# Deny a request by country

Deny or allow a request based on the visitor's country, resolved from GeoIP data on Azion's global network. Use this pattern in a firewall function to enforce geographic restrictions, blocking traffic from specific regions before it ever reaches your application.

```js
async function firewallHandler(event){
    // Access the country code through geoip
    let countryCode = event.request.metadata["geoip_country_code"]

    // Do some logic here
    // In this example, we are blocking access from Brazil
    if (countryCode === "BR"){
        event.deny();
    }

    // Then, if it comes from any other country,
    // the processing continues
    event.continue();
}

addEventListener("firewall", (event)=>event.waitUntil(firewallHandler(event)));
```

## How it works

This code runs as a `firewall` handler, so it executes in a firewall before the request reaches an application. It registers the handler with `addEventListener("firewall", ...)` and runs the asynchronous work inside `event.waitUntil()`. Refer to [Functions for Firewall](/en/documentation/platform/firewall/functions/) for the full set of actions a firewall handler can call.

The handler reads the visitor's country from `event.request.metadata["geoip_country_code"]`. When the request comes from Brazil it calls `event.deny()`, which returns a default 403 response and stops further processing. For requests from any other country, `event.continue()` allows the request to proceed to its destination.

## Related resources

- [JavaScript examples](/en/documentation/platform/functions/javascript-examples.md): Browse the other syntax patterns in the collection.
- [Functions for Firewall](/en/documentation/platform/firewall/functions.md): Read the reference for every action a firewall handler can call.
- [Metadata API](/en/documentation/devtools/runtime/api-reference/metadata.md): Look up the request metadata fields, including the GeoIP values.
- [Functions Instances for Firewall](/en/documentation/platform/firewall/functions-instances.md): See how a function is instantiated on a firewall and triggered by a rule.
- [Limits for functions on a firewall](/en/documentation/platform/functions/limits.md#limits-for-functions-on-a-firewall): The limits a firewall function shares with every function, and where the bounds of the firewall itself are listed.
