<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>IPv6 Country Block WAN to LAN strangeness</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/148018/ipv6-country-block-wan-to-lan-strangeness</link><description>Hello, 
 Since the XG Firewall does not have countries for IPv6, I have created my own countries based on published IPv6 address ranges which can be found here https://www.ipdeny.com/ 
 I created a LAN to WAN rule to block access to a country and a WAN</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: IPv6 Country Block WAN to LAN strangeness</title><link>https://community.sophos.com/thread/549225?ContentTypeID=1</link><pubDate>Sat, 30 Nov 2024 20:03:32 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:1d8a4716-8bf9-48d4-b8bb-7870bb46f53d</guid><dc:creator>Casual_User</dc:creator><description>&lt;p&gt;Seems like I&amp;#39;m beating a dead horse here, but the issue is not resolved.&lt;/p&gt;
&lt;p&gt;After much frustration and troubleshooting, In a nutshell:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;My network runs dual stack with an internal DNS server that uses DNS over TLS&lt;/li&gt;
&lt;li&gt;I have country block lists working correctly for IPv4&lt;/li&gt;
&lt;li&gt;I created my own IPv6 Group for a country&lt;/li&gt;
&lt;li&gt;When I add IPv6 block rules using the Source or Destination as &amp;quot;Any&amp;quot; the DNS server looses all IPv4 ability&lt;/li&gt;
&lt;li&gt;When I change the IPv6 Source or Destination to WAN for the respective incoming or outgoing rule, things appear to work but they actually get worse&lt;/li&gt;
&lt;li&gt;Testing the connection on internet.nl it now get a rating of 2. &amp;nbsp;IPv4 and IPv6 both fail. &amp;nbsp;DNSSEC fails too but If I run a separate DNSSEC test, DNSSEC works&lt;/li&gt;
&lt;li&gt;My DNS server shows a very large number of &amp;quot;Server Failures&amp;quot;. &amp;nbsp;What is very large, well 40% and more&lt;/li&gt;
&lt;li&gt;if I redirect to my other internal DNS server that does not use DNS over TLS, then things start to work again as the DNS caches clear up&lt;/li&gt;
&lt;li&gt;If I disable ALL blocking rules for IPv6, DNS over TLS&amp;nbsp;works perfectly once again with a 100% score on internet.nl&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;So, from this, it seems that the XG Firewall (I&amp;#39;m running v21) has severe issues with DNS over TLS and IPv6 block rules.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: IPv6 Country Block WAN to LAN strangeness</title><link>https://community.sophos.com/thread/548978?ContentTypeID=1</link><pubDate>Fri, 22 Nov 2024 20:04:05 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:cf6e88eb-bb5a-4caf-8863-61cd68ac5e8a</guid><dc:creator>Casual_User</dc:creator><description>&lt;p&gt;I have solved this issue. &amp;nbsp;If I put WAN with the relevant source and destination rules the country blocking works without interfering with IPv4.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>