<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blocking traffic from another country in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-traffic-from-another-country/m-p/47069#M34599</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Aaaah... got it... thanks!&amp;nbsp; I'm actually on 3.1.5 so that's where I was confused.&amp;nbsp; I'll check it out once we upgrade.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 03 Jun 2011 17:42:25 GMT</pubDate>
    <dc:creator>dwoolley</dc:creator>
    <dc:date>2011-06-03T17:42:25Z</dc:date>
    <item>
      <title>Blocking traffic from another country</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-traffic-from-another-country/m-p/47065#M34595</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have an Extranet server which sits on our DMZ... http and https are allowed through the firewall so that outside users can access the web app on that server.&amp;nbsp; My server admin asked me if I can block all inbound traffic from China and Taiwan as he gets a ton of hack attempts coming from those countries.&amp;nbsp; Our web app doesn't serve anybody in those countries so it makes sense to me.&amp;nbsp; Does anybody know a reason why I should not do that?&amp;nbsp; And does anybody know how I would go about blocking traffic from those sources?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for the help!&lt;/P&gt;&lt;P&gt;-Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jun 2011 00:02:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-traffic-from-another-country/m-p/47065#M34595</guid>
      <dc:creator>dwoolley</dc:creator>
      <dc:date>2011-06-02T00:02:43Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking traffic from another country</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-traffic-from-another-country/m-p/47066#M34596</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dave&lt;/P&gt;&lt;P&gt;With PAN-OS for 4.0, the security policies support specifying countries, in the source and destination fields of security policy. That will be the easiest and best option for you to block traffic from certian countries&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Jerish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jun 2011 00:44:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-traffic-from-another-country/m-p/47066#M34596</guid>
      <dc:creator>jpa</dc:creator>
      <dc:date>2011-06-02T00:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking traffic from another country</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-traffic-from-another-country/m-p/47067#M34597</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jerish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply.&amp;nbsp; That's exactly what I'm looking for... I just want to specify a country in the source field of my security policy.&amp;nbsp; I don't see how to add a country though... do I have to manually set up an object or something?&amp;nbsp; I know that IP source country is already defined and tracked somewhere as the Traffic Map under the Monitor tab shows traffic from different countries.&amp;nbsp; Can you point out what I'm missing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help!&lt;/P&gt;&lt;P&gt;-Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jun 2011 22:59:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-traffic-from-another-country/m-p/47067#M34597</guid>
      <dc:creator>dwoolley</dc:creator>
      <dc:date>2011-06-02T22:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking traffic from another country</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-traffic-from-another-country/m-p/47068#M34598</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As long as you are on 4.0.x, you can choose a source country when you add a security rule under the Policies tab.&amp;nbsp; The country list will appear in the drop down menu when you click "Add" under "Source Address" or in the drop down "Name" field under "Regions".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="countries.png" class="jive-image-thumbnail jive-image" onclick="" src="https://live.paloaltonetworks.com/legacyfs/online/2377_countries.png" width="450" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jun 2011 17:02:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-traffic-from-another-country/m-p/47068#M34598</guid>
      <dc:creator>nrice</dc:creator>
      <dc:date>2011-06-03T17:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking traffic from another country</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-traffic-from-another-country/m-p/47069#M34599</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Aaaah... got it... thanks!&amp;nbsp; I'm actually on 3.1.5 so that's where I was confused.&amp;nbsp; I'll check it out once we upgrade.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jun 2011 17:42:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-traffic-from-another-country/m-p/47069#M34599</guid>
      <dc:creator>dwoolley</dc:creator>
      <dc:date>2011-06-03T17:42:25Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking traffic from another country</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-traffic-from-another-country/m-p/47070#M34600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am slightly confused. Why would the external country be associated to a source address instead of a destination address? Our rules go from trust to untrust, (trust being internal IPs obviously). Therefore a user (source) hitting a chinese site (destination country block CN) should in theory be blocked but it isn't (IP confirmed to be registered in China).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the response from a chinese site then considered to be the "source" by PA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone elaborate a bit more on how this rule should work effectively?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To block CN, which would be the rule (or rule combo)?:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a) from Trust source (user) to Untrust destination (country block) action Deny? not working&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;b) from trust source (country block) to untrust source (user) action Deny? illogical to trust a blocked country&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;c) from Untrust source (country block) to Trust destination (user) action Deny?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Larry&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 May 2012 20:33:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-traffic-from-another-country/m-p/47070#M34600</guid>
      <dc:creator>hvcomputech</dc:creator>
      <dc:date>2012-05-29T20:33:35Z</dc:date>
    </item>
  </channel>
</rss>

