Help Center/ Web Application Firewall/ FAQs/ Protection Rules/ How Do I Allow Requests from Only IP Addresses in a Specified Geographical Region?
Updated on 2025-01-17 GMT+08:00

How Do I Allow Requests from Only IP Addresses in a Specified Geographical Region?

If you allow only IP addresses in a region to access the protected domain name, for example, only IP addresses from Shanghai can access the protected domain name, take the following steps:

Geolocation access control rules have higher priority than built-in WAF rules. If you configure a geolocation access control rule to allow IP addresses from a certain location, WAF then forwards traffic from those IP addresses without performing basic web protection checks.

  1. Log in to the management console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. Click in the upper left corner and choose Web Application Firewall under Security & Compliance.
  4. In the navigation pane on the left, choose Policies.
  5. Click the name of the target policy to go to the protection configuration page.
  6. In the upper left corner above the Geolocation Access Control list, click Add Rule.
  7. Add a geolocation access control rule: Select Shanghai for Geolocation and select Allow for Protective Action.

    Figure 1 Selecting Allow for Protective Action

  8. In the upper left corner above the Precise Protection rule list, click Add Rule. Configure a precise protection rule to block all requests.

    Figure 2 Blocking all access requests