USG40 Geo IP Not Working
Options
my USG-40 does not appear to be blocking based on Geo IP.
i have FW 4.65(AA 1), Geo IP date is 8-17-21
i create object for russia, used the geography setting.
then made policy as 1st rule to Deny, From Any, To Any Source-russia, Log
And i dont see anything in the log blocking traffic.
But i see the Default Rule Denying Russia labeled IPs in the log.
Why is my rule not blocking it?
Do i need to reboot after making new rules?
i have FW 4.65(AA 1), Geo IP date is 8-17-21
i create object for russia, used the geography setting.
then made policy as 1st rule to Deny, From Any, To Any Source-russia, Log
And i dont see anything in the log blocking traffic.
But i see the Default Rule Denying Russia labeled IPs in the log.
Why is my rule not blocking it?
Do i need to reboot after making new rules?
0
Best Answers
-
Add a 2nd rule below the first one you created:From: AnyTo: ZyWALLSource: russiaAction: Deny/logReboot is not required for new rules to take effect.
1 -
You need both.
From any to ZyWALL only blocks to the USG like remote login (if you have a rule to allow that) and VPN.
From any to any (except ZyWall) blocks like a NAT rule to a server for WAN to LAN and LAN to WAN
1
All Replies
-
Add a 2nd rule below the first one you created:From: AnyTo: ZyWALLSource: russiaAction: Deny/logReboot is not required for new rules to take effect.
1 -
great that worked perfect. So are two rules neccesary or just one?
I see some suspect IP scanning different ports on my public static IP.
Do i only need to block using rules with To=ZyWALL or both ZyWALL and other rule for Any(except ZyWall)?
0 -
You need both.
From any to ZyWALL only blocks to the USG like remote login (if you have a rule to allow that) and VPN.
From any to any (except ZyWall) blocks like a NAT rule to a server for WAN to LAN and LAN to WAN
1 -
great thanks!0
Categories
- All Categories
- 393 Beta Program
- 2.1K Nebula
- 116 Nebula Ideas
- 78 Nebula Status and Incidents
- 5.1K Security
- 51 USG FLEX H Series
- 247 Security Ideas
- 1.3K Switch
- 70 Switch Ideas
- 906 WirelessLAN
- 34 WLAN Ideas
- 5.9K Consumer Product
- 210 Service & License
- 332 News and Release
- 71 Security Advisories
- 21 Education Center
- 5 [Campaign] Zyxel Network Detective
- 1.9K FAQ
- 880 Nebula FAQ
- 415 Security FAQ
- 220 Switch FAQ
- 195 WirelessLAN FAQ
- 46 Consumer Product FAQ
- 137 Service & License FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 72 About Community
- 63 Security Highlight