We restricted web traffic on several shared-hosting servers to US visitors plus our CDN, a common hardening step when every client and customer is in the US. The firewall reported success. The allowlist was quietly incomplete.
What happened
The firewall (ConfigServer Security & Firewall, CSF) builds the country allowlist as a Linux ipset. The US list is roughly 131,000 address ranges. CSF's default maximum ipset size, LF_IPSET_MAXELEM, is 65,536. The set filled up and stopped accepting entries. No error a person would notice, no failed restart.
The result depends on which half got loaded: some legitimate US visitors were refused while the server looked correctly configured.
The second trap: an empty set
On another server the GeoIP database had not finished downloading when the rules were built, so the country set was created with zero entries. An allow-only rule over an empty set blocks everyone. We caught it before rollout and reverted rather than ship an empty allowlist.
What to do
- Raise the limit before enabling country filtering:
LF_IPSET_MAXELEM="300000"(or comfortably above the size of the largest list you load). - Verify the set, not the config:
ipset list <set> | grep 'Number of entries'and compare it to the source list's line count. - Never enable an allow-only rule over a set you have not counted. Zero entries means everyone is blocked.
- Scope it. We limited the country filter to web ports only, so mail, DNS and SSH keep working for systems that legitimately connect from elsewhere.
- Put a CDN in front for sites with real international visitors, and allowlist the CDN's ranges.
- Test from outside the country. We checked reachability from multiple countries before and after the change.
Creative Code runs security sweeps, hardening and incident response as part of its engineering work. Talk to us.