Create a Country Host object : Objects > Hosts and Services > Country Host and after that Create a Security policy and choose the Country Host Object to be blocked: Policies > Add Firewall Rule > User / Network Rule and on Source Or Destination Direction choose the object created over field "Networks *" and choose the DROP action
I'm using Country Group Object to limit external acess to manage interface and is working fine.
Is the same procedure to create the object in CarlosCesario comment.