Block country by geoip with nginx ingress controller and modsecurity

Viewed 844

I'm trying to block one country on nginx ingress controller with modsecurity enabled but still no luck. My configuration is:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  annotations:
    cert-manager.io/cluster-issuer: letsencrypt
    kubernetes.io/ingress.class: nginx
    nginx.ingress.kubernetes.io/modsecurity-snippet: |
      SecRuleEngine On                                       
      SeqRequestBodyAccess On                                
      SecAuditEngine On                                      
      SecAuditLogParts ABIJDEFHZ                             
      SecAuditLog /var/log/modsec_audit.log                  
      SecGeoLookupDb /etc/nginx/geoip/GeoIP.dat
      SecRule REMOTE_ADDR "@geoLookup" "chain,id:22,drop,msg:WrongIP"
      SecRule GEO:COUNTRY_CODE "@streq GR"
    nginx.ingress.kubernetes.io/whitelist-source-range: 0.0.0.0/0

when I try to access URL with curl I'm getting HTTP 200 instead of HTTP 403.

1 Answers

Start by validating that your solution works at all:

Try changing your condition from:

"@streq GR"

to:

"!@streq GR"

and testing again. If your rules are actually working then the result you get should flip: 200 to 403 or 403 to 200.

Related