Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
---
title: Country rules supported in Unified Routing
description: Cloudflare Advanced Network Firewall Country rules now work with Unified Routing mode.
date: 2026-04-21T12:00:00
products:
- cloudflare-network-firewall
- magic-transit
---

[Cloudflare Advanced Network Firewall](/cloudflare-network-firewall/) Country rules are now supported for accounts using [Unified Routing](/cloudflare-wan/reference/traffic-steering/#unified-routing-mode-beta) mode. This feature requires a Cloudflare Advanced Network Firewall subscription.

You can create firewall rules that match traffic based on source or destination country to enforce geographic access policies across your network.

This is the first of the Cloudflare Advanced Network Firewall features to become available in Unified Routing. Support for additional features - IP Lists, ASN Lists, Threat Intel Lists, IDS, Rate Limiting, SIP, and Managed Rulesets - is planned.

For the full list of current beta limitations, refer to [Traffic steering beta limitations](/cloudflare-wan/reference/traffic-steering/#beta-limitations).
Original file line number Diff line number Diff line change
Expand Up @@ -276,7 +276,7 @@ The following limitations apply to accounts using Unified Routing mode. This lis
| Network analytics | Not yet fully supported |
| Basic packet captures | Captures exclude Automatic Return Routing or BGP-over-tunnels traffic |
| Full packet captures | Not yet supported |
| Advanced Cloudflare Network Firewall features: GeoIP/Country rules, IP Lists, ASN Lists, Threat Intel Lists, IDS, Rate Limiting, SIP, Managed Rulesets | Not yet supported |
| Cloudflare Advanced Network Firewall features: IP Lists, ASN Lists, Threat Intel Lists, IDS, Rate Limiting, SIP, Managed Rulesets | Not yet supported |
| Gateway filtering rules | Not supported on traffic where both the onramp and offramp is IPsec/GRE/CNI |
| Load Balancer | Public-to-private use case is supported to IPsec/GRE/CNI destinations. Private-to-private use case does not yet support Cloudflare Source IPs |

Expand Down
Loading