What Is the Priority Order of Policies on the Security Router?

Zyxel_Jerry
Zyxel_Jerry Posts: 1,352  Zyxel Employee
Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 50 Answers 1000 Comments

On the SCR 50AXE and USG LITE 60AX.

The priority order is as follows:

Country Restriction > Security Policies > Virtual Server

If Country Restriction is set to "Allow", it takes precedence over security policies, even if a blocking rule exists.

Example: If a security policy blocks a specific IP from Taiwan, but country restriction allows all traffic from Taiwan, the IP will still be able to access the device.

Note: If traffic originates from inside the device and a blocked country is only responding, the response traffic is not blocked.

Example:

Device to Japan IP: Ping requests from the device to a Japan IP will go through.

Japan IP to Device: Ping requests from a Japan IP to the device will be blocked.