USG FLEX 100 - GEO block seems doesn't work
![Kolomeyets](https://us.v-cdn.net/6029482/uploads/avatarstock/n21OZ5G9ZPB04.png)
Kolomeyets
Posts: 5
Dear all, could you please help me with the next question I have USG FLEX 100 V5.20(ABUH.0), configured GEO_BLOCK deny policy (priority 2) from WAN to any (Excluding ZyWALL) for sources IP including China. (action - deny, log - no)
![Image: https://us.v-cdn.net/6029482/uploads/editor/wt/w81q3pgg3rj8.jpg](https://us.v-cdn.net/6029482/uploads/editor/wt/w81q3pgg3rj8.jpg)
![Image: https://us.v-cdn.net/6029482/uploads/editor/wt/w81q3pgg3rj8.jpg](https://us.v-cdn.net/6029482/uploads/editor/wt/w81q3pgg3rj8.jpg)
but in the log I see:
![Image: https://us.v-cdn.net/6029482/uploads/editor/kd/3tv3zsb380lu.jpg](https://us.v-cdn.net/6029482/uploads/editor/kd/3tv3zsb380lu.jpg)
![Image: https://us.v-cdn.net/6029482/uploads/editor/n1/ynqgj4roii9f.jpg](https://us.v-cdn.net/6029482/uploads/editor/n1/ynqgj4roii9f.jpg)
This is why I assume my policy doesn't work properly. Why the rule id "from WAN to ANY" has priority 1 and how to change this? Any idea how to solve the issue?
Thank you in advance
0
Accepted Solution
-
Kolomeyets,
You also need to add from WAN to ZyWALL rules, to deny access to ports of USG FLEX itself.
1
All Replies
-
Kolomeyets,
You also need to add from WAN to ZyWALL rules, to deny access to ports of USG FLEX itself.
1 -
I have an update on the subject, it seems the problem appeared again.
policy:
Any idea how to handle this?0 -
Hello @Kolomeyets, IMVHO... the problem seems just... the logging.
Rule #1 and #2 say "if it's coming from GEO_BLOCK" then "deny connection" and "don't log it".
Well... seems from the log that access is blocked; Rule #1 for "all but USG", rule #2 "USG". Issue seems that it's logged anyway.
Maybe a little bug on logging options by zyxel?
Moreover: is any policy with "log alert" or "log" enabled?0 -
I have plenty of policies with log enabled, but as a matter of fact, you may see in the screen upper the cause rule id 1 "from WAN to Any", and unfortunately I don't have any clue how to manage it.
0 -
You could try to change the setting from "no" to "Log alert" and see if the rule #1 triggers alerts...0
Categories
- All Categories
- 415 Beta Program
- 2.5K Nebula
- 152 Nebula Ideas
- 101 Nebula Status and Incidents
- 5.8K Security
- 296 USG FLEX H Series
- 281 Security Ideas
- 1.5K Switch
- 77 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.5K Consumer Product
- 254 Service & License
- 396 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 87 About Community
- 76 Security Highlight