The legacy Geo Policy is enforced well before Geo Updatable Objects, at roughly the same time as antispoofing enforcement. So if traffic is dropped by the legacy Geo Policy it will be dropped regardless of how your main policy layers are configured with Geo Updatable Objects. To disable the legacy Geo Policy:
1) Under Shared Policies...Geo Policy...select Policy
2) Make sure "Default Geo Policy" is selected in the dropdown at the top of the screen
3) Select Inactive or "Monitor Only", your choice
4) Using Geo Updatable objects, ban any countries you want using Geo Updatable Objects in the first layer of your policy package
5) Publish and install policy.
Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com