Not all global traffic is relevant to your service.
Automatic scans and attempts often come from areas where your activity has no users.
Block entire countries with local GeoIP database, apply different policies for each domain and evaluate the reputation of each source IP with a score 0-100. Less attack surface, without risk of blocking good customers.
Automatic scans and attempts often come from areas where your activity has no users.
Identify the IP address's country, evaluate lists and its risk score and apply the domain policy.
Allow traffic from the markets you serve and keep explicit exceptions for trusted customers and systems.
Attack surface
If your site only serves Italy or Europe, traffic from outside those markets is almost certainly noise, scan or attack. Filtering geography is the easiest way to get rid of large volumes of automated traffic.
Traffic from countries where you have no customers are stopped before even touching the application: scanners, brute-force attempts and floods disappear from the logs.
An Italian shop allows only Italy, a European portal allows Italy, Germany, France and Spain, a technical API logs traffic from higher-risk countries without blocking. Each domain has its own policy.
The IP address is resolved to an ISO country code on the server itself, using a local MaxMind database: no external queries, no added latency, no data leaving your infrastructure.
Geo-blocking · Local GeoIP
Sentinel uses the database MaxMind GeoLite2-Country (.mmdb) locally: The source IP is resolved in ISO country code directly in the agent code, without querying external services.

Policy per domain
Each request is evaluated with the right policy following a precise order: exact host → wildcard → global Thus each domain has its own geographical rules, independent of others.

IP blocklists and allowlists
In addition to geography, manage IP lists at the single address level. the allowlist has priority: a trusted IP always passes, regardless of geo, blocklist or reputation. Blocks have a TTL and are applied directly to the local firewall of each server, then synchronized by the dashboard.
Trusted office, monitoring and partner IP addresses are never blocked, regardless of other active rules.
The blocked IPs automatically expire after the set time: no lists that grow indefinitely and block addresses that are now clean.
Decisions end up on the server's firewall: hostile traffic is cut upstream, before consuming application resources.
Reputation & scoring
Sentinel calculates a reputation score where 0 is safe and 100 is malicious, by combining weighted sources. configurable threshold (default 70), IP is blocked. Gate is opt-in and supports the shadow mode to observe without blocking.

Synchronization
Geo rules, IP lists and reputation configuration start from the dashboard and arrive at every agent through the central server, over an encrypted, mutually authenticated channel.
Define allowlists and blocklists by country, per-domain policy, IP lists and reputation threshold. All from one console.
The central server distributes global or per-server blocks and retains the event history; allowlists travel in full sync.
The agent applies local rules on the firewall and reverse proxy: decisions in milliseconds, no data to third parties.
Operational security
Geo-blocking is designed to never turn into a service interruption: if the GeoIP database is absent or an IP address cannot be resolved to a country, the request pass instead of being blocked. Better to let in some extra requests than to block real customers for a missing file.
Frequently asked questions
No. The country of each IP is solved locally with the MaxMind GeoLite2 Country database .mmdb on the server itself: no external queries, no IP address leaves your infrastructure.
Fail-open: if the .mmdb is absent or IP is not solved in a country code, the request passeseses. Geo-blocking never causes a total block by mistake.
A non-empty allowlist activates the default-deny: only allowed countries pass. Without allowlist, only countries on the blocklist are blocked. The local allowlist also takes precedence over the central blocklist.
Yes. The policy applies by-domain with exact host order → wildcard → global, so each domain has its own countries allowed or prohibited and its own block or log mode.
It is a score where 0 is safe and 100 malicious, calculated by weighing DNSBL (40%), local event history (30%), geo-risk (15%), proxy/Tor/VPN/datacenter (15%) and a threat-feed bonus. Beyond the threshold (default 70) the IP is blocked.
Yes. The gate is opt-in and supports shadow mode: you can watch the scores and what will be blocked before you activate the real block, and adjust the threshold with real data.
We show you geo-blocking and reputation live on your infrastructure and tune them for your domains.