"Location Group" Not Honoring US-based IP addresses

"Location Group" Not Honoring US-based IP addresses

"Location Group" Not Honoring US-based IP addresses
"Location Group" Not Honoring US-based IP addresses
a week ago
Model: ER7206 (TL-ER7206)   OC200  
Hardware Version: V2
Firmware Version: 2.1.2 Build 20240324 Rel.46738

I was able to setup a Location block as a base firewall rule.  I am blocking all non-US/Canada websites under the Gateway ACL section using the "Location Group" and checking all countries except the US and Canada (direction is LAN->WAN).  It's been working well for a few days, however, I noticed one issue.

 

Apple[dot]com is blocked.  I ran wireshark to confirm this and indeed the IP being blocked is 23.52.117.x.  The public IP lookup information clearly states this is a US-based IP address, but the rule does not honor this IP range and blocks many services offered from Apple (even their main company website).

 

Is this a bug with the "Location Group" list provided by TP-Link?  Why is this IP address from the US being blocked?

 

I realize Apple hosts millions of services across many countries and its possible I could have been served from outside the US, but running WireShark confirmed the US-based-IP when I was hitting Apple's main company website from my PC.

 

The second I disable the rule, the website is allowed.  Or, switching over to LTE from cell phones also confirms this.

 

The workaround was to add a rule to allow the IP which was being blocked, but its only a matter of time before that changes.

 

 

 

 

 

  0      
  0      
#1
Options
6 Reply
Re:"Location Group" Not Honoring US-based IP addresses
a week ago

  @US007 IP locations can be tricky.

 

The location can be based on the office address that was used when the IPs were purchased. If I turn off location on my devices, it stops using the GPS and tries to figure out my location using my WAN IP. My Wan IP is from an ISP local to my city, but my location will be reported as the next city over.


Also, popular websites are likely hosted on multiple servers for redundancy and load balancing. The load balancer may be redirecting you to a server outside the US and Canada.

 

How many IPs are in the block list. I have seen when there is too many it might not always obey. I wish TP-LInk would add a GEO blocking feature so we don't have to create our own rules.

  1  
  1  
#2
Options
Re:"Location Group" Not Honoring US-based IP addresses
a week ago
Im not using IPs in my block list. Im using the TP-Link provided "Location Group" as a the source of the block, which are country based. I only had to add an allow rule from the IP based on what WireShark was seeing as blocked, which should be the destination for the website in my post above and not from a load balancer.
  0  
  0  
#3
Options
Re:"Location Group" Not Honoring US-based IP addresses
a week ago

  @US007 Thanks for the clarification. TP-Link may have the IP in the list by mistake, or something changed that they are not aware of.

  0  
  0  
#4
Options
Re:"Location Group" Not Honoring US-based IP addresses
a week ago
Its possible. Could just be a bug...not sure. Thanks! Have yet to reboot the gateway, but I dont think that will make a difference.
  0  
  0  
#5
Options
Re:"Location Group" Not Honoring US-based IP addresses
Monday - last edited Monday

Hi @HellBent 

Thanks for posting in our business forum.

HellBent wrote

  @US007 IP locations can be tricky.

 

The location can be based on the office address that was used when the IPs were purchased. If I turn off location on my devices, it stops using the GPS and tries to figure out my location using my WAN IP. My Wan IP is from an ISP local to my city, but my location will be reported as the next city over.


Also, popular websites are likely hosted on multiple servers for redundancy and load balancing. The load balancer may be redirecting you to a server outside the US and Canada.

 

How many IPs are in the block list. I have seen when there is too many it might not always obey. I wish TP-LInk would add a GEO blocking feature so we don't have to create our own rules.

You are correct. 

 

Maintaining a list of the geo-IP is not easy. We get the list from the vendor we cooperate with.

The geo-IP and ASN are dynamic. It was discussed previously that the IANA has this service dynamically and we may not be able to get the latest update as it might be changing every day.

Generically, for the rather stable ASN, it should be fine.

 

DPI and IP groups(geo) are updated along with the firmware. If there is no change from our partner, we may not update its list.

 

We do not have plans to update the list online due to privacy concerns that may come from users and it is hard to maintain a constantly updated and accurate database as we are a networking product company instead of a database company.

Currently, the system offers the IP Group which you can add the missing IP into the list.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  1  
  1  
#6
Options
Re:"Location Group" Not Honoring US-based IP addresses
Monday

  @Clive_A 

 

Thanks for the background and the information.

 

I guess my point was this is Apple[dot]com - so its a pretty critical site and service offering.  It's not like this was a small website with a questionable IP range.

 

My allow rule has been working fine so I will leave it for now.  Hopefully this gets further attention in future updates (I listed the IP in my original post).

  1  
  1  
#7
Options