Dev.to Security πŸ” Cybersecurity πŸ‘ 0 πŸ“– 1 min read

How to Block Malicious Traffic by Country

If your web application or internal dashboard only serves users in specific countries, allowing unrestricted global access unnecessarily exposes your login routes and APIs to automated botnets and brute-force scans origi

How to Block Malicious Traffic by Country

If your web application or internal dashboard only serves users in specific countries, allowing unrestricted global access unnecessarily exposes your login routes and APIs to automated botnets and brute-force scans originating from overseas bulletproof hosting providers.

In this tutorial, we are going to use Aegisβ€”an open-source edge security gateway and reverse proxyβ€”to configure Geo-IP Blocking and IP Reputation Denylists to drop unwanted traffic before it consumes origin server resources.

Aegis Geo-Blocking Traffic Control

Step 1: Access the Geo-Blocking Console

  1. Open the Aegis Admin Console at http://server-ip:8081.
  2. In the sidebar under Traffic Control, select Geo-Blocking.
  3. Toggle on Enable Geo-IP Enforcement.

Aegis uses an embedded MaxMind GeoLite2 country database to look up client IP geographic origins in sub-microsecond in-memory evaluations.

Step 2: Choose Your Policy Mode and Countries

Select the appropriate enforcement strategy for your application:

  1. Denylist Mode (Most Common): Allows traffic globally, but explicitly drops connections originating from countries where you observe malicious scanning (e.g., select target countries from the world map).
  2. Allowlist Mode: Drops all international traffic by default, only permitting requests from specified countries (ideal for regional SaaS or compliance-constrained workloads).
  3. Click Apply Policy.

Aegis reloads the routing table dynamically in memory with zero downtime.

Step 3: Add Dynamic IP & CIDR Blocklists

Under Traffic Control > Blacklist / Allowlist:

  1. Click + Add Entry.
  2. Enter a specific offending IP (203.0.113.50) or an entire malicious subnet (198.51.100.0/24).
  3. Set an Expiration Duration (e.g., ban for 24 hours, or select permanent ban).
  4. Save the entry to enforce the drop immediately at the TCP/HTTP layer.

Step 4: Verify Blocked Traffic

Test from a restricted IP or verify via curl:

curl -i http://localhost:8080/

Blocked responses are rejected immediately at the edge without opening any connection to your backend servers:

HTTP/1.1 403 Forbidden
Content-Type: text/html; charset=utf-8
X-Aegis-Action: geo-blocked

Access denied: Connections from your geographic region are not permitted.

Resources

The Community Edition is free to self-host:

πŸ“° Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.