IP Blocking by Country?

Unanswered Question
Mar 31st, 2008
User Badges:

We are considering a strategy of blacklisting or whitelisting IP by country.


Some questions:


1) Is there an easier method than adding lots of IP ranges (i.e. just specify a country)


2) What would be the performance considerations? i.e. how big of a list of IP ranges has to get before it starts to impact network throughput beyond neglible.


3) Are there better ways of achieving this objective, such as blocks at our ISP (AT&T) level, or specialized network appliances?


thanks for your answers in advance



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Collin Clark Tue, 04/01/2008 - 06:36
User Badges:
  • Purple, 4500 points or more

Chuck-


I have never found a really good way to block by Country, so I try and maintain a list. I send the network to null0 so it doesn't affect performance too much. Here are some resources that may help.


Bogon List

http://www.cymru.com/Documents/bogon-dd.html


ACL for DIACAP

http://kb.packetpros.com/?View=entry&EntryID=10


A site I used for building my list

http://www.unixhub.com/block.html


My list w/o Bogons

ip route 219.0.0.0 255.0.0.0 null0

ip route 22255.255.255.255 255.0.0.0 null0

ip route 221.0.0.0 255.0.0.0 null0

ip route 21255.255.255.255 255.0.0.0 null0

ip route 211.0.0.0 255.0.0.0 null0

ip route 20255.255.255.255 255.0.0.0 null0

ip route 209.67.38.99 255.255.255.255 null0

ip route 204.178.112.170 255.255.255.255 null0

ip route 205.138.3.62 255.255.255.255 null0

ip route 199.95.207.0 255.255.255.0 null0

ip route 199.95.208.0 255.255.255.0 null0

ip route 216.52.13.39 255.255.255.255 null0

ip route 216.52.13.23 255.255.255.255 null0

ip route 207.79.74.222 255.255.255.255 null0

ip route 209.122.130.0 255.255.255.0 null0

ip route 207.134.171.0 255.255.255.0 null0

ip route 62.253.164.0 255.255.255.0 null0

ip route 155.247.210.0 255.255.255.0 null0

ip route 61.77.78.0 255.255.255.0 null0

ip route 200.42.0.0 255.255.255.0 null0

ip route 193.252.19.0 255.255.255.0 null0

ip route 193.110.136.0 255.255.255.0 null0

ip route 67.96.136.0 255.255.255.0 null0

ip route 61.11.48.0 255.255.255.0 null0

ip route 209.63.68.0 255.255.255.0 null0

ip route 216.191.203.0 255.255.255.0 null0

ip route 209.125.37.0 255.255.255.0 null0

ip route 66.70.14.0 255.255.255.0 null0

ip route 64.80.217.0 255.255.255.0 null0

ip route 64.80.218.0 255.255.255.0 null0

ip route 202.108.44.0 255.255.255.0 null0

ip route 209.73.162.0 255.255.255.0 null0

ip route 66.7.131.0 255.255.255.0 null0

ip route 216.32.64.0 255.255.255.0 null0

ip route 168.95.4.0 255.255.255.0 null0

ip route 163.32.96.0 255.255.255.0 null0

ip route 207.253.100.0 255.255.255.0 null0

ip route 203.251.180.0 255.255.255.0 null0

ip route 195.53.182.0 255.255.255.0 null0

ip route 207.79.74.0 255.255.255.0 null0

ip route 200.212.99.0 255.255.255.0 null0

ip route 64.28.74.0 255.255.255.0 null0

ip route 210.145.137.0 255.255.255.0 null0

ip route 209.185.149.0 255.255.255.0 null0

ip route 216.33.104.0 255.255.255.0 null0

ip route 209.183.236.0 255.255.255.0 null0

ip route 202.219.52.0 255.255.255.0 null0

ip route 63.20.240.0 255.255.255.0 null0

ip route 210.123.152.0 255.255.255.0 null0

ip route 200.241.80.0 255.255.255.0 null0

ip route 194.21.74.0 255.255.255.0 null0

ip route 210.59.228.0 255.255.255.0 null0

ip route 150.57.60.0 255.255.255.0 null0

ip route 64.28.75.0 255.255.255.0 null0

ip route 209.121.135.0 255.255.255.0 null0

ip route 212.210.15.0 255.255.255.0 null0

ip route 216.35.159.0 255.255.255.0 null0

ip route 210.59.144.0 255.255.255.0 null0

ip route 192.106.88.0 255.255.255.0 null0

ip route 211.20.142.0 255.255.255.0 null0

ip route 202.96.194.0 255.255.255.0 null0

ip route 216.251.232.0 255.255.255.0 null0

ip route 202.242.18.0 255.255.255.0 null0

ip route 202.166.255.0 255.255.255.0 null0

ip route 206.190.171.0 255.255.255.0 null0

ip route 64.71.132.0 255.255.255.0 null0

ip route 64.1.242.0 255.255.255.0 null0

ip route 216.233.51.0 255.255.255.0 null0

ip route 216.233.69.0 255.255.255.0 null0

ip route 206.130.106.0 255.255.255.0 null0


HTH

Actions

This Discussion