Website Migration Notice: SafePoint is now operated by CyberServal.Learn more →
DiscussionSLA

Help custom rule

Published 8 months ago

# SafeLine WAF
# ❓ question

Published 8 months ago

profile_photo

Omahku

Updated 8 months ago

0

I created a custom rule with the expectation of blocking all connections to the e-learning application except those coming from Indonesia’s geolocation and local IPs. However, after testing, traffic from Indonesia’s geolocation can access it, but traffic from local IPs gets blocked.
Capture.PNG

profile_photo

Carrie

Updated 8 months ago

You sure the IP you tested is included in the local IP group?
How large is this IP group?
If the IP group contains too many entries, it might cause performance issues. You can try CIDR notation instead.

profile_photo

Omahku

Updated 8 months ago

0

this my IP group
1.PNG

profile_photo

Omahku

Updated 8 months ago

0

image.png

profile_photo

Carrie

Updated 8 months ago

Please check Detail and send the screenshot.
And which SafeLine version are you using?
image.png

profile_photo

Omahku

Updated 8 months ago

0

image.png

profile_photo

Omahku

Updated 8 months ago

0

image.png

profile_photo

Carrie

Updated 8 months ago

0

Please try restarting those SafeLine containers and see if it's still blocked:
docker restart safeline-detector
docker restart safeline-mgt
docker restart safeline-fvm

profile_photo

Omahku

Updated 8 months ago

0

Is the rule I created correct?

profile_photo

Carrie

Updated 8 months ago

Yes. Our engineer also saw it and thought it was set correctly

profile_photo

Omahku

Updated 8 months ago

0

Oke