Block via GeoIP Alias. You can allow SMTP globally and then deny USA
Hi Julien,Point your MX record to a mail filter in the DMZ and don't IDS that traffic. Something like https://efa-project.org/Bart...
WAN2 is a Virtual IP and sitting on which physical interface?Geoblocking with IPS is not the right way doing things (since 17.7.x). Use GeoIP Alias, it's easier and more powerful, just try it.
https://docs.opnsense.org/manual/aliases.htmlThen set up a firewall rule with this alias.
Yes, it's way more flexible and delivers better performance.