Does ADP take into consideration the GeoIP and the rules with blocked ranges?
Does ADP take into consideration the blocking rules entered in the GeoIP? I have for example blocked specific countries, and still there are often ADP hits from these blocked countries.
I am aware tha the GeoIP database for any country or continent may not include the latest status for public IP ranges, but nevertheless - I get ADP hits from all the blocked countries.
Can somebody answer my question above?
Many thanks in advance
Best Answers
-
Hi @Zyxel_USG_User ,
Based on your description, we assume you've implemented GeoIP blocking rules in your firewall security policy. However, it's important to understand the processing order:
- ADP (Anomaly Detection & Prevention) rules take priority over firewall security rules. The firewall first checks incoming packets against ADP rules.
- If a packet is not blocked by ADP, the firewall then checks it against security policies.
Key point: ADP does not consider the blocking rules set in GeoIP. This means that even if you have GeoIP rules in firewall security policy, ADP will process packets independently of these rules.
1 -
Thanks for the very clear statement,very helpful to understand how the FW works.
0
All Replies
-
Hi @Zyxel_USG_User ,
Based on your description, we assume you've implemented GeoIP blocking rules in your firewall security policy. However, it's important to understand the processing order:
- ADP (Anomaly Detection & Prevention) rules take priority over firewall security rules. The firewall first checks incoming packets against ADP rules.
- If a packet is not blocked by ADP, the firewall then checks it against security policies.
Key point: ADP does not consider the blocking rules set in GeoIP. This means that even if you have GeoIP rules in firewall security policy, ADP will process packets independently of these rules.
1 -
Thanks for the very clear statement,very helpful to understand how the FW works.
0
Categories
- All Categories
- 415 Beta Program
- 2.5K Nebula
- 152 Nebula Ideas
- 101 Nebula Status and Incidents
- 5.8K Security
- 296 USG FLEX H Series
- 281 Security Ideas
- 1.5K Switch
- 77 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.5K Consumer Product
- 254 Service & License
- 396 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 87 About Community
- 76 Security Highlight