<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom region not reflecting in &amp;quot;show location ip xxx.xxx.xxx.xxx&amp;quot; in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/custom-region-not-reflecting-in-quot-show-location-ip-xxx-xxx/m-p/482400#M104288</link>
    <description>&lt;P&gt;I don't have it any more, but in 8.1 we were using a custom region rule to rewrite a few IPs into the CN region. Sometime after upgrading to 9.1 I rewrote some Security policies and changed to having my custom regions being unique (i.e. "CDN" for allowed CDNs regardless of geolocation, some custom regions for malware/exploit ranges that are scattered across the world). I assume that adding an IP/range to a predefined region still works the same but I don't have a way to test that easily at the moment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;An easy test might be to take something known, say Google DNS 8.8.8.8, and add it to the custom CN region. Commit and then run some ping/DNS tests and look at the logs, see if it now shows as CN instead of US (or India as kept happening to us, now part of our CDN rule).&lt;/P&gt;</description>
    <pubDate>Mon, 25 Apr 2022 19:40:14 GMT</pubDate>
    <dc:creator>Adrian_Jensen</dc:creator>
    <dc:date>2022-04-25T19:40:14Z</dc:date>
    <item>
      <title>Custom region not reflecting in "show location ip xxx.xxx.xxx.xxx"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-region-not-reflecting-in-quot-show-location-ip-xxx-xxx/m-p/482377#M104283</link>
      <description>&lt;P&gt;I have an IP address that is showing up in the wrong region, say AM (Armenia) and should be CN (China).&amp;nbsp; I have a support case open to get that fixed, but it has been open for over a week so I want to do a workaround.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ideally I could specify to override this IP address to show up in CN.&amp;nbsp; It seems like this could be done via Objects &amp;gt; Regions &amp;gt; Add &amp;gt; Choose CN from the Region drop down &amp;gt; add the IP address in the list below.&amp;nbsp; But "show locations ip x.x.x.x" still shows that the IP is considered to be in Armenia.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So maybe it has to be a custom region?&amp;nbsp; I created a region called "Test" and put the IP address in it.&amp;nbsp; "show locations ip x.x.x.x" still shows that the IP is considered to be in Armenia.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does the "show locations ip" command only consider the built-in regions?&lt;/P&gt;&lt;P&gt;If I test with some actual traffic would it do the correct thing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 18:37:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-region-not-reflecting-in-quot-show-location-ip-xxx-xxx/m-p/482377#M104283</guid>
      <dc:creator>AaronAxvig</dc:creator>
      <dc:date>2022-04-25T18:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: Custom region not reflecting in "show location ip xxx.xxx.xxx.xxx"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-region-not-reflecting-in-quot-show-location-ip-xxx-xxx/m-p/482389#M104285</link>
      <description>&lt;P&gt;Testing here, it appears that the "show location ip" only queries the PA geolocation database. I have some custom regions defined for CDNs/etc. that get misidentified (or are in a different country but we don't want to allow the entire country) and the custom region is both used in the Security policy and appears as the source/destination region in the Traffic logs.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 19:27:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-region-not-reflecting-in-quot-show-location-ip-xxx-xxx/m-p/482389#M104285</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-04-25T19:27:06Z</dc:date>
    </item>
    <item>
      <title>Re: Custom region not reflecting in "show location ip xxx.xxx.xxx.xxx"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-region-not-reflecting-in-quot-show-location-ip-xxx-xxx/m-p/482394#M104286</link>
      <description>&lt;P&gt;Thanks, interesting to hear that result of your testing and I guess that confirms my suspicions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any thoughts then on whether the override of the built-in regions would work as I described in the "Ideally..." paragraph?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 19:30:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-region-not-reflecting-in-quot-show-location-ip-xxx-xxx/m-p/482394#M104286</guid>
      <dc:creator>AaronAxvig</dc:creator>
      <dc:date>2022-04-25T19:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: Custom region not reflecting in "show location ip xxx.xxx.xxx.xxx"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-region-not-reflecting-in-quot-show-location-ip-xxx-xxx/m-p/482400#M104288</link>
      <description>&lt;P&gt;I don't have it any more, but in 8.1 we were using a custom region rule to rewrite a few IPs into the CN region. Sometime after upgrading to 9.1 I rewrote some Security policies and changed to having my custom regions being unique (i.e. "CDN" for allowed CDNs regardless of geolocation, some custom regions for malware/exploit ranges that are scattered across the world). I assume that adding an IP/range to a predefined region still works the same but I don't have a way to test that easily at the moment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;An easy test might be to take something known, say Google DNS 8.8.8.8, and add it to the custom CN region. Commit and then run some ping/DNS tests and look at the logs, see if it now shows as CN instead of US (or India as kept happening to us, now part of our CDN rule).&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 19:40:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-region-not-reflecting-in-quot-show-location-ip-xxx-xxx/m-p/482400#M104288</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-04-25T19:40:14Z</dc:date>
    </item>
    <item>
      <title>Re: Custom region not reflecting in "show location ip xxx.xxx.xxx.xxx"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-region-not-reflecting-in-quot-show-location-ip-xxx-xxx/m-p/482763#M104313</link>
      <description>&lt;P&gt;I added the IP address to the region as I described in the "Ideally..." paragraph and that worked.&amp;nbsp; It shows up in the traffic logs as that being the Source Country too, which is nice.&lt;/P&gt;&lt;P&gt;I did not verify that this doesn't wipe out any other addresses that are included in the region out-of-the-box.&amp;nbsp; That is unlikely I think and we don't have any other traffic coming from that region so it would have been a little harder to test.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2022 20:42:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-region-not-reflecting-in-quot-show-location-ip-xxx-xxx/m-p/482763#M104313</guid>
      <dc:creator>AaronAxvig</dc:creator>
      <dc:date>2022-04-26T20:42:51Z</dc:date>
    </item>
  </channel>
</rss>

