---
title: "Geoblocking"
canonical: "https://docs.aryaka.com/space/KNOW/1275330624/Geoblocking"
format: markdown
---
Geoblocking— a technology that can block web traffic from entire countries —can be an effective way to stop hackers from attacking enterprise networks. Geoblocking blocks network connections based on geographic location—information it obtains from IP addresses. Cybercrime is a growing world-wide phenomenon, yet the majority of attacks originate from a few main countries.  Aryaka has introduced geoblocking in its Aryaka Network Access Point (ANAP) devices that can block all traffic from entire countries or continents. It can also be used to ensure compliance and to stop hackers from attacking their businesses. In addition to blocking inbound traffic, geoblocking can also block outbound traffic to specific countries. Aryaka uses  MaxMind , a leading provider of geographic IP intelligence and online fraud detection tools.  MaxMind covers 99.9999% of IP addresses in use worldwide.  They created a database of IP blocks assigned to countries and continents and typically updates it every two days. Aryaka checks for updates every 24 hours. For more information about MaxMind service updates, see  GeoIP2 Databases and Services  (at MaxMind.com). Enable geoblocking Aryaka's provisioning and support teams perform a simple process to enable geoblocking functionality on the ANAPs deployed at your sites. Aryaka provides the following spreadsheet-based SmartServices Geoblocking Provisioning Form that you and your IT team can complete.  The following table describes the fields on the form and the information required for each of them. Field Description Rule Name A descriptive name that includes how and where the rule is used. This rule name appears in the MyAryaka UI in various Config (Configuration) and Monitor pages. New/Existing/Delete Select one of the following: New—If you are requesting the addition of a rule to your configuration. Existing—If you are requesting an edit to an existing rule in your configuration. Delete—If you are requesting the deletion of a rule from your configuration. Apply Rule to Sites List one or more sites to which the configured rule is applied. Select All to apply this rule to apply to all sites with ANAPs, otherwise provide a comma-separated list of sites to be updated. Block Traffic for Direction Select Inbound, Outbound, or Inbound & Outbound depending on which direction the traffic must be blocked. Countries to Block Select one or more countries to block from the drop-down list. Aryaka's provisioning team uses your responses in this template to enable geoblocking on all of the requested sites. Aryaka support contacts you to schedule a time for the upgrade, and performs the required ANAP and site configuration within the service period defined by your existing support SLAs. Change requests initiated using MyAryaka is currently in the product roadmap. Geoblocking policies and traffic processing Geoblocking is implemented as WAN Routing policies or internet policies, depending on the specific types of rules you requested and also depending on the direction of the traffic that must be blocked. There are two types of internet policies: Interzone Firewall policies process traffic destined for local zones, while Internet Routing policies process traffic destined for an unknown destination.  Inbound traffic This section and the following diagram describe the processing of traffic sourced from a public zone or cloud zone destined for the LAN: If the destination is found in the local LAN subnet routing table, the traffic encounters the Interzone Firewall policies that permit or deny this traffic. If no route match is found for the destination, the traffic encounters the Internet Routing policies. Geoblocking and Interzone Firewall policies Inbound internet traffic is considered a match by the Interzone Firewall policies if the destination is on one of the the local subnets. For geoblocking to block inbound traffic to a site from any of the named countries, Aryaka customer support can create  traffic match rules  that match  source  IPs of specific countries and then associate the traffic match rule to an Interzone Firewall policy.  Outbound traffic In general, observe the following outbound traffic best practices: Use WAN Routing policies if you want to apply geoblocking in the outbound direction from a specific LAN zone.  Use Internet Routing policies if you want to apply geoblocking in the outbound direction to specific zones. The following diagram describes the processing of traffic sourced from a VPN or DMZ zone destined to the internet. This traffic first encounters zone-specific WAN Routing policies, then Interzone Firewall policies, and then Internet Routing policies. WAN Routing policies WAN Routing policies control the LAN-side perimeter of the ANAP. These rules are written and applied per LAN zone. WAN Routing policies enable you to control the traffic as follows: Deny it and send an  ICMP Unreachable  response Forward it to an interface Route it to a remote site Blackhole it The default WAN Routing policy for a VPN zone searches for a route in the route tables from various networks in the zone and router (additional WAN Routing policies can be written for your sites to meet your hybrid WAN needs). If a match is found, it uses the longest prefix match.   If no match is found, the traffic is processed by Interzone Firewall policies.   