Skip to main content
See All Integrations

IP geolocation data

Use selected IP geolocation records in Pomerium policy with the documented GeoIP data-source pattern.

First-party Pomerium context guide

Category
Context Data Sources

Overview

IP geolocation data maps an IP address to an approximate country, region, city, network, or other location attribute. Pomerium documents a request-context pattern that imports an IP2Location data file and matches records through request.ip.

A coarse location signal can help a policy detect unexpected access paths or meet a narrow regional rule. It must stay one signal among identity, request, and application controls because an IP address does not prove physical location.

This is a named Pomerium request-context guide. The data source sends records toward Pomerium. Pomerium evaluates the record for request.ip before it sends approved traffic toward the protected service.

How it works

Select and license an IP geolocation dataset that has the required fields and update cadence. The documented Pomerium example uses IP2Location CSV data and the Pomerium datasource project.

Run the datasource on a protected endpoint. Configure Pomerium Enterprise to poll the records and use request.ip as the foreign key.

Use a Pomerium Policy Language record matcher for the required field. Test IPv4, IPv6, proxy headers, missing records, and update behavior.

Example

A team imports an approved country-code field from an IP2Location CSV file. A Pomerium route policy permits access only when request.ip matches an imported record with an allowed country code. The application still applies its own authorization after Pomerium permits the request.

Considerations

  • IP geolocation is approximate. It does not identify a user or a device.
  • Accuracy, permitted use, fields, and update cadence depend on the selected data license.
  • Pomerium states that example data sources are not maintained in perpetuity.
  • External data sources need Pomerium Enterprise and update on a polling schedule.

Sources and official resources

  • Protect access to private DNS services through separate Pomerium UDP and TCP routes.

  • Protect access to internal HTTP APIs with identity-aware Pomerium routes.

  • Use Tor exit relay IP data in Pomerium Enterprise policy to identify or restrict requests from known Tor exits.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo