cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
24612
Views
5
Helpful
5
Replies

ASA 5520 IP range block or Country IP block

rabih_saleh
Level 1
Level 1

hi,

i need help on ASA 5520 and i would like to block countries IP address from the attack, there is any way to block countries ip address or range ip address .

Thanks,

Rabih

2 Accepted Solutions

Accepted Solutions

Jennifer Halim
Cisco Employee
Cisco Employee

Here is the URL on how to check what IP Range the countries has:

http://www.find-ip-address.org/ip-country/

(NB: pls scroll down to the bottom of the page, choose the country and hit "Submit").

Hope that helps.

View solution in original post

puseth
Level 1
Level 1

You can get the country ip blocks from here:-http://www.countryipblocks.net/country-blocks/19/

And then you can implement ACL's to block traffic coming in from these subnet range's.

Thanks

Puneet

View solution in original post

5 Replies 5

Jennifer Halim
Cisco Employee
Cisco Employee

Here is the URL on how to check what IP Range the countries has:

http://www.find-ip-address.org/ip-country/

(NB: pls scroll down to the bottom of the page, choose the country and hit "Submit").

Hope that helps.

Can I allow just one country and kick the rest off the world out ? As the usa has over 50 .000 ip,s the list of deny will be huge

puseth
Level 1
Level 1

You can get the country ip blocks from here:-http://www.countryipblocks.net/country-blocks/19/

And then you can implement ACL's to block traffic coming in from these subnet range's.

Thanks

Puneet

jdarnellacsmi
Level 1
Level 1

I've created a script where you chose an authority by selecting in a menu and it'll give you the configuration to drop into the ASA. 

https://github.com/in-transit/regional-asa

You can block or allow a specific region if you want. I'll be upgrading it to do specific countries but now it does authorities like ARIN, RIPE, APNIC, etc.

Do you have an updated script?  I know this is old, just wondering if you've updated it lately.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card