100H - block external IP address ... not all IP's are blocked !
Freshman Member
Hello All,
I blocked several external IP adresses and found that most of them are not really blocked via "external block list". Firmware is "V1.36(ABXF.0)".
Example IP 209.38.78.160:
IP address blocked via "external block list" "IP reputation" - IP-addess not blocked - in Log / events under note as "ACCESS FORWARD".
IP address blocked "object" "address" - there I make an entry type HOST with IP 209.38.78.160, than under "security policy" and "policy control" a GeoIP blocking from "WAN to any" - IP-addess is perfect blocked - in Log / events under note as "ACCESS BLOCK".
Blocking IP's via a list is very comfortablem via a certain rule in GeoIP a lot of work.
Whats wrong? Or, what I'm doing wrong? What's the best - and most efficient way - to block external IP's.
all the Best from Austria, and TNX for help
Siegfried
Best Answers
-
Testing here it does seem like the external block list does not work either for destination or source IP blocking
0 -
Hi @SiegfriedH
Thanks for the information. This is an issue for the External Block List > IP Reputation when you also have a security policy that allow the traffic from WAN to any/ZyWALL/etc. In my lab, I can replicate this issue when I have a policy that allow this traffic flow. And here is the result.
However, if you set an IP address in IP Reputation > Block List,
the IP Reputation will block this traffic flow even the security policy allows.
We will fix this issue.
Hi @PeterUK
Yes, the IP Reputation filter needs to be enabled, since this is the main function. The external block list is an extra database for the IP Reputation filter/DNS/URL threat filter.
Zyxel Melen0 -
Hi @SiegfriedH
After checking with our team, the external block list IP reputation does block the traffic from LAN to WAN and from WAN to LAN. It does not block only the traffic from WAN to ZyWALL.
Result from WAN to LAN:
Since this is the current spec design, we created an idea post for this. Our product team will monitor the idea post to evaluate it.
USG FLEX H - external block list also blocks traffic from WAN to ZyWALL — Zyxel Community
Zyxel Melen0
All Replies
-
Testing here it does seem like the external block list does not work either for destination or source IP blocking
0 -
Thanks for fast answer
0 -
Now i made also a few more tests and you are right …
The external block list feature isn't working correct.
waiting for a fix …0 -
Hi @SiegfriedH
The External Block List (EBL) is a feature that allows the firewall to import a text file hosted on an external web server. There for, may I confirm your configuration here?
- Did you setup a web server with the txt file for all access?
- Is the blocked IP in this txt file?
- Did you sync the signature with the external block list server?
- Could you share the txt file and your setting with us?
- Could you share the logs of the issue?
Additionally, I did a local test and get this result.
Zyxel Melen0 -
Hello Melen,
- Did you setup a web server with the txt file for all access?
yes, see screenshot
- Is the blocked IP in this txt file?
yes
- Did you sync the signature with the external block list server?
see screenshot - is this correct?
- Could you share the txt file and your setting with us?
IP file "blocklist_sigi.ipset" is also here as rar file
- Could you share the logs of the issue?
i didn't log this - sorry
0 -
Hi @SiegfriedH
Thanks for the update.
May I know your test path is from LAN to WAN or? This could help us to identify this issue.
Zyxel Melen0 -
I hope I understand, here are the screenshots.
0 -
in both direction are the same IP's blocked in "GeoIP_blocking_in" an "GeoIP_blocking_out".
0 -
Melen do you need to enable IP Reputation filter when you enable External Block List or can the two work independently?
0 -
Hi @SiegfriedH
Thanks for the information. This is an issue for the External Block List > IP Reputation when you also have a security policy that allow the traffic from WAN to any/ZyWALL/etc. In my lab, I can replicate this issue when I have a policy that allow this traffic flow. And here is the result.
However, if you set an IP address in IP Reputation > Block List,
the IP Reputation will block this traffic flow even the security policy allows.
We will fix this issue.
Hi @PeterUK
Yes, the IP Reputation filter needs to be enabled, since this is the main function. The external block list is an extra database for the IP Reputation filter/DNS/URL threat filter.
Zyxel Melen0
Categories
- All Categories
- 441 Beta Program
- 2.9K Nebula
- 210 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.4K Security
- 538 USG FLEX H Series
- 340 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.3K Wireless
- 51 Wireless Ideas
- 6.9K Consumer Product
- 295 Service & License
- 462 News and Release
- 90 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.7K FAQ
- 34 Documents
- 86 About Community
- 99 Security Highlight
Guru Member
Zyxel Employee










