- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: IPS Geo Protection doesn't recognize the count...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IPS Geo Protection doesn't recognize the country
Hello.
On freshly updated R80.40 there is some issue with Geo Protection. We have added Poland as source country in one of ours security rules and one address is blocked, but it should not be.
Let's take for example following IP: 194.36.19.20. Acording to this sk94364 it's "value" used in the IpToCountry.cvs is:
194.36.19.20 = 20 + 19 * 256 + 36 * 256*256 + 194 * 256*256*256 = 20 + 4864 + 2359296 + 3254779904 = 3257144084
In IpToCountry.cvs (it was updated automatically few hours ago) it shows correctly as Poland:
"3257144064","3257144319","iana","410227200","PL","POL","Poland"
At https://www.maxmind.com/en/geoip-demo that IP is Poland, too. So everything seems ok, but unfortunately it is blocked by "Geo-location inbound enforcement" although all traffic from Poland is allowed. In default geo policy we only block some countries and all others are allowed (default policy for other countries is allow). In logs there is no even the flag in front of that IP (as it always should be). It seems like it's unrecognized country and ... that's why blocked :-(.
Any ideas?
Best regards
Mirek
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would contact TAC with the issue !
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Make sure your gateway and management have updated IpToCountry databases.
One-liner to update IpToCountry data on Security Managements
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As far as I know management has no in.geod service and IpToCountry.csv file.
On gateways service is running and the file was (as I wrote) updated few hours ago.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Your management has an IpToCountry.csv, see my links above.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes Sir,
one-liner works great! Now management correctly shows this IP's country in logs.
Thank You very much, however sk114216 is talking only about gateway and not a word about management. Strange.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
By the way in Support Service Request we have only 2 options:
1. Non-Technical Issue (Account Services and Licensing)
2. Content Classification (Report Spam misclassification, Request URL Categorization)
Don't You think it should be (at least) 3-rd option:
3. Geo IP issues (country misclassification) ?
