However, I was originally unable to download the security certificate they require until I turned off Geo-IP blocking on our SonicWall TZ-300. I would definitely go for the established/related approach, because whitelisting is way to static, IMHO. All rights Reserved. TZ 370 IPSec Site2Site VPN not working - SonicWall Community I have tried the following without success. I'm not sure if I set those up right. Apologize for the inconvinience. As a countercheck I'll (against my better knowledge) allow the USofA via GeoIP. and you'll get a list of all the countries, broken out by hostile or non-hostile hosts, and the details of the communication with those hosts. sonicwall policy is inactive due to geoip license. The information we provide includes locations (whenever possible) in case you want to pay a visit. SonicOSX 7 Rules and Policies - Geo-IP - SonicWall Our users fortunately stay in the states and Canada so I can block the whole world except the US and Canada if I have to. r/sonicwall on Reddit: Minimum subscription required to use Geo-IP NFTs Simplified > Uncategorized > sonicwall policy is inactive due to geoip license. Security_Services_GeoIP - SonicWall Online Help If you're curious to see what countries/hosts your devices are communicating with, you can upload a sonicwall log file into the freeOTX ThreatFinder tool (http://www.alienvault.com/open-threat-exchange/dashboard#/threats/top Opens a new window)and you'll get a list of all the countries, broken out by hostile or non-hostile hosts, and the details of the communication with those hosts. Navigate to POLICY | Security Services | Geo-IP Filter. But you send to screenshot is same everything. The Botnet Filtering feature allows administrators to block connections to or from Botnet