Set the rule in Network Center > Security > Firewall > Create.
Use:
1. Name — enter a rule name.
2. Protocol — choose the traffic protocol.
3. Source — choose IP Address > Region and click Select to specify the countries/locations you want.
4. Destination — choose IP Address > SRM if you want the rule to apply only to the Synology Router itself, or All / Specific IP as needed.
5. Action — use Allow if you want only the selected countries to access SRM/local network, and deny the rest.
If your goal is “only my region can connect,” create an Allow rule for your country/region first, then adjust the default policies so unmatched traffic is denied:
- If IPv4 WAN-to-SRM traffic matches no rules: deny
- If IPv4 WAN-to-LAN traffic matches no rules: deny
- If IPv6 WAN-to-SRM traffic matches no rules: deny
- If IPv6 WAN-to-LAN traffic matches no rules: deny
Note: the KB says firewall rules cannot regulate access attempts within a local network; for blocking communication between two devices, Synology suggests placing them on different local networks.
Sources: [1], [4], [6]