Question
Deny all before allow policy
I' m trying to block specific regions of the world from accessing our public services. Particularly, I' m testing access from China using http://www.websitepulse.com/help/testtools.china-test.html -- so far I added a policy that denies all sources orginating from China. That policy sits before our allow policy for http access to our internal web server. That metod doesn' t seem to work. I have to lock down our allow policy to only allow like US/Canada/Mexico sources in order for the access from China to be restricted. I was hoping adding a policy to deny all international source addresses before our allow policy would do the trick - is that not doable?
