As I understand it, Cisco firewalls apply the geo blocking to traffic passing trough them, not traffic passing to them. Therefore the IDS/IPS will see the traffic, even if it can't go anywhere. At a recent job, I placed a pair of Cisco firewalls being used as VPN concentrators, behind another pair that are the main edge devices with a geoblocking rule on them. This was so that the blocked countries could not attack the VPNs so easily. It does seem to have worked and the attacks have all but stopped now.
... View more