Because the destination in the geoblocking use case is on the internet, the traffic does not encounter any Interzone Firewall policies. Instead, it is processed by the Internet Routing policies. To block traffic to a specific set of countries, you can configure WAN Routing policies if they are meant to override the existing WAN Routing policies. For example, if Policy A matches the traffic you want to block, and Policy B needs to be implemented to override it, then request that Policy B be configured. Aryaka customer support responds to this request by creating traffic match rules that match  destination  IPs of  specific  countries and then associate the traffic match rule to a WAN Routing policy. If you want to block  all  traffic to specific countries—independent of source zones—configure Internet Routing policies instead of WAN Routing policies.  Internet Routing policies Internet Routing policies are default policies that apply to outbound internet traffic. Internet Routing policies enable you to control the traffic as followings: Forward it to an interface (cloud security connector, internet interfaces, and so on) Blackhole it Internet Routing policies are encountered by traffic from all LAN zones. The default Internet Routing policy forwards all outbound traffic to the default internet interface. To block traffic to a specific set of countries, you can request Internet Routing policies if they are meant to override the existing Internet Routing policies. Aryaka customer support responds to this request by creating traffic match rules that match  destination  IPs of  specific  countries and then associating the traffic match rule with an Internet Routing policy. Aryaka ANAP updates  Aryaka checks the MaxMind database every 24 hours for any updates to the geolocation datasets. Depending on the nature of the update, Aryaka either applies changes to the datasets immediately using an automated procedure or reviews it before applying the update. Consider the following examples: Automatic update—Applied when new prefixes get added to a blocked country. Review process—If you have geoblocking enabled for Country X, and a geographic event results in that country splitting into two countries—X1 and X2—the update includes datasets for X1 and X2. Our system recognizes this delta and immediately flags it for manual review. After review, we contact you to determine if you want to block X1, X2, or both. Depending on your response, we update the ANAPs with the appropriate datasets. We estimate two to four weeks for this review and update process.  Note the following: Aryaka does not currently support online lookup for associating an IP with a country. Aryaka does not currently support on-demand listing of all CIDRs for a specific country. Aryaka currently cannot withhold updates from being applied or selectively apply updates for specific customers. Aryaka does not support rollbacks or back outs—we only support forward updates in MyAryaka for all features. You can view the change history using  Order management . View geoblocking policies in MyAryaka MyAryaka enables you to view, configure, and monitor most functionality provided in your Aryaka SmartServices subscription. Geoblocking is enabled for you by Aryaka support based on the returned provisioning form, but after the configuration is complete, the associated policies, their rules, and policy details can be viewed in MyAryaka. To view WAN Routing policies for a site Log in to MyAryaka. The Home page appears. Click  Sites  in the left navigation pane. The Sites page appears. Select the site whose policies you want to view. The < siteName > page appears. In the Site Information pane, click  View  on the Site Information tile. The selected site's details page appears. By default, the Site Information tab page is displayed. Click the  Advanced Settings  icon, and then click the  WAN Routing  tile. The WAN Routing page appears. It displays the existing zones. Click a zone to display the zone's details page. It contains the WAN Routing policy table for the selected zone, which lists all existing policies.  (Optional) Click a policy name to display the policy's details page. See  Create site-level WAN Routing policies  for details.    To view Interzone Firewall policies for a site Log in to MyAryaka. The Home page appears. Click  Sites  in the left navigation pane. The Sites page appears. Select the site whose policies you want to view. The < siteName > page appears. In the Site Information pane, click  View  on the Site Information tile. The selected site's details page appears. By default, the Site Information tab page is displayed. Click the  Advanced Settings  icon, and then click the  Internet Policies  tile. The Internet Policies page appears. It displays the existing Interzone Firewall policies. (Optional) Click a policy name to display the policy's details page. See  Create internet policies  for details.  To view Internet Routing policies for a site Log in to MyAryaka. The Home page appears. Click  Sites  in the left navigation pane. The Sites page appears. Select the site whose policies you want to view. The < siteName > page appears. In the Site Information pane, click  View  on the Site Information tile. The selected site's details page appears. By default, the Site Information tab page is displayed. Click the  Advanced Settings  icon, and then click the  Internet Policies  tile. The Internet Policies page appears. It displays the existing Internet Routing policies. (Optional) Click a policy name to display the policy's details page. See  Create internet policies  for details.  Cost Geoblocking is included as part of the Aryaka site license. There are no additional costs for this feature. In this topic Related topics Create site-level WAN Routing policies   Create internet policies Monitor LAN zone policies GeoIP2 Databases and Services  ( MaxMind.com ) View an order