Configure Geographic Controls
Geographic Controls allow administrators to restrict web access based on destination country. Using this feature, you can block or allow traffic to specific countries at the account level, and apply these restrictions across selected policies. This granular control helps organizations enforce regional compliance and data residency requirements.
Use the page to configure country-based blocking rules.
Steps
Result
The geographic controls are now active and will block traffic to the selected countries based on your configuration.
Important:
- Geographic restrictions are enforced at the account level and apply across all selected policies.
- Hostname exceptions override blocked country settings. Use exceptions to permit access to critical services in otherwise blocked regions.
- The Block based on country code top-level domain toggle enables domain-level filtering (e.g., blocking .ru, .in domains) in addition to IP-based geographic filtering. Enable both for comprehensive regional access control.
- The Apply to future policies option automatically applies geographic restrictions to newly created policies, ensuring consistent enforcement across your organization.
- Test policy scope settings in a non-production environment before applying to critical policies.

