Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

IP Blocking by Country?

We are considering a strategy of blacklisting or whitelisting IP by country.

Some questions:

1) Is there an easier method than adding lots of IP ranges (i.e. just specify a country)

2) What would be the performance considerations? i.e. how big of a list of IP ranges has to get before it starts to impact network throughput beyond neglible.

3) Are there better ways of achieving this objective, such as blocks at our ISP (AT&T) level, or specialized network appliances?

thanks for your answers in advance

  • Firewalling
1 REPLY

Re: IP Blocking by Country?

Chuck-

I have never found a really good way to block by Country, so I try and maintain a list. I send the network to null0 so it doesn't affect performance too much. Here are some resources that may help.

Bogon List

http://www.cymru.com/Documents/bogon-dd.html

ACL for DIACAP

http://kb.packetpros.com/?View=entry&EntryID=10

A site I used for building my list

http://www.unixhub.com/block.html

My list w/o Bogons

ip route 219.0.0.0 255.0.0.0 null0

ip route 22255.255.255.255 255.0.0.0 null0

ip route 221.0.0.0 255.0.0.0 null0

ip route 21255.255.255.255 255.0.0.0 null0

ip route 211.0.0.0 255.0.0.0 null0

ip route 20255.255.255.255 255.0.0.0 null0

ip route 209.67.38.99 255.255.255.255 null0

ip route 204.178.112.170 255.255.255.255 null0

ip route 205.138.3.62 255.255.255.255 null0

ip route 199.95.207.0 255.255.255.0 null0

ip route 199.95.208.0 255.255.255.0 null0

ip route 216.52.13.39 255.255.255.255 null0

ip route 216.52.13.23 255.255.255.255 null0

ip route 207.79.74.222 255.255.255.255 null0

ip route 209.122.130.0 255.255.255.0 null0

ip route 207.134.171.0 255.255.255.0 null0

ip route 62.253.164.0 255.255.255.0 null0

ip route 155.247.210.0 255.255.255.0 null0

ip route 61.77.78.0 255.255.255.0 null0

ip route 200.42.0.0 255.255.255.0 null0

ip route 193.252.19.0 255.255.255.0 null0

ip route 193.110.136.0 255.255.255.0 null0

ip route 67.96.136.0 255.255.255.0 null0

ip route 61.11.48.0 255.255.255.0 null0

ip route 209.63.68.0 255.255.255.0 null0

ip route 216.191.203.0 255.255.255.0 null0

ip route 209.125.37.0 255.255.255.0 null0

ip route 66.70.14.0 255.255.255.0 null0

ip route 64.80.217.0 255.255.255.0 null0

ip route 64.80.218.0 255.255.255.0 null0

ip route 202.108.44.0 255.255.255.0 null0

ip route 209.73.162.0 255.255.255.0 null0

ip route 66.7.131.0 255.255.255.0 null0

ip route 216.32.64.0 255.255.255.0 null0

ip route 168.95.4.0 255.255.255.0 null0

ip route 163.32.96.0 255.255.255.0 null0

ip route 207.253.100.0 255.255.255.0 null0

ip route 203.251.180.0 255.255.255.0 null0

ip route 195.53.182.0 255.255.255.0 null0

ip route 207.79.74.0 255.255.255.0 null0

ip route 200.212.99.0 255.255.255.0 null0

ip route 64.28.74.0 255.255.255.0 null0

ip route 210.145.137.0 255.255.255.0 null0

ip route 209.185.149.0 255.255.255.0 null0

ip route 216.33.104.0 255.255.255.0 null0

ip route 209.183.236.0 255.255.255.0 null0

ip route 202.219.52.0 255.255.255.0 null0

ip route 63.20.240.0 255.255.255.0 null0

ip route 210.123.152.0 255.255.255.0 null0

ip route 200.241.80.0 255.255.255.0 null0

ip route 194.21.74.0 255.255.255.0 null0

ip route 210.59.228.0 255.255.255.0 null0

ip route 150.57.60.0 255.255.255.0 null0

ip route 64.28.75.0 255.255.255.0 null0

ip route 209.121.135.0 255.255.255.0 null0

ip route 212.210.15.0 255.255.255.0 null0

ip route 216.35.159.0 255.255.255.0 null0

ip route 210.59.144.0 255.255.255.0 null0

ip route 192.106.88.0 255.255.255.0 null0

ip route 211.20.142.0 255.255.255.0 null0

ip route 202.96.194.0 255.255.255.0 null0

ip route 216.251.232.0 255.255.255.0 null0

ip route 202.242.18.0 255.255.255.0 null0

ip route 202.166.255.0 255.255.255.0 null0

ip route 206.190.171.0 255.255.255.0 null0

ip route 64.71.132.0 255.255.255.0 null0

ip route 64.1.242.0 255.255.255.0 null0

ip route 216.233.51.0 255.255.255.0 null0

ip route 216.233.69.0 255.255.255.0 null0

ip route 206.130.106.0 255.255.255.0 null0

HTH

130
Views
0
Helpful
1
Replies
This widget could not be displayed.