"It'd be a great addition to the sw-nginx build. Enforcing rate limits is a must have these days and using ngx_http_geoip_module should be a very effective way to slow down the botnets' brute force attacks against commonly abused locations, like Wordpress/Joomla/Drupal or Magento login pages. A basic example: