPLIED_RULES_SET_BEFORE_LAST 1
Policy is simple. Single Security layer and first rule is the country geo block.
So recommended to try the fw_ignore_before_drop_rules kernel change on the two gateways in the cluster? If that works, do I need to back out the change made in SK180808?