Actions
Bug #17027
openGeoIP alias generated via ThreatGate fails to match traffic for valid country IPs
Status:
New
Priority:
Normal
Assignee:
-
Category:
ThreatGate
Target version:
-
Start date:
Due date:
% Done:
0%
Estimated time:
Release Notes:
Default
Affected Plus Version:
26.07
Affected Architecture:
4100
Description
Summary:
An IP alias created for a specific country using ThreatGate does not match incoming traffic on the WAN interface, despite the source IP being correctly geolocated in the MaxMind database.
Steps to Reproduce
Navigate to ThreatGate and create a new country-based list.
Generate a firewall Alias from this selection.
Create a WAN firewall rule using the generated GeoIP Alias as the Source.
Attempt to connect from an IP located within the selected country.
Observe that the firewall rule fails to match the incoming connection.
Expected Result
Traffic originating from the target country's IP should match the firewall rule that references the ThreatGate GeoIP alias.
Actual Result
Traffic does not match the rule.
Additional Context & Isolation Steps
Rule Logic Test: Removing the source alias restriction from the WAN rule allows the connection to succeed immediately (confirming ports, routing, and NAT are working correctly).
IP Verification: Verified the source IP address directly on MaxMind's official tool, confirming it is correctly registered under the expected country code.
No data to display
Actions
Also available in: Atom