<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How best to block countries IP addresses via ASDM/ASA (5555) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288131#M1078275</link>
    <description>&lt;P&gt;Look up the past my suggested post has information.&lt;/P&gt;</description>
    <pubDate>Mon, 08 Feb 2021 16:42:27 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2021-02-08T16:42:27Z</dc:date>
    <item>
      <title>How best to block countries IP addresses via ASDM/ASA (5555)</title>
      <link>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288068#M1078257</link>
      <description>&lt;P&gt;Hi All, I am looking for some advice on how to block some country's IP addresses on our ASA 5555 firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On firepower its quite easy we get the option of Geolocation but on the ASA I cant see a convenient way of doing this. Has anyone had any experience in doing this, or advise me on how best to do this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance for all the help.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 15:36:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288068#M1078257</guid>
      <dc:creator>Ciscoguy85</dc:creator>
      <dc:date>2021-02-08T15:36:36Z</dc:date>
    </item>
    <item>
      <title>Re: How best to block countries IP addresses via ASDM/ASA (5555)</title>
      <link>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288074#M1078258</link>
      <description>&lt;P&gt;On ASA you need to do still manual entries as per i know.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;here is script help you :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/in-transit/regional-asa" target="_blank"&gt;https://github.com/in-transit/regional-asa&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 15:45:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288074#M1078258</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-02-08T15:45:12Z</dc:date>
    </item>
    <item>
      <title>Re: How best to block countries IP addresses via ASDM/ASA (5555)</title>
      <link>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288075#M1078259</link>
      <description>&lt;P&gt;There isn't one. In Firepower you are getting the geolocation database updates periodically to account for all the IP addresses moving around the globe. In ASA there is no such feed. You have to go to a NGFW such as Firepower to get that feature.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 15:45:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288075#M1078259</guid>
      <dc:creator>TJ-20933766</dc:creator>
      <dc:date>2021-02-08T15:45:55Z</dc:date>
    </item>
    <item>
      <title>Re: How best to block countries IP addresses via ASDM/ASA (5555)</title>
      <link>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288080#M1078260</link>
      <description>&lt;P&gt;Thank you Balaji.bandi.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;im not quite sure how to interpret the script details you sent.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 15:50:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288080#M1078260</guid>
      <dc:creator>Ciscoguy85</dc:creator>
      <dc:date>2021-02-08T15:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: How best to block countries IP addresses via ASDM/ASA (5555)</title>
      <link>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288085#M1078263</link>
      <description>&lt;P&gt;Thanks for your response&amp;nbsp;&lt;SPAN&gt;Tyson Joachims. I had a feeling&amp;nbsp;that would be the case.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have found a website,&amp;nbsp;&lt;A href="https://www.countryipblocks.net/acl.php" target="_blank"&gt;https://www.countryipblocks.net/acl.php&lt;/A&gt;&amp;nbsp;that allows you to select the countries you require and generate ACL's for each subnet range or create network objects for each subnet range. My only reluctance to this is how reliable and up to date the ranges are.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am doing it based on 3 countries so this will be going into the thousands which ever option I choose.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 15:55:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288085#M1078263</guid>
      <dc:creator>Ciscoguy85</dc:creator>
      <dc:date>2021-02-08T15:55:21Z</dc:date>
    </item>
    <item>
      <title>Re: How best to block countries IP addresses via ASDM/ASA (5555)</title>
      <link>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288089#M1078265</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Just small addon from my end. You can enable rest api on asa then use an&lt;BR /&gt;intermediate server with a script (there are many available online) to&lt;BR /&gt;query open source geo feed and update an object group in asa. This can be&lt;BR /&gt;scheduled once a day. Not a complex task and there are python scripts&lt;BR /&gt;available online for geo feeds.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;***** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Mon, 08 Feb 2021 16:01:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288089#M1078265</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2021-02-08T16:01:29Z</dc:date>
    </item>
    <item>
      <title>Re: How best to block countries IP addresses via ASDM/ASA (5555)</title>
      <link>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288091#M1078266</link>
      <description>&lt;P&gt;It is possible to manually lookup the current geolocation for IP addresses but the process exponentially takes up more time the more countries you are trying to nail down and the number of firewalls you are maintaining. Every day you'd have to recheck all those IP addresses because an IP may have moved to an adjacent country and should no longer be blocked. It's more pain than it's worth for many people&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 16:02:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288091#M1078266</guid>
      <dc:creator>TJ-20933766</dc:creator>
      <dc:date>2021-02-08T16:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: How best to block countries IP addresses via ASDM/ASA (5555)</title>
      <link>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288093#M1078267</link>
      <description>&lt;P&gt;Do you have any instructions for this? Website guides or anything? I'm interested to see more on this topic&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 16:03:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288093#M1078267</guid>
      <dc:creator>TJ-20933766</dc:creator>
      <dc:date>2021-02-08T16:03:17Z</dc:date>
    </item>
    <item>
      <title>Re: How best to block countries IP addresses via ASDM/ASA (5555)</title>
      <link>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288095#M1078269</link>
      <description>&lt;P&gt;its script it you run them you get geo based List of the IP address, you need to group those IP address Manually in to ASA and block it with ACL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or you can use below API enable and make it work for you easy way&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/api/qsg-asa-api.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/api/qsg-asa-api.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;good blog may help you :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://medium.com/@daniela.mh20/rest-api-for-cisco-asa-3374a22d2e24" target="_blank"&gt;https://medium.com/@daniela.mh20/rest-api-for-cisco-asa-3374a22d2e24&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 16:06:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288095#M1078269</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-02-08T16:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: How best to block countries IP addresses via ASDM/ASA (5555)</title>
      <link>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288105#M1078270</link>
      <description>&lt;P&gt;Thanks &lt;SPAN&gt;Mohammed al Baqari,&amp;nbsp;&lt;/SPAN&gt;that sounds like a good solution. Can you direct me to any websites or guides on this? Seems like there is a few us that could benefit from this.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 16:16:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288105#M1078270</guid>
      <dc:creator>Ciscoguy85</dc:creator>
      <dc:date>2021-02-08T16:16:07Z</dc:date>
    </item>
    <item>
      <title>Re: How best to block countries IP addresses via ASDM/ASA (5555)</title>
      <link>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288106#M1078271</link>
      <description>&lt;P&gt;The script is intended to be run on a Unix host. Copy country.list and regional-asa.sh to a folder on your host. Make the .sh file executable (chmod +x regional-asa.sh). Then run it. Based on your inputs, it will generate a file with a listing of network objects and an object-group that you could then use in an ASA ACL.&lt;/P&gt;
&lt;P&gt;To be honest, most people don't go to the trouble since the listings end up being huge and may even exceed the capability of an ASA if you were to, for example, try to exclude all of a region like Asia.&lt;/P&gt;
&lt;P&gt;Example of running the script:&lt;/P&gt;
&lt;PRE&gt;root@eve-ng:~/asa# ls -al
total 3256
drwxr-xr-x 2 root root    4096 Feb  8 18:03 .
drwx------ 5 root root    4096 Feb  8 17:58 ..
-rw-r--r-- 1 root root    4248 Feb  8 18:03 country.list
-rwxrwxrwx 1 root root    8768 Feb  8 17:59 regional-asa.sh
root@eve-ng:~/asa# ./regional-asa.sh
Please choose the authority you would like to acquire addresses from.
1. ARIN
2. LACNIC
3. APNIC
4. AfriNIC
5. RIPE
 
