Wrong Country on Threat Management

Wrong Country on Threat Management

Wrong Country on Threat Management
Wrong Country on Threat Management
Yesterday
Tags: #Firewall #threat management
Model: ER7206 (TL-ER7206)  
Hardware Version:
Firmware Version:

Hello

 

I see there is threat detail from the island of Mauritius

 

 

However this IP comes UP from AS from China. Please clarify. I have blocked China. This is no good because it is allowing traffic from China.

Please provide fix ASAP

  0      
  0      
#1
Options
5 Reply
Re:Wrong Country on Threat Management
21 hours ago - last edited 19 hours ago

Hi  @maurirope 

 

Thanks for posting here.

 

To understand the situation better, please give us the following info:

1. Which country is the router installed in?

2. What's the hardware version and firmware version of the ER7206?

3. I have blocked China.

>>>Please share the related config screenshots, is it WAN-in ACL? Please also include the selected country/region, cause we have a separate option for HK.

  0  
  0  
#4
Options
Re:Wrong Country on Threat Management
14 hours ago - last edited 14 hours ago

  @maurirope 

 

The geoblock lists are not 100% foolproof and cant be as IPs, BGP, VPNs routing all sorts of things can reorder packets all over the world sometimes.  Also, ISP stuff like CGNAT can effect where an IP shows up as, it depends where the public IP terminates and the internal ISP routing begins, as well as websites that attempt to tell you where an IP actually is can also be wrong - my ISP static public always lists as a different country in the UK as thats where their datacentre is.  

 

  0  
  0  
#5
Options
Re:Wrong Country on Threat Management
27 minutes ago
1- This is installed in Uruguay 2- The ER7206 is v2.0 with hardware v2.2.3 3- I have blocked China from Geomap page in security under global view, I tried to upload the screenshot, but somehow this forum wont allow to update screenshot, didnt allow me to update the post either as it says can only post 1 post per day. I will try to show screenshot
  0  
  0  
#6
Options
Re:Wrong Country on Threat Management
25 minutes ago
  0  
  0  
#7
Options
Re:Wrong Country on Threat Management
18 minutes ago

  @maurirope This is more misleading now for Hong Kong because it shows as blocked as whole china but it is not, now I understand why I still see the 1 thing hitting my IPS from hong Kong.

 

Anyway that is a separate issue, the issue was that traffic showing on MAP from Mauritania is actually a Hong Kong ASN ISP

 

I am unable to upload the screenshot for that right now because I uploaded the hong kong screenshot, that is a bit silly

  0  
  0  
#8
Options