---
title: "FAQ: How do I achieve geographic separation in my network?"
canonical: "https://docs.aryaka.com/space/KNOW/1284407302/FAQ%3A%20How%20do%20I%20achieve%20geographic%20separation%20in%20my%20network%3F"
format: markdown
---
This topic includes questions users often ask about geographic separation (geoseparation) of a customer's network.

### How can I prevent my sites and users from connecting to sites in another country?

The easiest way to separate sites and users based on their geographic location (that is, their country) is to control the site-to-site topology. Each customer site is typically connected to every other site. Same for private access nodes—they are typically connected to every site. To achieve geoseparation, sites not in the same country can be disconnected from each another using MyAryaka. If this configuration needs to happen in a large scale, the Network Topology feature can be used to build a custom topology. Sites in separate countries can be grouped together into site groups. Site groups can then be configured to never connect to each another.

See [View network topology configuration](https://aryakadocs.atlassian.net/wiki/spaces/KNOW/pages/1544017) for information about configuring a custom topology.

### How can I prevent my users from accessing a server hosted in a specific country?

You can create Interzone Firewall rules with match criteria that specifies the country that you want to block and set the rule’s action to *Blackhole* (drop the traffic). The destination of outbound traffic is checked for its geographic information using our integration with MaxMind. The MaxMind database identifies which country the server belongs to and, if an Aryaka security rule match is found containing that country, the traffic is blocked by the rule’s Blackhole action. 

See the following two sections in [Basic Firewall](https://aryakadocs.atlassian.net/wiki/spaces/KNOW/pages/1275232263) for more information:

- Geolocation Discovery
- Interzone Firewall

### How can I prevent clients in a specific country from accessing resources at my sites?

You can write Interzone Firewall rules with match criteria that includes the country that you want to block and set the rule’s action to *Blackhole* (drop the traffic). The source of inbound traffic is checked for its geographic information using our integration with MaxMind. The MaxMind database identifies which country the client belongs to and, if an Aryaka security rule match is found containing that country, the traffic is blocked by the rule’s Blackhole action. 

See the following two sections in [Basic Firewall](https://aryakadocs.atlassian.net/wiki/spaces/KNOW/pages/1275232263) for more information:

- Geolocation Discovery
- Interzone Firewall