This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

country blocking - block all then add exceptions??

New to sophos UTM. Is it do-able and would it make sense/work to block "from" all countries and have exception allowing from my own country for IPSec VPN and Webadmin services (for Any IP), which is the only traffic I would like to accept?

I'm assuming blocking traffic "from" a country is about blocking calls initiated by that country, i.e. it wouldn't block the *response* to a call initiated from my allowed country to the blocked country. Is that true?

Unit is remote right now and I fear testing my theories could result in my losing access to the remote device and the people at that site losing all internet access...



This thread was automatically locked due to age.
Parents
  • You're right, Jean, Country Blocking does work as you understand.  That said,  I wouldn't use Country Blocking for this.

    I would only use specific IPs or subnets instead of the "Any" object in WebAdmin Settings:

    As for IPsec remote access, I would use Authentication by X509 instead of a preshared key.

    In both cases, you could add extra security with One-Time Passwords.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • You're right, Jean, Country Blocking does work as you understand.  That said,  I wouldn't use Country Blocking for this.

    I would only use specific IPs or subnets instead of the "Any" object in WebAdmin Settings:

    As for IPsec remote access, I would use Authentication by X509 instead of a preshared key.

    In both cases, you could add extra security with One-Time Passwords.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data