How to Block all countries

Showing results for 
Show  only  | Search instead for 
Did you mean: 

How to Block all countries

L0 Member

I am trying to make a policy on my new PA-220 and i want to block all traffic coming in from every country except the united states..I can't figure out how to do that except by blocking every country one country at a time.. Can anyone tell me if there is a block all except feature?


Cyber Elite
Cyber Elite


You should be able to create a security policy that has the source set as the 'US' and then simply Negate the source and set the action to block. 

or set 'US' as the only source for your inbound allow policies, anything not from the US will hit the default deny rule (or an 'any' drop rule you create right after the allow policies)

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Community Team Member

Hi @hill11,


Both options are valid.  The negate option is an often 'forgotten' feature and it has my preference in this case.


Depending on how many rules you have, you don't want to wait until you hit the final default deny all rule.  This uses up precious resources and to avoid that I would recommend to block early on ^_^


Cheers !


LIVEcommunity team member, CISSP
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

L3 Networker

create an allow rule with US as source followed by a deny rule of source 'any'.

  • 4 replies
  • 101 Subscriptions
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!