DocsCountry blocking

Country blocking

Drop traffic from chosen countries at the server firewall, for websites only or for every port, keep trusted addresses open, and undo it safely if you lock someone out.

Country blocking drops connections from the IP address ranges of countries you choose, in the server's firewall, before they reach nginx, SSH, mail or the panel. Use it when a website serves only some regions and receives most of its attacks, scans or spam sign-ups from countries where it has no visitors. It reduces noise; it does not stop a determined attacker, who can use a VPN or a server in another country.

Country blocking is an administrator feature on the Security page and applies to the whole server, not to single websites.

How it works

  • Address ranges come from ipdeny.com (aggregated IPv4 and IPv6 lists per country) and are loaded into kernel ipset sets. The ipset package is installed the first time you block a country.
  • ZoPanel adds a rule to UFW's before.rules and before6.rules that drops new connections from those ranges. Connections that are already open are not cut.
  • Addresses in Never blocked are always let through.
  • The lists are refreshed automatically once a week. A small service, zp-geoblock.service, restores them at boot before the firewall starts.
  • The rules only work while the firewall (UFW) is on. See Security.

What is blocked

Mode Blocked from the chosen countries Still reachable from everywhere
Websites only (ports 80 and 443) (default) Websites over HTTP and HTTPS SSH, mail (25, 465, 587, 993, 995, 143, 110), the panel (8888), webmail (2096), calendars (2080), FTP, DNS
All ports (switch off) Every service on the server, IPv4 and IPv6 Only the addresses in Never blocked

Important: in all-ports mode, mail servers in those countries cannot deliver mail to your domains, and anyone who signs in to SSH, the panel or a mailbox from there is cut off. Start with Websites only unless you are sure.

Block countries

  1. Open Security and scroll to Country blocking.
  2. In Countries, enter two-letter ISO 3166 codes separated by spaces, for example CN RU KP. Up to 60 countries.
  3. Keep Websites only (ports 80 and 443) on, or turn it off to block every port. Turning it off asks you to confirm Block every port for these countries?
  4. In Never blocked, add the IPs or ranges (CIDR) that must always get through, one per line: your offices, monitoring services, payment gateway callbacks, partners.
  5. Click Save. A task downloads the lists and applies the rules; it takes a few seconds per country.

The address you are using is added to Never blocked automatically when you save, so you cannot lock yourself out of the panel by mistake. When blocking is active, the card shows N countries blocked and how many address ranges were loaded and when.

Check the number of address ranges after saving. A code that does not exist (for example a typo such as XX) has no list at ipdeny.com and silently adds no ranges.

Trusted addresses (fail2ban)

The Trusted addresses (fail2ban) card next to it is a separate list: IPs or ranges that Fail2ban never bans for failed logins (SSH, panel, mail, calendars). Use it for an office whose users sometimes mistype passwords, or for monitoring that logs in. Up to 200 entries, one per line. It does not affect country blocking; an address in a blocked country needs to be in Never blocked as well.

Impact on legitimate users

  • Visitors, customers and search engine crawlers in a blocked country cannot open your websites. Their browser shows a connection timeout, not an error page.
  • IP-to-country data is never perfect. Mobile networks, VPNs and recently reassigned ranges can be listed under another country. If someone reports that they cannot connect, add their IP to Never blocked.
  • Webhooks and API callbacks (payment gateways, shipping services, Git hosting) may come from servers in a blocked country. Add their published ranges to Never blocked.
  • A new Outlook account syncs through Microsoft's servers, and many mail apps and phone services connect from data centres abroad. This only matters in all-ports mode.

Websites behind Cloudflare

When a website is proxied through Cloudflare (orange cloud), every connection to your server comes from a Cloudflare address, not from the visitor. As a result:

  • Country blocking does not block those visitors. Block countries in Cloudflare instead, with a WAF custom rule on the country field (for example ip.src.country in {"CN" "RU"}).
  • If a Cloudflare range is listed under a country you block, Cloudflare cannot reach your server and visitors from anywhere get Cloudflare error pages. Add Cloudflare's published ranges (cloudflare.com/ips) to Never blocked if you combine both.

The Websites behind Cloudflare switch on the same page makes logs and Fail2ban see the real visitor IP. It does not change country blocking, which works at the firewall level.

Change or turn off blocking

  • Change countries or mode: edit the fields and click Save. The lists are downloaded again.
  • Turn off: empty Countries and click Save. The firewall rules, the address sets and the boot service are removed.

If you are locked out

In all-ports mode, if you cannot reach the server from your location, use your VPS provider's web console or connect from an address in Never blocked, then, as root:

ipset flush zp-geo4
ipset flush zp-geo6

This empties the blocked ranges at once. Then sign in to the panel, add your address to Never blocked or empty Countries, and click Save. Without that, the next weekly refresh or a reboot loads the ranges again.

Troubleshooting

Message or symptom Cause and fix
"invalid country code …" Use two-letter codes only, separated by spaces or commas.
"at most 60 countries" Reduce the list.
"invalid address …" Each line of Never blocked must be an IP or a CIDR range such as 203.0.113.0/24.
"too many address ranges: choose fewer countries" The chosen countries together have more than 524,288 IPv4 or IPv6 ranges. Remove some countries.
"cannot find where to add the rules in /etc/ufw/before.rules" The UFW rules file was edited by hand and lacks the standard rule for established connections. Make sure it contains -A ufw-before-input -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT (and before6.rules the same line with ufw6-before-input).
"the firewall refused the rules (nothing changed): …" UFW could not load the rules. The previous rules were restored. Check that UFW is installed and enabled.
The task fails while downloading a list ipdeny.com could not be reached. The previous lists stay in place; try again later.
Visitors from a blocked country still get through They use a VPN, the site is behind Cloudflare, or their range is listed under another country.
A legitimate user cannot connect Add their IP or range to Never blocked and click Save.

← Two-factor authentication and account security Malware scan →