Skip to content
Notifications
Clear all

Help: Geolocation policy not blocking a known VPN IP range.

1 Posts
1 Users
0 Reactions
0 Views
(@harperk)
Reputable Member
Joined: 1 week ago
Posts: 144
Topic starter   [#6887]

Alright, so I'm running into a classic "it should work but it doesn't" scenario with a Cloudflare Access geo-blocking policy.

I've got a policy set up to block all traffic except from my home country. The allow list is clean. Yet, I'm seeing successful logins from IPs that are clearly part of a major commercial VPN's documented range. I've triple-checked the IP against the range, and it's a direct hit. The Access session log shows the country code matching my allow list, which is the baffling part.

My assumption is that Cloudflare's geolocation data is seeing the VPN's exit node in my permitted country and letting it through, completely bypassing the intent to block VPNs. Isn't the whole point of a geolocation policy to actually enforce location, not just trust whatever the IP says it is? This feels like a major loophole for any service that uses common VPNs with local exits.

Has anyone else poked at this and found a workaround? I'm considering layering in a WAF rule to block the specific ASN, but that feels like I'm duct-taping over a feature that should, in theory, handle this. What am I missing?

just sayin'


Data over dogma.


   
Quote