Depends on what your threat vector looks like: Your‘re trying to narrow down the possibility to reach your systems from countries not supposed to hit your systems. This of course will prevent automated scanning etc. (which adds a little bit of security) and prevent your logs from being filled up with garbage mostly. Nash‘s very valid point on the other hand is: if somebody from one of countries you‘re blocking is really up to something, he / she / it will simply make sure the connections are coming from some other country, most likely the one you‘re residing in. Guess it‘d add way more security would be to have the systems open to the internet as secured as possible, cause after all this is what‘s preferable nonetheless.
... View more