Tim, if I can add to this - we see the same behavior and it is confusing. As I understand it the Geo Policy used to be part of the IPS blade. We changed to the updatable objects in the policy rules, so now the Geo Blocking is happening in the access rules. As I understand it the IPS blade comes first. Is that true? If it is that might explain the original question.
When I look at the cyber attack view, I see IPS hits on countries we have blocked in the access policy. The normal expectation would be that a geo blocked IP would not make it to the IPS, but if IPS is still coming first (where geo blocking used to be) then this would be expected behavior.
If this is wrong, then I am seeing the same pattern as Hllrdm.
If this is right (expected behavior because IPS comes first), it is adding a lot of unnecessary noise. If true, is there a good way to change that behavior? I assume even if we layer the access policies it wouldn't matter if IPS is coming first.