An overview of geolocation objects, including translated addresses, rule behavior, interface scope, and policy impact.
A geolocation object defines countries and continents that host the device that is the source or destination of traffic. You can use these objects in policies to control traffic instead of using IP addresses. For example, using geographical location, you could easily restrict access to a particular country without needing to know all of the potential IP addresses used there.
You can usually select geographical locations directly in a policy without using geolocation objects. Use an object when several policies need the same countries or continents.
Update the geolocation database
To use current geographical location data to filter traffic, Cisco recommends that you regularly update the geolocation database (GeoDB). You cannot update the GeoDB in Security Cloud Control. Refer to the following sections of the Cisco Firepower Threat Defense Configuration Guide for Firepower Device Manager for the version your device is running to learn more about the GeoDB and how to update it.
-
Updating System Databases and Feeds
-
Updating System Databases
