Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Hllrdm
Contributor

Geo object does not work correctly

We encountered a problem that some IP addresses do not pass the rules with Geo object country as source, so the traffic is blocked on Cleanup rule.
We can see that some addresses from Geo object country are not found when dynamic_objects -uo_show command is output, but they are related to the addresses of the country of interest and the country flag is displayed in Logs (screen 2)

Part of the addresses are in the output of the command (for these addresses also works cleanup, although they are in the output of the command dynamic_objects -uo_show) (screen1)

How can this problem be solved? Maybe there is a command that allows you to update the geo object country?

 
 

Log_1.jpglog.jpg

R80.40 Last JHF

0 Kudos
4 Replies
_Val_
Admin
Admin

May I ask which countries you are trying to filter here? Two examples are belonging to different countries, is this how you want to use them?


0 Kudos
Hllrdm
Contributor

The addresses refer to Russia. Both appear in the SmartConsole with the Russia flag.

0 Kudos
_Val_
Admin
Admin

Not really, at least some of the IPs in the second example belong to a French ISP. I am talking about 45.15.221.0/24.

You can check them here: https://www.maxmind.com/en/geoip-demo

Please look into sk126172, and if you do not see any issues with your config after reviewing that SK, open a TAC case to investigate further.

 

0 Kudos
the_rock
Legend
Legend

@_Val_ is correct, if you check few of those 45.15.x.x subnets, they all belong to locations in France. I actually used 5 different sites and they all gave same results. I know CP escalation team told me they officially use maxmind, but if other sites show the same, then its safe to conclude 100% its valid info.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events