- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Why does the wrong flag show up for an IP address ...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Why does the wrong flag show up for an IP address in GeoBlocking?
I've seen an interesting behavior in our 80.10 infrastructure.
We use GeoBlocking and many times we'll see where the firewall is dropping the traffic due to a GeoBlock. But, it posts the wrong country's flag next to the IP address.
In the attachment, you'll see 13.75.126.169 being marked with an American flag. However, the destination country is marked as HKG.
Checking the MaxMind GeoIP2 City Database does indeed note the IP is registered to Hong Kong.
MSFT is the owner of the IP block.
So, is the firewall log telling me that the IP is owned by a US company, but assigned in another country?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That doesn’t sound like correct behavior.
Have you opened a TAC case?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, spoke with TAC.
They believe that because the netblock is owned by MSFT, the firewall is showing that as owned by an American company while the network is assigned to another country. Hence the 2 flags.
It kinda, sorta makes sense. Just weird to see it like that when you're troubleshooting.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi there! I found the same issue here. Maybe it works for you:
