Skip to main content

How to block countries with a Perimeter Policy

You block traffic from specific countries with a Perimeter Policy using the Geo Guard strategy. The policy applies at the edge of your VDC, before traffic reaches your VNets.

Prerequisites

  • A VDC with at least one VNet.

Steps

  1. Open Perimeter Policies and click Create Policy.
  2. Enter a name (and an optional description). Leave the policy enabled.
  3. For the filtering strategy, choose Geo Guard (Block by Country).
  4. In Blocked Countries, select every country whose traffic you want to reject.
  5. (Optional) Under Global Exceptions, add CIDRs that must always be allowed, regardless of country.
  6. Under Scope & Rules, choose the protocol (and destination ports, for TCP or UDP) the policy applies to.
  7. Under Apply to VNets, select the VNets this policy should protect.
  8. Click Create Policy.

The policy takes effect immediately. Traffic from the blocked countries is rejected before it reaches the selected VNets.

Notes

  • To allow a specific address from an otherwise blocked country, add it under Global Exceptions.
  • Geo Guard is coarse, country-level filtering. For rules by protocol and port between your own resources, use the firewall.