Sure their packets will still hit your router, but if they are dropped immediately at least you're not wasting a syn-ack on them.
Sure their packets will still hit your router, but if they are dropped immediately at least you're not wasting a syn-ack on them.
Keep in mind that this should be paired with an ASN blacklist - MaxMind also has an ASN mmdb for convenience - because IP address to country maps are almost entirely self-declared[0].
For example, Tencent (AS132203), which you almost certainly want to block, has ranges in 73 different countries per [1].
Thanks in advance.
Your firewall vendor should supply you with country lists, just select the known bad ones and drop their traffic. If you have a consumer grade router, you will probably have to configure the blocklists manually.
Eventually, my lets encrypt cert expired and it turns out certbot is run from USA, so the auto renewal failed me.
ISPs sometimes do trade IPv4 blocks and countries to which it belongs do change occasionally. That can become a problem if you were like literally Netflix and someone few nation states over started an ISP.
Here is a "simplified" version in various formats.
Why not just block all the inbound connections you don't need? Is there a particular reason your firewall policy needs to be xenophobic?