As a network admin for a local government agency, there is really no reason for us to be receiving any traffic from China, Russia, Brazil, etc. In light of all the common problems every organization has with viruses, spam, and hackers originating from these countries, what drawback would there be to create a firewall filter on our ingress interface to discard all traffic originating from these countries? Or would it be more efficient to create a filter to allow all traffic from the US and then discard the rest? Is this sort of approach becoming more common now? What kind of performance impact could I possibly see on our SRX650 with a filter like this? Any feedback on this would greatly be appreciated. Thanks.