How to block countries with a Perimeter Policy
You block traffic from specific countries with a Perimeter Policy using the Geo Guard strategy. The policy applies at the edge of your VDC, before traffic reaches your VNets.
Prerequisites
- A VDC with at least one VNet.
Steps
- Open Perimeter Policies and click Create Policy.
- Enter a name (and an optional description). Leave the policy enabled.
- For the filtering strategy, choose Geo Guard (Block by Country).
- In Blocked Countries, select every country whose traffic you want to reject.
- (Optional) Under Global Exceptions, add CIDRs that must always be allowed, regardless of country.
- Under Scope & Rules, choose the protocol (and destination ports, for TCP or UDP) the policy applies to.
- Under Apply to VNets, select the VNets this policy should protect.
- Click Create Policy.
The policy takes effect immediately. Traffic from the blocked countries is rejected before it reaches the selected VNets.
Notes
- To allow a specific address from an otherwise blocked country, add it under Global Exceptions.
- Geo Guard is coarse, country-level filtering. For rules by protocol and port between your own resources, use the firewall.