USG FLEX 100 - GEO block seems doesn't work
Kolomeyets
Posts: 5
Dear all, could you please help me with the next question I have USG FLEX 100 V5.20(ABUH.0), configured GEO_BLOCK deny policy (priority 2) from WAN to any (Excluding ZyWALL) for sources IP including China. (action - deny, log - no)
but in the log I see:
This is why I assume my policy doesn't work properly. Why the rule id "from WAN to ANY" has priority 1 and how to change this? Any idea how to solve the issue?
Thank you in advance
0
Accepted Solution
-
Kolomeyets,
You also need to add from WAN to ZyWALL rules, to deny access to ports of USG FLEX itself.
1
All Replies
-
Kolomeyets,
You also need to add from WAN to ZyWALL rules, to deny access to ports of USG FLEX itself.
1 -
I have an update on the subject, it seems the problem appeared again.
policy:
Any idea how to handle this?0 -
Hello @Kolomeyets, IMVHO... the problem seems just... the logging.
Rule #1 and #2 say "if it's coming from GEO_BLOCK" then "deny connection" and "don't log it".
Well... seems from the log that access is blocked; Rule #1 for "all but USG", rule #2 "USG". Issue seems that it's logged anyway.
Maybe a little bug on logging options by zyxel?
Moreover: is any policy with "log alert" or "log" enabled?0 -
I have plenty of policies with log enabled, but as a matter of fact, you may see in the screen upper the cause rule id 1 "from WAN to Any", and unfortunately I don't have any clue how to manage it.
0 -
You could try to change the setting from "no" to "Log alert" and see if the rule #1 triggers alerts...0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 149 Nebula Ideas
- 96 Nebula Status and Incidents
- 5.7K Security
- 264 USG FLEX H Series
- 271 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 41 Wireless Ideas
- 6.4K Consumer Product
- 249 Service & License
- 387 News and Release
- 84 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.5K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 73 Security Highlight