---
title: 'Country Settings'
url: 'https://docs.danami.com/juggernaut/settings/login-failure-daemon/country-settings'
markdown: 'https://docs.danami.com/juggernaut/settings/login-failure-daemon/country-settings.md'
date: '2026-09-22'
description: '• Make sure not to block any countries where your server may be pulling yum or apt-get updates from otherwise yum or apt-get will fail when you try to grab any package updates. • Country and ASN blocks apply to incoming connections only. How to get a Maxmind License Key Signup fo…'
taxonomy:
  category:
    - docs
  tag:
    - country
    - asn
---

[](#)  [ Basics ](https://docs.danami.com/juggernaut/)     [ Settings Reference ](https://docs.danami.com/juggernaut/settings)     [ Login Failure Daemon ](https://docs.danami.com/juggernaut/settings/login-failure-daemon)      Country Settings    

# Country Settings

> > > > • Make sure not to block any countries where your server may be pulling yum or apt-get updates from otherwise yum or apt-get will fail when you try to grab any package updates.
> > > > • Country and ASN blocks apply to incoming connections only.

## How to get a Maxmind License Key

1. Signup for the **free** license key [here](https://www.maxmind.com/en/geolite2/signup).
2. Generate a license key [here](https://www.maxmind.com/en/accounts/current/license-key) (When asked - Will this key be used for geoipupdate? Choose: no)
3. Navigate to `Juggernaut Firewall -> Settings -> Country Settings` and enter the license key under MaxMind license key.

## Country Provider Settings

**Country source** - `CC_SRC`
The source for where CSF downloads its country databases.
Default: 1 (MaxMind)

**MaxMind license key** - `MM_LICENSE_KEY`
MaxMind requires you to create a free account on their site and to generate a license key to use their Geolite2 databases.
Default: empty

## Country Settings

**Deny countries to all ports** - `CC_DENY`
Deny whole country or ASN CIDR ranges. The CIDR blocks are generated from the Maxmind GeoLite2 Country database and entirely relies on that service being available.
Default: empty

**Allow countries though all ports** - `CC_ALLOW`
Allow whole country or ASN CIDR ranges. Warning: this option allows access through all ports in the firewall.
Default: empty

**Only allow countries and filter** - `CC_ALLOW_FILTER`
Only allow access from the following countries or ASN but still filter based on the port and packets rules. All other connections are dropped.
Default: empty

**LFD blocking ignore countries** - `CC_IGNORE`
Prevent the login failure daemon from blocking IP address hits for the following countries or ASNs. CC\_LOOKUPS must me enabled to use this option.
Default: empty

**LFD blocking ignore countries** - `CC_MESSENGER_ALLOW`
Only a blocked IP that resolves to one of these country codes will be redirected to the MESSENGER service.
Default: empty

**LFD blocking ignore countries** - `CC_MESSENGER_DENY`
A blocked IP that resolves to one of those Country Codes will NOT be redirected to the MESSENGER service.
Default: empty

**Ignore CIDR blocks smaller than** - `CC_DROP_CIDR`
Ignore CIDR blocks smaller than this value when implementing CC\_DENY / CC\_ALLOW / CC\_ALLOW\_FILTER. This can help reduce the number of CC entries and may improve iptables throughput. This will deny/allow fewer IP addresses depending on how small you configure the option. Set to None to block all CC IP addresses.
Default: empty

**Ipv4 address lookups** - `CC_LOOKUPS`
Display Country Code and Country for reported IP addresses.
Default: 1 Range: 0-3

**IPv6 address lookups** - `CC6_LOOKUPS`
Display Country Code and Country for reported IPv6 addresses using the MaxMind Country IPv6 Database. This option must also be enabled to allow IPv6 support to CC\_\*, MESSENGER and PORTFLOOD.
Default: 0

**Maxmind DB retrieval interval** - `CC_INTERVAL`
How often the login failure daemon will retrieve the Maxmind GeoLite Country database for CC\_ALLOW, CC\_ALLOW\_FILTER, CC\_DENY, CC\_IGNORE and CC\_LOOKUPS (in days).
Default: 7 Range: 1-31

## Allow Countries to Port Settings

**Allow countries to ports** - `CC_ALLOW_PORTS`
Allow access from the following countries or ASNs to specific ports listed in CC\_ALLOW\_PORTS\_TCP and CC\_ALLOW\_PORTS\_UDP.
Default: empty

**Allow countries to TCP ports** - `CC_ALLOW_PORTS_TCP`
Allow access to the following TCP ports from the `CC_ALLOW_PORTS` countries. All listed ports should be removed from TCP\_IN to block access from elsewhere.
Default: empty

**Allow countries to UDP ports** - `CC_ALLOW_PORTS_UDP`
Allow access to the following UDP ports from the `CC_ALLOW_PORTS` countries. All listed ports should be removed from UDP\_IN to block access from elsewhere.
Default: empty

## Deny Countries to Port Settings

**Deny countries to ports** - `CC_DENY_PORTS`
Deny access from the following countries or ASNs to specific ports listed in CC\_DENY\_PORTS\_TCP and CC\_DENY\_PORTS\_UDP.
Default: empty

**Deny countries to TCP ports** - `CC_DENY_PORTS_TCP`
Deny access to the following TCP ports from the CC\_DENY\_PORTS countries. All listed ports should NOT be removed from TCP\_IN.
Default: empty

**Deny countries to UDP ports** - `CC_DENY_PORTS_UDP`
Deny access to the following UDP ports from the CC\_DENY\_PORTS countries. All listed ports should NOT be removed from UDP\_IN.
Default: empty

## Related Pages

- [Country Code Lists](https://docs.danami.com/juggernaut/user-guide/country-code-lists "Country Code Lists")

---

## Navigation

- Parent: [Login-failure-daemon](https://docs.danami.com/juggernaut/settings/login-failure-daemon.md)
- Previous: [Global Lists and DynDNS](https://docs.danami.com/juggernaut/settings/login-failure-daemon/global-lists-and-dyndns-settings.md)
- Next: [Directory Watching](https://docs.danami.com/juggernaut/settings/login-failure-daemon/directory-watching.md)
