Back to problems

Block Malicious IPs at an API Gateway Across Data Centers

System Design · LinkedIn · Hard

Design a request-filtering component for an API gateway that rejects traffic from IP addresses known to be abusive. The control path that creates and removes block rules is separate from the data path that applies them. After describing a single-region design, explain how you would extend it to multiple data centers so all regions converge on the same policy within an acceptable duration. Before committing to a design, clarify: Which team or operator may add and remove…

Checking your access…