With all the global turmoil we have a desire to block traffic from bad actor countries. Such as China, North Korea, Iran and so forth. Is there a way to do this in the XG firewall?
This thread was automatically locked due to age.
Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.
With all the global turmoil we have a desire to block traffic from bad actor countries. Such as China, North Korea, Iran and so forth. Is there a way to do this in the XG firewall?
Hi,
yes there is using the predefined country groups. In the GUI - Hosts and Services - Country Groups. You set up an incoming reject rule at the top of your rule list and either select the countries or create your own policy group of countries.
Ian
XG115W - v20.0.2 MR-2 - Home
XG on VM 8 - v21 GA
If a post solves your question please use the 'Verify Answer' button.
Out of curiosity: why use a reject rule in stead of a drop rule?
I'd rather not give any response to these 'attackers'.
Out of curiosity: why use a reject rule in stead of a drop rule?
I'd rather not give any response to these 'attackers'.
Only because someone suggested it.
I suggested it, but I agree with your suggestion.
One thing to watch while trying to block bad countries is that not all bad sites even with country suffix are based in their home country from my experience a number use the Amazon servers.
Ian
XG115W - v20.0.2 MR-2 - Home
XG on VM 8 - v21 GA
If a post solves your question please use the 'Verify Answer' button.
Thank you for clearing that up.
Hi John,
you will be surprised how many sites get blocked which in most situations don't matter but some do even though you think they are locally based.
Ian
XG115W - v20.0.2 MR-2 - Home
XG on VM 8 - v21 GA
If a post solves your question please use the 'Verify Answer' button.