Summary
VyOS's GeoIP data pipeline already ingests DB-IP's two non-standard, documented country codes — XK (temporary code for Kosovo) and ZZ (bogon/no-location address blocks) — into the local GeoIP lookup cache with full IP range data. However, the CLI schema for firewall ... geoip country-code and policy route ... geoip country-code hardcodes a fixed ISO 3166-1 alpha-2 list that excludes both codes, so they can never actually be referenced in a rule. This is a CLI-schema gap, not a data or ingestion problem.
I have checked in Lab, the local SQLite cache VyOS has once the geoip is updated, it clearly show the two non-standard country-code, but since this has been hardcoded in the geoip.xml.i file, from VyOS cli is not possible to included.
Use case
db-ip.com shows that those are included but not-standard: https://db-ip.com/faq.php
Proposed fix
In interface-definitions/include/firewall/geoip.xml.i:
- Add xk and zz to the <completionHelp><list> enumeration.
- Add xk and zz as alternatives in the <constraint><regex> pattern.
to get something like this:
- set firewall ipv4 name smoketest rule 1 source geoip country-code xk / zz