Country code blocks with IP address exception - is there a way to do this?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Country code blocks with IP address exception - is there a way to do this?

L4 Transporter

I have a block rule for some of the more egregious regions of the internet. Unfortunately, the regions use the source address within the rule on the Palo so I see no way to negate an IP address in a region being blocked.

 

Is there a way I'm not aware of to do this?  It would be nice if you could group a rule with another and skip the next rule if the first rule applies or if the rule criteria is met it isn't necessarily an allow or deny but a "continue at rule X".

 

Any ideas on how to do this?

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

@TonyDeHart,

There's not a great way of handling this exception process outside of making a prior rule that would capture the traffic for the exceptions you want to have still be able to reach your resources unfortunately.  What resources are you hoping to allow access to? The easiest way to manage things is to create exceptions to a single resource like GlobalProtect if it's a user that belongs to your organization. 

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

@TonyDeHart,

There's not a great way of handling this exception process outside of making a prior rule that would capture the traffic for the exceptions you want to have still be able to reach your resources unfortunately.  What resources are you hoping to allow access to? The easiest way to manage things is to create exceptions to a single resource like GlobalProtect if it's a user that belongs to your organization. 

L4 Transporter

The most likely exception in the future will be for GP which is a relatively simple rule that we could add except for the fact that these block rules are SHARE pre-rules making it difficult but I think in the rule I can just target the device directly.

 

The other though it that we have some developers spread about that could need exceptions but it could be a number of resources making it more difficult.  I was hoping to get ahead of the question before it was aske but it sounds like the only way is the way I was thinking it would have to be to start with.

 

Thank you.

  • 1 accepted solution
  • 1830 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!