Description
CloudFront geographic restrictions control content access by country using the geographic location of the connecting IP address. They can support licensing or service policies that limit distribution, but a service intended for worldwide access may leave them disabled.
This feature does not establish a user’s identity or actual physical location, and does not replace authentication or origin access restrictions.
Potential impact
Without required country restrictions, content may be accessible outside the permitted regions. An incorrect list can instead block legitimate users.
Remediation
Confirm the service’s country requirements and, where needed, configure an appropriate allow or block list in Restrictions.GeoRestriction. Verify actual access and direct origin access, and retain other controls such as authentication.
Examples
These distribution excerpts compare geographic restrictions only. Origins, cache behaviors and other required settings are omitted; choose country codes according to the service policy.
Before
AWSTemplateFormatVersion: '2010-09-09'
Resources:
myDistribution:
Type: AWS::CloudFront::Distribution
Properties:
DistributionConfig:
Logging:
IncludeCookies: 'false'
Bucket: mylogs.s3.amazonaws.com
Prefix: myprefix
Restrictions:
GeoRestriction:
RestrictionType: none
ViewerCertificate:
CloudFrontDefaultCertificate: 'true'
RestrictionType: none applies no country-based access restriction.
After
AWSTemplateFormatVersion: '2010-09-09'
Resources:
myDistribution:
Type: AWS::CloudFront::Distribution
Properties:
DistributionConfig:
Logging:
IncludeCookies: 'false'
Bucket: mylogs.s3.amazonaws.com
Prefix: myprefix
Restrictions:
GeoRestriction:
RestrictionType: whitelist
Locations:
- AQ
- CV
ViewerCertificate:
CloudFrontDefaultCertificate: 'true'
This specifies AQ and CV in a whitelist. These countries are illustrative, not a recommended list for every service.