Geography does not work

webdisaster
webdisaster Posts: 8  Freshman Member
First Comment Fifth Anniversary

wantes to block access from outside austria for an external service.
adde d geo austria , made nat and securriy rule with source austria. Somerimes it work. Other times source is blocked and the block is logged

Log shows ,that the source comes from austria.
bit austria should be unblocked.

Removing geo give access to all and the service works


this problem exists at actual flex series (dont know if h series to) and on older usg. Thonk the problem exists since 4.38

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 2,855  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @webdisaster,

    What's the log when the access is blocked? And what's your full security policy list?

    Zyxel Melen


  • webdisaster
    webdisaster Posts: 8  Freshman Member
    First Comment Fifth Anniversary
    edited February 10

    Blocked with austrian flag at the end of the line. the strange thing is that sometimes it works

    added group GEO. addad austria to group

    made Firewall rule and NAT ( not representative - like i do every time on forwarding)

    wan to lan1 sourc. GEO dest. 192.168.110.253 (Obj. XPC) service 1001 (XPC-Service) allow

    Security Policy Control

    Match default rule, DROP

    x.x.x.x:53812

    192.168.110.253:1001

  • PeterUK
    PeterUK Posts: 3,605  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    If the other end uses a VPN then the rule will not apply

  • webdisaster
    webdisaster Posts: 8  Freshman Member
    First Comment Fifth Anniversary

    yes its a vpn. Flex is a VPN Endpoint. want to secure it to specific country

  • PeterUK
    PeterUK Posts: 3,605  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    how does the other end and from where connect to this port 1001?