Geolocation ACL is not working

Geolocation ACL is not working

12 Reply
Re:Geolocation ACL is not working
2025-04-23 19:28:43

  @Matva 

 

Yes

 

Main: ER8411 x1, SG3428X x1, SG3452 x1, SG2428LP x1, SG3210 x1, SG2218P x1, SG2008P x3, ES208G x1, EAP650 x6 Remote: ER7206 v2 x1, ER605 v2 x3, SG2008P x2, EAP650 x2, ES205G x1 Controller: OC300
  0  
  0  
#13
Options
Re:Geolocation ACL is not working
2025-04-28 18:40:28 - last edited 2025-04-28 18:51:33

  @GRL 

Thanks for the confirmation.

 

However, that doesn't seem to fully block everything.

 

Just today, I had a blocked attack on my NGINX:

 

time="2025-04-28T05:17:07+02:00" level=info msg="(localhost/crowdsec) crowdsecurity/http-sensitive-files by ip 193.24.123.65 (RU/200593) : 4h ban on Ip 193.24.123.65"

 

RU has both an ACL Deny for the Management page, as well as for Ipgroup_any. Yet it still makes it through my router onto my NGINX server.

 

So either the geo-matching is not done 100% correctly, or the ACL doesn´t seem to work.

 

Edit: Nevermind, my order is off. The Gateway Management Deny should be on top. Currently, it was at the bottom because I created it last.

It would be a really nice-to-have if blocked attempts got logged somewhere. (I haven´t enabled IPS/IDS on the ER707-M2 because it completely tanks the speed down to 200Mbps from 1Gbps).

  0  
  0  
#14
Options