You can create Geo IP policies from the Geo IP policies page.
You must have a Sky ATP account to receive Geo IP feeds. Make sure you configure the necessary steps for Sky ATP before creating a Geo IP policy.
Geo IP filtering is a useful tool when you are experiencing certain types of attacks, such as DDOS from specific geographical locations.
If you are using Sky ATP without Policy Enforcer, you must select your Geo IP policy as the source and/or destination of a firewall rule to apply it.
To create a Geo IP policy:
Table 308: Fields on the Geo IP Policy Page
Name | Enter a unique string that must begin with an alphanumeric character and can include underscores; no spaces allowed; 63-character maximum. |
Description | Enter a description; maximum length is 1024 characters. You should make this description as useful as possible for all administrators. |
Countries | Select the check box beside the countries in the Available list and click the > icon to move them to the Selected list. The countries in the Selected list will be included in the policy and action will be taken according to their threat level. |
Block Traffic | Choose what traffic to block from the selected countries. Incoming traffic, Outgoing traffic, or Incoming and Outgoing traffic. (Policy Enforcer only) |
Log Setting | Choose to log all traffic or only blocked traffic. (Policy Enforcer only) |
Once you have a Geo IP policy, you assign it to one more groups (Policy Enforcer only):
To assign a Geo IP policy to a group or groups:
© 2018 Juniper Networks, Inc. All rights reserved