Hello all,
I have GeoIP setup and active with Maxmind. I have setup a number of countries that I should just drop. I have Suricata active also, in IDS mode, and I am seeing a number of hits from countries that are in my GeoIP list. Why am I seeing these, as I thought GeoIP would just drop the traffic if its part of the countries I have in my list.
Thanks,
Steve
QuoteI have setup a number of countries that I should just drop
This means you've created an alias with selected countries?
Then you can add firewallrule(s) using that/those alias(es) to block traffick.
Ok that makes sense...then what is the need for GeoIP?