Monitor Geolocation Activity
Geolocation of Allowed Connections
In Fireware Web UI you can use the Geolocation Dashboard to monitor the geographic location of connections allowed through the Firebox and to look up the geographic location of an IPv4 or IPv6 address. The Geolocation Dashboard does not show connections that were blocked based on the geographic location of the source or destination. For more information about the Geolocation Dashboard, see Geolocation Dashboard.
From Fireware Web UI and Firebox System Manager, you can see Geolocation statistics, which include the total number of source and destination IP addresses that were scanned, and the number of connections blocked based on source or destination IP address. You can also see the version information of your Geolocation database and manually update the database to the latest version.
Select Dashboard > Subscription Services.
Select the Subscription Services tab.
For more information about these statistics, see Geolocation Statistics.
Geolocation Log Messages
Your Firebox generates a log message when Geolocation blocks a connection based on the geographic location of the source or destination. Geolocation log messages indicate whether the connection was blocked based on the geographic location of the connection source or destination, and include the country abbreviation. For example, this log message shows a connection denied based on the geographic location of the destination:
2016-10-04 14:16:13 Deny 10.0.1.2 22.214.171.124 50802 80 1-Trusted 0-External blocked sites (geolocation destination) 52 127 (Internal Policy) proc_id="firewall" rc="101" msg_id="3000-0148" tcp_info="offset 8 S 1489658951 win 32" geo="geo_dst" geo_dst="IRL"
When Geolocation is enabled, all traffic log messages show the destination or source of the connection external to the Firebox.
In Traffic Monitor, you can filter the log messages for information about connections blocked by Geolocation.
- To see log messages for all connections blocked by Geolocation, search for: geo=
- To see log messages for connections blocked based on the source, search for: geo="geo_src"
- To see log messages for connections blocked based on the destination, search for: geo="geo_dst"
For more information about how to see and filter log messages in Fireware Web UI, see Traffic Monitor.
For more information about how to see and filter log messages in Firebox System Manager, see Device Log Messages (Traffic Monitor).