Traffic Block OutSide Canada

Joby Chacko 0 Reputation points
2026-07-02T14:53:18.4033333+00:00

I have created WAF rule that traffic allowed only from Canada, block rest of the country. Still we are getting traffic from outside countries, especially from US.

Azure Web Application Firewall

1 answer

Sort by: Newest
  1. Christos Panagiotidis 3,551 Reputation points
    2026-07-15T07:47:53.8833333+00:00

    An Allow rule for Canada does not block other countries; traffic that does not match simply continues to the next rule and may be allowed by the policy default.

    Create one high-priority custom Match rule with:

    • Match variable: RemoteAddr for the original client IP
    • Operator: GeoMatch
    • Country: CA
    • Negate condition: enabled
    • Action: Block

    Also confirm the WAF policy is enabled, in Prevention mode, and associated with the correct Front Door domain. For strict Canada-only access, allow-list handling of ZZ/unknown addresses must be intentional; permitting ZZ also permits addresses Azure cannot geolocate.

    Finally, check the WAF logs for this rule's name and block action. If requests reach the origin without a WAF log entry, they are bypassing Front Door, so restrict the origin to Front Door traffic only.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.