> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# General Guidelines for Migrating from Legacy ThreatIQ and Geoblocking to Distributed Cloud Firewall

> If you configured ThreatIQ and/or Geoblocking, you can upgrade to Distributed Cloud Firewall (DCF) and its ExternalGroup functionality. This migration requires Controller 8.1 or greater.

If you configured ThreatIQ and/or Geoblocking, you can upgrade to Distributed
Cloud Firewall (DCF) and its ExternalGroup functionality. This migration
requires **Controller 8.1 or greater**. DCF-powered Threat and Geo functionality
provides more granular configuration and can be pushed to any DCF-supported
gateways.

<Warning>
  You cannot use ThreatIQ and/or Geoblocking in conjunction with DCF and
  ExternalGroups.
</Warning>

<Note>
  ExternalGroups built from the Threat Feeds and Countries feeds are maintained
  by Aviatrix and update automatically (roughly daily). You do not need to
  download or paste IP lists by hand to keep them current.
</Note>

<Note>
  These are generalized guidelines only. Reach out to [Aviatrix
  Support](https://support.aviatrix.com) for assistance with this migration.
</Note>

## Upgrading ThreatIQ to Threat Feed ExternalGroups

ThreatIQ is located at Security > ThreatIQ.

In DCF, threat protection is delivered through the **Default ThreatGroup**, an
ExternalGroup fed by the Aviatrix Threat Feed. The feed updates automatically
(roughly daily) and already covers the majority of malicious IPs that ThreatIQ
previously matched, so you do not need to recreate that list manually.

<Note>Currently there is no Custom ThreatGroup creation.</Note>

* Any VPC/VNets that are not currently protected on the ThreatIQ > Configure
  Exclusion List for VPCs page should have a SmartGroup configured that excludes
  those VPC/VNets from threat analysis.

<img src="https://mintcdn.com/aviatrix-14b37c43/MwMAaVUDwCmP6YfF/images/guides/security/threatiq-migrate-2.png?fit=max&auto=format&n=MwMAaVUDwCmP6YfF&q=85&s=4ad01f11865ee68efb9be552526c6dd0" alt="" width="1924" height="1548" data-path="images/guides/security/threatiq-migrate-2.png" />

* For any custom threats you have configured on the ThreatIQ > Custom Threat
  list, create a SmartGroup named Custom Threat List that contains those threat
  IPs. Use this SmartGroup alongside the Default ThreatGroup so DCF rules cover
  both the Aviatrix-managed threat feed and your custom additions.

<img src="https://mintcdn.com/aviatrix-14b37c43/MwMAaVUDwCmP6YfF/images/guides/security/threatiq-migrate-3.png?fit=max&auto=format&n=MwMAaVUDwCmP6YfF&q=85&s=28321a7883830f4ce434e53c0dec9e45" alt="" width="2218" height="1020" data-path="images/guides/security/threatiq-migrate-3.png" />

<a href={"/docs/enterprise/" + "10.1" + "/concepts-architectures/components/dcf/smartgroups-about"}>Creating a SmartGroup</a>

* Check if ThreatIQ > Advanced Settings is set to Append or Prepend. This
  determines where new ThreatIQ firewall rules were added. When you create your
  threat-based DCF rules, Aviatrix recommends that these be at the top of the
  set of rules.

<img src="https://mintcdn.com/aviatrix-14b37c43/MwMAaVUDwCmP6YfF/images/guides/security/threatiq-migrate-1.png?fit=max&auto=format&n=MwMAaVUDwCmP6YfF&q=85&s=7202ccb35d985798bbaf6f65719b239c" alt="" width="2014" height="544" data-path="images/guides/security/threatiq-migrate-1.png" />

## Upgrading Geoblocking to Country ExternalGroups

With ExternalGroups > Countries, you have the choice to block specific IPs to
and from a country.

