11-15-2021 10:11 AM
We are thinking of using Firepower's Geolocation database to block all incoming IP traffic from both China and Russia. My organization has no business dealing with any of those countries. That is not to say we do not see any traffic already blocked from both of those countries. We get lots of "dropped traffic from both in our logs. Has anyone else tried using this as a basis for a rule in their access policies? Are there any drawbacks to doing this?
11-15-2021 11:36 AM
I do not see any issue here, that is the purpose of the FW it should be the job as mentioned.
11-15-2021 11:47 PM
It's a common use case and I've used it successfully for multiple customers for both outgoing and incoming rules.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide