- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-20-2017 10:49 AM
I am trying to make a policy on my new PA-220 and i want to block all traffic coming in from every country except the united states..I can't figure out how to do that except by blocking every country one country at a time.. Can anyone tell me if there is a block all except feature?
11-20-2017 12:28 PM
You should be able to create a security policy that has the source set as the 'US' and then simply Negate the source and set the action to block.
11-21-2017 01:34 AM
or set 'US' as the only source for your inbound allow policies, anything not from the US will hit the default deny rule (or an 'any' drop rule you create right after the allow policies)
11-21-2017 02:05 AM
Hi @hill11,
Both options are valid. The negate option is an often 'forgotten' feature and it has my preference in this case.
Depending on how many rules you have, you don't want to wait until you hit the final default deny all rule. This uses up precious resources and to avoid that I would recommend to block early on ^_^
Cheers !
-Kiwi.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!