I use this setup [1] on my servers. IPs are mapped to countries using Maxmind's GeoLite2 database. Linux's Tcp Wrappers are configured to block access for all IPs that aren't in my country.
A custom fail2ban jail adds all IPs that get blocked by the Tcp Wrappers to the system's firewall.