I didn't find a straightforward solution using Meraki MX since it lacks this feature.However, I previously managed this task with legacy Cisco ASA firewalls :). The workaround involves manually creating objects at the Meraki organization level for each CIDR and organizing them into object groups for each country or region, then setting up corresponding firewall rules. For instance, you can explore IP CIDR or range by country using resources like this example: https://github.com/herrbischoff/country-ip-blocks Another consideration for the most secure approach is to eliminate this attack surface altogether and replace direct access with VPN connectivity.
... View more