DGardiner Posted April 27, 2021 Posted April 27, 2021 Anyone have any info on how this works? theres no documentation on the KB/Release Notes Ive ticked everything but the UK - Is this firewall in general? the smoothwall portal? Smoothwall admin? ssh?
Joeloman Posted April 28, 2021 Posted April 28, 2021 Today only firewall, does not stop responses from e.g. browser. The traffic is only ignored (Dropped), no logs to save power in an attack. The geo list comes from a well-known company that has few errors in many tests. We have not tested but it should block Smoothwall admin and ssh if the traffic comes from blocked countries or regions. 1
highsky Posted June 1, 2021 Posted June 1, 2021 (edited) Tested From version 46 + Under Network > Firewall > GeoBlocking or search for it Select the continents or countries to block, carefully as the collapse - expand icon is close to Select all, save the changes. Result, tested with a VPN: Site hosted services, like RDS and web server are not accessible from the selected countries. Any side effects to be aware off? Thanks Edited June 1, 2021 by highsky
free780 Posted June 1, 2021 Posted June 1, 2021 What happens if the source IP is v6? Or a user goes to a banned country (unlikely at the moment) and needs to access services?
DGardiner Posted June 1, 2021 Author Posted June 1, 2021 What happens if the source IP is v6? Or a user goes to a banned country (unlikely at the moment) and needs to access services? Smoothwall doesnt do v6 yet i dont think. As for the latter thats your issue to manage. As for unintended side effects, stopped my letsencrypt renewals working - Presumably the verification servers are not in the uk 1
highsky Posted June 3, 2021 Posted June 3, 2021 (edited) A workaround will be DNS validation, not tested. On the same front, I had to whitelist the Impero licensing IP. Banned countries? I already have the Azure conditional access enabled for a few months, for the majority of them. They know by now how to send an email to support. We then add an exception for X time for a user in Azure or a country on the Firewall, the second will be less likely to be requested. Versus having everything open, this implies that the workload is manageable. Probably there are better solutions too. Edited June 3, 2021 by highsky
taz Posted October 8, 2025 Posted October 8, 2025 Just picking this thread up - what worked best - did you geoblock all countries and just open up the UK? Were there any side effects please?
Joeloman Posted October 8, 2025 Posted October 8, 2025 Side effects that may be good to consider are, for example, when the staff is traveling. Since the blocking applies to all services that you have internally, such as VPN, telephone exchange, various other services.. For various fixed services, it is no problem to make exceptions as long as you know the IP addresses. Good to know is that Turkey in this system is counted as Asia and not Europe. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now