cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Who rated this post

Cyber Elite
Cyber Elite

Hi @bpotter98 ,

 

Traffic from the untrust zone to the interface in the same untrust zone is allowed by the intrazone-default rule.  The easiest way to solve your problem is to create a drop rule (which will be above intrazone-default) that will drop all countries you do not want.

 

Rule Type:  intrazone

Source Zone:  Untrust

Source Address:  List you countries you want to allow and check Negate.

Destination Address:  Portal IP (could also be any if you want to block for all public IP addresses)

Application:  Any

Service/URL Category:  Any

Action:  Drop

 

You can choose not to log if you don't want the clutter, but you may need to enable for troubleshooting.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.
Who rated this post