- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
We have a geo blocking rule, so far so simple.
However, we now have 1 specific IP which needs to get to the rest of the rules below the geo blocking rule... but is from one of the countries which we block.
How do I add an exception for specific IPs to the geo blocking rule, while still having all the other rules below the geo blocking function?
I cant see how this can work with rule below geo block, as first rule will always block the country. You need to add exception above.
We just add bypass rules above the GeoBlock, like this:
Thanks for the quick reply.
This works if you know exactly which service etc the allowed IP needs.
But we have 470 rules below the geo block I want the IP to be checked against.
I don't want to give it access to everything (HTTP(S) in your example) encase it gain access to something it should not.
A workaround is to build an inline layer for just them above the geo block, with just the access they need.
Basically what you have, but more granular
But I would then need to build a new inline layer for every exception to our geo blocklist.
Right, but if you think about it, any fw policy goes top to bottom, left to right, so if you try an exception below that geo block rule, it will never work, since upper rule will always take effect first.
Hope that makes sense.
That is true, but there is no sadly better choice. That is just how policy works with any fw vendor out there.
Thats exactly how I do it and recommend to customers.
I cant see how this can work with rule below geo block, as first rule will always block the country. You need to add exception above.
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY