Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Secret-goblin-5
Contributor
Jump to solution

Create whitelist for single IP when using Geo-blocking objects

Screenshot 2025-12-12 135538.png

We have a geo blocking rule, so far so simple.

However, we now have 1 specific IP which needs to get to the rest of the rules below the geo blocking rule... but is from one of the countries which we block.

 

How do I add an exception for specific IPs to the geo blocking rule, while still having all the other rules below the geo blocking function?

0 Kudos
2 Solutions

Accepted Solutions
CaseyB
Advisor

We just add bypass rules above the GeoBlock, like this:

GeoBypass.png

View solution in original post

(1)
the_rock
MVP Platinum
MVP Platinum

I cant see how this can work with rule below geo block, as first rule will always block the country. You need to add exception above.

Best,
Andy

View solution in original post

0 Kudos
(1)
6 Replies
CaseyB
Advisor

We just add bypass rules above the GeoBlock, like this:

GeoBypass.png

(1)
Secret-goblin-5
Contributor

 

Thanks for the quick reply.

This works if you know exactly which service etc the allowed IP needs.
But we have 470 rules below the geo block I want the IP to be checked against.

I don't want to give it access to everything (HTTP(S) in your example) encase it gain access to something it should not.

 

A workaround is to build an inline layer for just them above the geo block, with just the access they need.
Basically what you have, but more granular
But I would then need to build a new inline layer for every exception to our geo blocklist.

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Right, but if you think about it, any fw policy goes top to bottom, left to right, so if you try an exception below that geo block rule, it will never work, since upper rule will always take effect first.

Hope that makes sense.

Best,
Andy
the_rock
MVP Platinum
MVP Platinum

That is true, but there is no sadly better choice. That is just how policy works with any fw vendor out there.

Best,
Andy
0 Kudos
the_rock
MVP Platinum
MVP Platinum

Thats exactly how I do it and recommend to customers.

Best,
Andy
0 Kudos
the_rock
MVP Platinum
MVP Platinum

I cant see how this can work with rule below geo block, as first rule will always block the country. You need to add exception above.

Best,
Andy
0 Kudos
(1)

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events