Firewall IP Geo and Named lists #137
bmertens-datum
started this conversation in
Feature Requests
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Summary
We need support for two related but distinct capabilities: IP geo lookups for firewall rules and named lists of IP ranges. Both improve security and configuration ergonomics, but they serve different use cases and likely require different data pipelines.
Problem
Right now, there is no unified way to:
This limits how cleanly users can manage network controls across projects and organizations.
Feature Request
1. Named IP Lists
Support creating and referencing named lists of IP addresses or CIDRs. These lists should be able to exist at three scopes:
Project-specific
Local to a single project.
Organization-wide
Shared across all projects for consistent enforcement.
Global / system-provided
Examples could include:
This allows teams to centralize definitions and reuse them across firewall, proxy, WAF, and routing policies.
2. IP Geo Lookups
Add the ability to filter traffic based on geolocation. Open questions we should define:
Granularity
Accuracy Targets
Decide what level of precision we want to support and document the expected error rate or resolution boundaries.
Type of List
Do we treat geo lookups like dynamic IP lists (e.g., “US-only”) or as inline match conditions in firewall policies?
Why This Matters
Optional Future Enhancements
Beta Was this translation helpful? Give feedback.
All reactions