How to Use Country and IP-Based Access Policies

Advanced 20 minutes Security Engineers / Compliance Teams Security & Policy

Configure GeoIP-based policies to restrict package access by country, and create IP allowlists/blocklists for network-level access control.

Overview

Some organizations need to restrict package access based on geographic location or source IP address — for compliance with export controls, data residency requirements, or to limit access to known office networks. Chainsaw supports both country-based (GeoIP) and IP-based policy conditions.

Prerequisites

  • Admin or Manager role in Chainsaw
  • GeoIP MMDB database installed (MaxMind) for country-based policies
  • Knowledge of your organization’s network ranges for IP-based policies

Step 1: Understand GeoIP Detection

Chainsaw uses a MaxMind GeoIP MMDB database to resolve client IP addresses to country codes. When a package request arrives, Chainsaw:

  1. Extracts the client IP address
  2. Looks it up in the MMDB database
  3. Resolves to a country code (ISO 3166-1 alpha-2, e.g., US, DE, JP)
  4. Makes the country available as a policy condition
GeoIP resolution flow
Client IP is resolved to a country code for policy evaluation
Ensure your MaxMind MMDB file is updated regularly for accurate geolocation. Outdated databases may misidentify client locations.

Step 2: Create a Country-Based Policy

Navigate to Policies and click Create Policy.

Restrict Access to Approved Countries

  1. Name: Block Non-Approved Countries
  2. Action: Block
  3. Condition: Country → not in list
  4. Country List: US, CA, GB, DE (your approved countries)
  5. Scope: All repositories
Country-based policy creation
Block package access from non-approved countries

Allow Specific Countries Only

Alternatively, create an Allow policy for approved countries and a catch-all Block:

Policy 1 (High precedence): Allow — Country in [US, CA, GB, DE]
Policy 2 (Low precedence):  Block — All requests (catch-all)
Country-based policies affect all clients connecting from that location, including remote employees using VPNs. Ensure your VPN egress IPs resolve to approved countries.

Step 3: Create IP-Based Policies

Allowlist Corporate Networks

Restrict access to known office or VPN IP ranges:

  1. Name: Allow Corporate Network Only
  2. Action: Allow
  3. Condition: IP → in range
  4. IP Ranges: 10.0.0.0/8, 172.16.0.0/12, 203.0.113.0/24
IP allowlist policy
Allow access only from your corporate network ranges

Blocklist Known Bad IPs

Block requests from specific IP addresses:

  1. Name: Block Suspicious IPs
  2. Action: Block
  3. Condition: IP → in list
  4. IP List: Specific IPs you’ve identified as suspicious
IP blocklist policy
Block requests from specific IP addresses

Step 4: Combine Country and IP Policies

Layer policies for defense in depth:

PrecedencePolicyPurpose
100Allow — Corporate VPN IPsAlways allow from known infrastructure
90Block — Non-approved countriesGeographic restriction
80Block — Suspicious IP rangesThreat intelligence
10Allow — DefaultAllow remaining approved traffic
Layered country and IP policies
Combine country and IP policies for defense in depth

Step 5: Compliance Use Cases

Export Control Compliance

Block access from countries subject to export restrictions:

Block — Country in [embargoed country list]
Scope: All repositories
Precedence: Very high (above exceptions)

Data Residency

Ensure packages are only accessed from approved jurisdictions:

Allow — Country in [approved jurisdictions]
Block — All others (catch-all)

PCI-DSS / SOC2

Restrict production package access to controlled network segments:

Allow — IP in [production network ranges]
Block — All others for service-token client types
For compliance scenarios, combine IP/country policies with audit logging to maintain a complete evidence trail of who accessed what from where.

Step 6: Monitor Geo/IP Violations

Navigate to the Overview dashboard to see violations triggered by geographic or IP restrictions.

Geographic restriction violations
Monitor violations from geographic and IP-based policies

Check the Traffic page for details on blocked requests:

  • Source IP address
  • Resolved country code
  • Policy that triggered the block

Step 7: Handle Remote Workers

Remote employees may trigger country or IP policies. Solutions:

ScenarioSolution
Employee traveling abroadVPN with approved egress IP
Remote worker in non-approved countryVPN or IP-based exception
Contractor on external networkDedicated credential with IP exception

Create a temporary exception policy:

  1. Name: Exception: Remote Worker — Jane Doe (2026-Q2)
  2. Action: Allow
  3. Conditions: Client ID = jane-doe-cred AND Country = JP
  4. Expiry: End of quarter

Next Steps