100H - block external IP address ... not all IP's are blocked !

Options
SiegfriedH
SiegfriedH Posts: 18 image  Freshman Member
First Comment First Anniversary

Hello All,
I blocked several external IP adresses and found that most of them are not really blocked via "external block list". Firmware is "V1.36(ABXF.0)".

Example IP 209.38.78.160:
IP address blocked via "external block list" "IP reputation" - IP-addess not blocked - in Log / events under note as "ACCESS FORWARD".

IP address blocked "object" "address" - there I make an entry type HOST with IP 209.38.78.160, than under "security policy" and "policy control" a GeoIP blocking from "WAN to any" - IP-addess is perfect blocked - in Log / events under note as "ACCESS BLOCK".

Blocking IP's via a list is very comfortablem via a certain rule in GeoIP a lot of work.
Whats wrong? Or, what I'm doing wrong? What's the best - and most efficient way - to block external IP's.

all the Best from Austria, and TNX for help
Siegfried

Best Answers

  • PeterUK
    PeterUK Posts: 4,656 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    Answer ✓
    Options

    Testing here it does seem like the external block list does not work either for destination or source IP blocking

  • Zyxel_Melen
    Zyxel_Melen Posts: 5,030 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Answer ✓
    Options

    Hi @SiegfriedH

    Thanks for the information. This is an issue for the External Block List > IP Reputation when you also have a security policy that allow the traffic from WAN to any/ZyWALL/etc. In my lab, I can replicate this issue when I have a policy that allow this traffic flow. And here is the result.

    image.png

    However, if you set an IP address in IP Reputation > Block List,

    image.png

    the IP Reputation will block this traffic flow even the security policy allows.

    image.png

    We will fix this issue.

    Hi @PeterUK

    Yes, the IP Reputation filter needs to be enabled, since this is the main function. The external block list is an extra database for the IP Reputation filter/DNS/URL threat filter.

    Zyxel Melen


  • Zyxel_Melen
    Zyxel_Melen Posts: 5,030 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Answer ✓
    Options

    Hi @SiegfriedH

    After checking with our team, the external block list IP reputation does block the traffic from LAN to WAN and from WAN to LAN. It does not block only the traffic from WAN to ZyWALL.

    Result from WAN to LAN:

    image.png

    Since this is the current spec design, we created an idea post for this. Our product team will monitor the idea post to evaluate it.

    USG FLEX H - external block list also blocks traffic from WAN to ZyWALL — Zyxel Community

    Zyxel Melen


  • Zyxel_Melen
    Zyxel_Melen Posts: 5,030 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Answer ✓
    Options

    Hi @SiegfriedH

    I agree it is confusing. That's why I ask our product team to enhance the UIUX of the External block list page. It seems many users think this is an independent feature from the reputation filter, but it is not.

    Zyxel Melen


«13

All Replies