It would be an awesome feature if it were possible to exclude geolocation countries from the ASM traffic learning, for example only allowing to learn from specific countries. Likewise preventing traffic learning entries to be spoiled with foreign countries.
Is there any upcoming release where it would be possible to configure geographic location exclusions in the IP address exclusion section and/or inside the traffic learning settings of ASM?
This isn't available with ASM, but can be achieved using iRule, where you can drop from blacklisted countries or allow traffic from whitelisted one. So that ASM learning would be only from allowed geo locations
Maybe with LTM Traffic Policy? Like this requests from US would come unfiltered to the backend.
Other alternative would be to use different policies for different country codes. Maybe for the "bad" country codes you use only a policy with Attack Signatures and Threat Campaings, but not Entity Learning.
No offense, DE and US were the country codes I know by heart. 🙂
Edit: same can be achieved with iRules.