Was thinking about coming back to Untangle but had a question about geo blocking. On my OPNsense firewall, I got connection attempts all day, every day from mainly Russia, China and Belarus. I could look at the live log in OPNsense and these would scroll by non-stop.
I created the following rule in Untangle:
...and when looking at the Firewall Blocked Events log, I don't see any foreign IPs. The only reason you see that 54.170.120.91 address is I was desperate to see anything popping in there as I wasn't sure if blocked events were even being captured. I added ALLLLLLLL countries except the United States and XL and that finally gave me those 54.170.120.91 IPs.
So the big question is, OPNsense was showing non-stop blocks for IPs from those 3 countries all the time WITHOUT having any geo blocking rules implemented in OPNsense. They were just being intercepted and dropped.
.....It's just weird to me that after months and months of seeing those dropped connections from Russia, China, etc.... after creating that rule, nothing. Unless all the hackers in Russia, China and Belarus gave up a few hours after testing out Untangle?
I created the following rule in Untangle:
...and when looking at the Firewall Blocked Events log, I don't see any foreign IPs. The only reason you see that 54.170.120.91 address is I was desperate to see anything popping in there as I wasn't sure if blocked events were even being captured. I added ALLLLLLLL countries except the United States and XL and that finally gave me those 54.170.120.91 IPs.
So the big question is, OPNsense was showing non-stop blocks for IPs from those 3 countries all the time WITHOUT having any geo blocking rules implemented in OPNsense. They were just being intercepted and dropped.
.....It's just weird to me that after months and months of seeing those dropped connections from Russia, China, etc.... after creating that rule, nothing. Unless all the hackers in Russia, China and Belarus gave up a few hours after testing out Untangle?

Comment