In DCF, Geoblocking is delivered through Country ExternalGroups built from the
Aviatrix-managed Countries feed. Aviatrix keeps the per-country IP membership up
to date (the feed refreshes roughly daily), so you do not need to download or
maintain country IP lists yourself. Recreate your blocked-country selection by
creating an ExternalGroup of type **Countries** rather than building a
SmartGroup from a downloaded IP list.

1. Note the countries you have blocked on the Security > ThreatIQ > Geoblocking
   tab.

   <img src="https://mintcdn.com/aviatrix-14b37c43/mOZ0lmP7pRPIryx3/images/guides/security/geoblocking-list.png?fit=max&auto=format&n=mOZ0lmP7pRPIryx3&q=85&s=db05e766f4f0c1175ae54710604ebce7" alt="" width="1232" height="1302" data-path="images/guides/security/geoblocking-list.png" />

2. <a href={"/docs/enterprise/" + "10.1" + "/reference/externalgroup-about"}>Create a Country ExternalGroup</a>
   that selects the same countries. The ExternalGroup is fed automatically by
   the Aviatrix Countries feed, so the IP membership stays current without
   manual updates.

## Creating DCF Rules

Create DCF rules that encompass the threat and Country information above.

<Note>
  If ThreatIQ did not have any exception VPCs, ignore Rules 1 and 2.

  If you configured the Custom Threat List in ThreatIQ, add the Custom Threat List
  SmartGroup created above to Rule 3 as a Source, and to Rule 4 as a Destination.
</Note>

If ThreatIQ had exception VPCs create the following DCF rules:

| Rule                                   | Description                                                                                                                   |
| -------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------- |
| Rule 1: Threat Exception Inbound Rule  | the Source Group is the ThreatGroups database and the Destination Group is the ThreatIQ Exclusion VPC list. Action is Permit. |
| Rule 2: Threat Exception Outbound Rule | Source Group is the Threat Exclusion VPCs SmartGroup and the Destination is the ThreatGroups database. Action is Permit.      |

| Rule                                    | Description                                                                                                                                                                                                            |
| --------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Rule 3: Inbound Threat Protection Rule  | the Source Group is the <a href={"/docs/enterprise/" + "10.1" + "/reference/externalgroup-about"}>Default ThreatGroup</a> (under ExternalGroups > Threat Feeds) and the Destination Group is Anywhere. Action is Deny. |
| Rule 4: Outbound Threat Protection Rule | Source Group is Anywhere and the Destination is the <a href={"/docs/enterprise/" + "10.1" + "/reference/externalgroup-about"}>Default ThreatGroup</a> (under ExternalGroups > Threat Feeds). Action is Deny.           |

Create these geo-based (Country ExternalGroups) DCF rules:

| Rule                            | Description                                                                                                             |
| ------------------------------- | ----------------------------------------------------------------------------------------------------------------------- |
| Rule 5: Inbound Geo Block Rule  | Source Group is the Country ExternalGroup that contains the blocked countries; Destination is Anywhere. Action is Deny. |
| Rule 6: Outbound Geo Block Rule | Source Group is Anywhere; Destination is the Country ExternalGroup that contains the blocked countries. Action is Deny. |

## Final Steps

Contact [Aviatrix Support](https://support.aviatrix.com) for final steps
(including disabling ThreatIQ and Geoblocking) and testing the configuration.

## Related Topics

* <a href={"/docs/enterprise/" + "10.1" + "/guides/security/threatiq"}>
    Blocking Known Threat IP Traffic using ThreatIQ
  </a>
* <a href={"/docs/enterprise/" + "10.1" + "/guides/security/geoblocking"}>Blocking Traffic from Countries using Geoblocking</a>
* <a href={"/docs/enterprise/" + "10.1" + "/reference/externalgroup-about"}>Managing the Relationship Between Feeds and ExternalGroups</a>
* <a href={"/docs/enterprise/" + "10.1" + "/reference/dcf/dcf-configuring#creating-distributed-cloud-firewall-rules"}>Creating Distributed Cloud Firewall Rules</a>
