Geo Filter - access for only certain countries
Freshman Member
If I want only one country to access from WAN to ZyWALL/Intranet. How can I make this simple?
I know I could exclude all other countries and continents, but is this the only way? A simple one were better. 😅
Thanks!
All Replies
-
The end default rule is from any to any deny but also check your default rules to Zywall.
So a rule that is from WAN to Zywall with Source country allow is all you need to do.
0 -
Thanks PeterUK!
I'm not sure if I'm missing something. If i put a rule at the first position an say that the country xy is allow than the following rules will be executed and if the country not xy it will end the execution?
I think only a denied will end the execution of the rules, or not?
I want to prevent access immediately.
0 -
There is a WAN_to_Device rule that is a default you can disable
or you can under the allow rule for the given country add a deny rule under it for from WAN to Zywall if you want.
0 -
Hi @weite,
To restrict WAN access to your ZyWALL/Intranet to only one specific country on your USG FLEX H device, you can efficiently use Geo Filter policies. Instead of denying access from all other countries individually, you can create an "allow" rule for your desired country and then a general "deny" rule for everything else.
Here’s how to set this up:
- Update GeoIP Database: First, ensure your GeoIP database is current. Go to Object > Address > GeoIP in the Web GUI and configure scheduled updates.
- Configure Policy Rules:
- Navigate to Security Policy > Policy Control.
- Rule 1 (Allow Specific Country): Create a new policy rule with,
- Action: Allow
- From: WAN
- To: ZyWALL (or your Intranet zone)
- Source: Select your specific country (you can use keyword search).
- Service: Specify the services you want to allow (e.g., HTTPS, HTTP).
- Rule 2 (Deny All Others): Create another policy rule below the first one with,
- Action: Deny
- From: WAN
- To: ZyWALL (or your Intranet zone)
- Source: Any
- Service: Any (or the specific services you are protecting).
This setup allows traffic from your chosen country while blocking all other WAN traffic to your ZyWALL/Intranet, making the configuration simpler.
Zyxel Tina
0
Categories
- All Categories
- 439 Beta Program
- 2.8K Nebula
- 205 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.4K Security
- 522 USG FLEX H Series
- 330 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.3K Wireless
- 49 Wireless Ideas
- 6.9K Consumer Product
- 290 Service & License
- 462 News and Release
- 90 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.5K FAQ
- 34 Documents
- 86 About Community
- 98 Security Highlight
Guru Member
Zyxel Employee