Use External Block List only option
Guru Member
Very simple really a option to use only External Block List for IP Reputation filter
Comments
-
Make it per filter rule and not global please.
Good idea for compliance.
0 -
Hi @PeterUK,
To better understand your request, could you clarify if you mean enabling the External Block List for IP Reputation to work even when the main IP Reputation filter is disabled?
Since some users may not have seen your previous comment in other threads, to help everyone understand the purpose of this request, could you please share more details here? It would also help if you could share the motivation or use case behind this—any details on your scenario would assist us in evaluating this feature request.
Zyxel Tina
0 -
hi Tina
Yes that would be one way or the option in main IP Reputation filter with it enabled and only to use the External Block List but your suggested way might be better.
From what I know the main IP Reputation filter query the cloud and caches the if it should be allowed or not but with External Block List when you download the list is it on the USG or does it upload to the cloud for offload if its a big list?
0 -
Hi @PeterUK,
Thank you for your feedback! We will be monitoring the votes and comments as part of our evaluation process.
To answer your question about where the data resides: The IP Reputation filter queries the cloud and stores the signature locally on the device. Also, once you update the External Block List, the list is downloaded to the device's local memory but will not be uploaded to the cloud for offloading. The USG FLEX H handles the filtering locally based on the downloaded entries.
Zyxel Tina
1 -
Hi @PeterUK,
Regarding the request to use only the External Block List as the filter while IP Reputation is disabled, please note that IP Reputation and its External Block List are designed as licensed security services—they cannot be used independently.
As a workaround, please set the IP Reputation action to Pass, then enable the External Block List. This lets you use only your custom External Block List to detect malicious IPs, bypassing the main reputation filter's blocking.
Thank you for your understanding!
Zyxel Tina
1 -
Understood about the license Tina
But the workaround (not tried yet but sure it works) seems confusing that by saying action to Pass would seem it pass all including External Block List.
Could this be improved such that there is a option showing “Action for External Block List”.
Thanks
0
Categories
- All Categories
- 441 Beta Program
- 2.9K Nebula
- 210 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.4K Security
- 540 USG FLEX H Series
- 340 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.3K Wireless
- 51 Wireless Ideas
- 6.9K Consumer Product
- 295 Service & License
- 464 News and Release
- 90 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.7K FAQ
- 34 Documents
- 86 About Community
- 99 Security Highlight
Freshman Member
Zyxel Employee

