Access Control by Country
Access Control by Country allows or blocks a user's connection based on the country associated with the IP address they connect from.
We do not recommend using this feature in most cases. The country behind an IP address is always an approximation, so the feature locks out legitimate users who travel, work remotely, or connect through a VPN, while doing little to stop anyone determined to evade it. The feature exists because a small number of regulatory regimes require geographic access restrictions, not because it is a sound default.
You do not need this feature to block sanctioned countries. Files.com always blocks connections from Iran, Cuba, Syria, and North Korea on every site.
When you do enable it, use the Allowed Countries and Disallowed Countries settings on the Geo Blocking page to allow or block specific countries. When a user authenticates using any protocol or application, their IP address is analyzed to detect their country, and the result is compared against your settings.
Access Control by Country Is Not Recommended
Restricting access by country looks like a straightforward control, but IP geolocation is not accurate enough to carry that weight, and the failures land on your legitimate users.
The location associated with an IP address is always an approximation. It is determined by the Internet Service Provider of the network, not by the physical location of the device. A user sitting in San Francisco whose corporate VPN exits in Toronto is detected as connecting from Canada. Geolocation databases also lag behind reality, so a reassigned IP address can resolve to the wrong country until the database catches up. Files.com compares two commercial geolocation databases to reduce this error, and the result is still an approximation.
Those inaccuracies produce lockouts that are difficult to diagnose. Vendors, suppliers, and trading partners whose networks route through an unexpected country are blocked without warning, and so is any employee on the road. Because the block happens at authentication, the user sees only a failed login.
The feature provides little real security benefit in exchange for those lockouts. VPN and proxy services circumvent IP-based geolocation, so anyone motivated to reach your site only needs an exit point in a country you allow.
The control stops ordinary users who happen to be in the wrong place. It does not stop a determined attacker.
Country restrictions also interact with IP whitelists in a way that surprises administrators. A country on your Disallowed Countries list blocks a connection even when its IP address is explicitly whitelisted, so an address you deliberately trusted can stop working when its geolocation record changes.
Identity-based controls protect your site more effectively and without these operational costs. Enforce Two-Factor Authentication (2FA), use SSO (Single Sign-On) where you have an identity provider, and set strong password requirements.
When Country Restrictions Are Appropriate
Configure Allowed or Disallowed Countries when a regulation or your security office explicitly requires you to restrict access geographically, and not otherwise. ITAR and Controlled Goods Regulations are the common cases. In those environments the restriction is a documented compliance obligation, and the approximation and lockout problems described above are costs you absorb and plan around rather than reasons not to proceed.
Using the Allowed Countries and Disallowed Countries Lists
To restrict access to a select group of countries, add them to the allowed countries list and leave the disallowed countries list empty. Users whose IP addresses are not associated with an allowed country will be blocked.
To block certain countries while allowing all others, leave the allowed countries list blank and add the restricted countries to the disallowed countries list. Users from any of the disallowed countries will be prevented from logging in.
If both lists are populated, only users from the allowed countries have access. Any country not in the allowed countries list is blocked, regardless of the disallowed countries list.
Disallowed Countries take precedence over Allowed Countries.
These settings apply to Site Administrators as well, so an allowed countries list that omits your own detected country locks you out of your own site. Confirm which country Files.com detects for every Site Administrator before you save the configuration, and keep one or two backup Site Administrator accounts as a precaution.
Interaction With IP Whitelists
The IP Whitelist setting does not override any Access Control by Country restrictions you set up.
For example, IP addresses associated with countries in your list of Disallowed Countries cannot connect, even if they are in IP whitelists.
Country restrictions take precedence because they are normally set to satisfy a company-wide or regulatory policy, which a per-user or per-group whitelist cannot relax.
Authenticated versus Public Connections
Allowed Countries and Disallowed Countries settings apply only to authenticated connections from users.
Features that do not require a user account are not affected by the Allowed Countries and Disallowed Countries settings, including Share Links, Inboxes, and Public Hosting.
Logging
Files.com logs every login attempt by any user or system. When a login is attempted from a country or IP address that the Administrator has not allowed, Files.com rejects the authentication and records the attempt in the user's activity history.