The Geoblocking tab is only displayed if you had Geoblocking enabled and configured prior to Controller version 7.2.4820.Aviatrix recommends using Distributed Cloud Firewall and its integration with
ExternalGroups to monitor for threats and enable geoblocking.
If Geoblocking is disabled (from Setting > Configuration > License tab under
Feature Previews) this feature is not available. When you disable Geoblocking
you are prompted that all blocking IPs will be removed.
- Users with admin permissions can enable the feature (prior to Controller 7.2.4820 only; in 7.2.4820 and later, if the Geoblocking feature is disabled, it cannot be re-enabled).
- When you enable Geoblocking on the License tab, you are informed that a tag-based security policy will be implemented on each gateway, to deny traffic for IP addresses associated with the country. All gateways in those VPC/VNets will be blocked.
Configuring Geoblocking
Configure Geoblocking to block IP traffic coming into and coming from a country.A cloud-region IP may be blocked if that region is in the blocked country. For
example, if the public IP for your service is registered in a specific country
by the cloud and you block that country.
all_write or all_security_write
permissions.
To configure Geoblocking, use the following steps:
- In CoPilot, go to Security > ThreatIQ > ThreatIQ > Geoblocking. A list of the countries you can block and unblock displays. The IPs Observed column shows you the number of IP addresses CoPilot observed from each country when scanning Netflow records over the last seven days. If you click on a country name, you can view recent IP traffic going to or coming from that selected country in the time range you specify.
- In the Status column, toggle the switch to Blocked for each country you want to block IP traffic.
-
Click Save.
IP traffic coming into and coming from that country will be blocked on each
Aviatrix gateway.
Each time you toggle the switch for a country to block or unblock, you must click Save for your changes to take effect.