Location filter also on outgoing connections

I would like to avoid connections to certain countries.
How can I solve this.


The location filter blocks also the ack to the syn packet so you already cannot establish a connection if the filter is enabled.

This can’t be entirely true as I can still FTP to blocked countries with my servers.
The syn packet does not seem to be enough here.

Is not for green the connection to red basically allowed.

Have you tried such rule?

If the rule is incorrect, someone please fix me.

