"Location Group" Not Honoring US-based IP addresses
I was able to setup a Location block as a base firewall rule. I am blocking all non-US/Canada websites under the Gateway ACL section using the "Location Group" and checking all countries except the US and Canada (direction is LAN->WAN). It's been working well for a few days, however, I noticed one issue.
Apple[dot]com is blocked. I ran wireshark to confirm this and indeed the IP being blocked is 23.52.117.x. The public IP lookup information clearly states this is a US-based IP address, but the rule does not honor this IP range and blocks many services offered from Apple (even their main company website).
Is this a bug with the "Location Group" list provided by TP-Link? Why is this IP address from the US being blocked?
I realize Apple hosts millions of services across many countries and its possible I could have been served from outside the US, but running WireShark confirmed the US-based-IP when I was hitting Apple's main company website from my PC.
The second I disable the rule, the website is allowed. Or, switching over to LTE from cell phones also confirms this.
The workaround was to add a rule to allow the IP which was being blocked, but its only a matter of time before that changes.