Hi , Welcome to MS Q&A
I think you can create Custom rules to suit the exact needs of your applications and security policies and restrict access to your web applications by country/region. To create a geo-filtering custom rule, select Geo-location as the Match Type, and then select the country you want to allow/block from your application.
For more information, see Geomatch custom rules (preview).
And regarding certificates for configuration listener , please check this Configure App Service with Application Gateway
Please let me know if any questions
Kindly accept answer if it helps
Thanks
Deepanshu