100H - block external IP address ... not all IP's are blocked !
All Replies
-
TNX for fast answer.
So I use this you wrote above till a fix via firmware is available.
0 -
Ok Melen thanks for the info I think I put it in ideas so that the IP Reputation filter have a option to use only External Block List.
I think the layout for External Block List where it is in the UI is misleading when you enable it at least to me.
0 -
Hi @SiegfriedH
After checking with our team, the external block list IP reputation does block the traffic from LAN to WAN and from WAN to LAN. It does not block only the traffic from WAN to ZyWALL.
Result from WAN to LAN:
Since this is the current spec design, we created an idea post for this. Our product team will monitor the idea post to evaluate it.
USG FLEX H - external block list also blocks traffic from WAN to ZyWALL — Zyxel Community
Zyxel Melen0 -
So I've another Problem, please see screenshots:
see Entry 334 - access forward, although the IP address ist blocked via external Block list.I made a routing through the firewall to internal web-server.
When a policy control is made like the screenshots than a blocked IP adress is routed through to internal IP.I thought, that a blocked IP address via external bliock list is always blocked.
What can I do to block a IP address 100% although a routing to the internal web-server is active?
LG Siegfried
0 -
Looks like the block list was only designed to block internal to external so there needs to be options like
block for:
internal to external (including General)
internal to internal
external (including General) to external (including General)
external (including General) to internal
external (including General) to zywall
So your only option to do block as it is it to do your own block list in address object to add to the control policy for source
0 -
So what should I do now to block all external IP's in the external block list, although there are 3 routing from external to internal web-server?
Is there an easy way to do so?0 -
So you would need to add IP's in block list to USG address object one by one then make control policy for from WAN to LAN and WAN to zywall with a source address group all them IP's
0 -
Hi @SiegfriedH
Your result is not an expected behavior, which is different from our test result (the same NAT rule, security policy, and the external block list).
Could you help query this IP (204.76.203.212) in Security Services > Reputation filter > IP Reputation tab? In here we can check if the device adds this signature.
If the result shows your signature, please check if the IP Reputation and External block list > IP reputation is enabled.
If both are enabled, please share your configuration file with us to check. You may share it by sending a message to me on the community.
Zyxel Melen1 -
Hello Melen,
here are the results.
Where should I send my config file?
Results are not so good …
0 -
Hi @SiegfriedH
I have sent you a private message, please share your config file in the message. Thanks~
Zyxel Melen0
Categories
- All Categories
- 441 Beta Program
- 2.9K Nebula
- 210 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.4K Security
- 539 USG FLEX H Series
- 340 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.3K Wireless
- 51 Wireless Ideas
- 6.9K Consumer Product
- 295 Service & License
- 464 News and Release
- 90 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.7K FAQ
- 34 Documents
- 86 About Community
- 99 Security Highlight
Freshman Member
Guru Member
Zyxel Employee










