SonicOS 8 Rules and Policies for Classic Mode

Table of Contents

Settings

The Settings page in POLICY | Rules and Policies > Settings > GEO-IP | Settings provides a group of settings that can be configured for Geo-IP Filtering. Several of the settings have (information) icons next to them that give screen tips about that setting. The GEO-IP Filter feature allows administrators to block connections to or from a geographic location based. SonicWall appliances use IP addresses to determine the location of the connection.

Policy-based Settings

To enable Policy-based settings

  1. When Block connections when Geo IP database is not downloaded and rules need Geo locationis enabled, all connections are dropped when the Geo-IP map database is not downloaded and your policies still need country details.
  2. When Bypass decryption when Geo IP database is not downloaded and policies need Geo location is enabled, all connections bypass decryption when the Geo-IP map database is not downloaded and your policies still need country details.

Global Settings

To enable Global settings

  1. Enable Custom List: This option is disabled by default. Custom lists are sometimes used to correct a false country assignment for an IP address. When the checkbox is selected, Override Firewall Countries by Custom List is made available.

  2. Override Firewall Countries by Custom List: This selection is only available when Enable Custom List is enabled. It allows your custom list to override the firewall list where there are differences. Unless you select this Override, the firewall list takes precedence, even when you have enabled a custom list.

System Management Traffic

To manage Traffic

  1. Block Country: Please select the country group from which management traffic for HTTPS/Ping/SNMP/SSH (configured per interface in Network > Interfaces page) to be blocked.

  2. Block all Unknown Countries: Please enable/disable ability to block/allow management traffic for HTTPS/Ping/SNMP/SSH (configured per interface in Network > Interfaces page) for IP addresses that are unclassified.

  3. Click Accept to save your settings.