Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

PIX 515 Blocking non-US IPs

Is there a way to block all IPs from outside the US on a PIX 515e version 7.1(1)?

3 REPLIES

Re: PIX 515 Blocking non-US IPs

Is this from the inside going outside? or outside coming in?

Either way - it would be an exercise in futility.

You bascially talking about blocking 80% of the routable terresteral internet IP space.

New Member

Re: PIX 515 Blocking non-US IPs

This would be outside coming in. I know that there is a ton of IP space to block, I could do it with a bunch of access lists using class A or B subnets assigned to RIPE, APNIC,LACNIC, and AfriNIC but I was wondering if there was some easier way?

Thanks,

Brandon

Re: PIX 515 Blocking non-US IPs

Of course there is an easier way - just allow the subnets you want to come in, then the default deny all is applied!

130
Views
0
Helpful
3
Replies
CreatePlease login to create content