If your web application or internal dashboard only serves users in specific countries, allowing unrestricted global access unnecessarily exposes your login routes and APIs to automated botnets and brute-force scans originating from overseas bulletproof hosting providers.
In this tutorial, we are going to use Aegis—an open-source edge security gateway and reverse proxy—to configure Geo-IP Blocking and IP Reputation Denylists to drop unwanted traffic before it consumes origin server resources.
Step 1: Access the Geo-Blocking Console
- Open the Aegis Admin Console at
http://server-ip:8081. - In the sidebar under Traffic Control, select Geo-Blocking.
- Toggle on Enable Geo-IP Enforcement.
Aegis uses an embedded MaxMind GeoLite2 country database to look up client IP geographic origins in sub-microsecond in-memory evaluations.
Step 2: Choose Your Policy Mode and Countries
Select the appropriate enforcement strategy for your application:
- Denylist Mode (Most Common): Allows traffic globally, but explicitly drops connections originating from countries where you observe malicious scanning (e.g., select target countries from the world map).
- Allowlist Mode: Drops all international traffic by default, only permitting requests from specified countries (ideal for regional SaaS or compliance-constrained workloads).
- Click Apply Policy.
Aegis reloads the routing table dynamically in memory with zero downtime.
Step 3: Add Dynamic IP & CIDR Blocklists
Under Traffic Control > Blacklist / Allowlist:
- Click + Add Entry.
- Enter a specific offending IP (
203.0.113.50) or an entire malicious subnet (198.51.100.0/24). - Set an Expiration Duration (e.g., ban for 24 hours, or select permanent ban).
- Save the entry to enforce the drop immediately at the TCP/HTTP layer.
Step 4: Verify Blocked Traffic
Test from a restricted IP or verify via curl:
curl -i http://localhost:8080/
Blocked responses are rejected immediately at the edge without opening any connection to your backend servers:
HTTP/1.1 403 Forbidden
Content-Type: text/html; charset=utf-8
X-Aegis-Action: geo-blocked
Access denied: Connections from your geographic region are not permitted.
Resources
The Community Edition is free to self-host:
- Aegis GitHub Repository: https://github.com/divinelabio/aegis
- Documentation: https://divinelab.io/products/aegis/docs/traffic-control/overview

Top comments (0)