[1-5]? 3
--2021-02-08 18:03:41--  ftp://ftp.apnic.net/pub/stats/apnic/delegated-apnic-latest
           =&amp;gt; 'APNIC.orig'
Resolving ftp.apnic.net (ftp.apnic.net)... 202.12.29.205, 2001:dc0:2001:11::205
Connecting to ftp.apnic.net (ftp.apnic.net)|202.12.29.205|:21... connected.
Logging in as anonymous ... Logged in!
==&amp;gt; SYST ... done.    ==&amp;gt; PWD ... done.
==&amp;gt; TYPE I ... done.  ==&amp;gt; CWD (1) /pub/stats/apnic ... done.
==&amp;gt; SIZE delegated-apnic-latest ... 3303673
==&amp;gt; PASV ... done.    ==&amp;gt; RETR delegated-apnic-latest ... done.
Length: 3303673 (3.2M) (unauthoritative)

delegated-apnic-latest            100%[============================================================&amp;gt;]   3.15M  1.00MB/s    in 3.2s    

2021-02-08 18:03:45 (1.00 MB/s) - 'APNIC.orig' saved [3303673]


Would you like to specify a country?
[y/n]? y

Please enter the name or part of the country's english name. Mal
0  :  FK - Falkland Islands (Malvinas)
1  :  GT - Guatemala
2  :  ML - Mali
3  :  MT - Malta
4  :  MV - Maldives
5  :  MW - Malawi
6  :  MY - Malaysia
7  :  SO - Somalia
8  :  None of the above
Please select the nubmer associated with the country you desire.
[0-8]? 6
You have selected:  MY - Malaysia
MY
Creation of APNIC.cidr has started.
Creation of APNIC.cidr has finshed.
Creation of APNIC.conf has started.
 54 / 154 
Creation of APNIC.cidr has finished.
root@eve-ng:~/asa# ls -al
total 3276
drwxr-xr-x 2 root root    4096 Feb  8 18:03 .
drwx------ 5 root root    4096 Feb  8 17:58 ..
-rw-r--r-- 1 root root    2464 Feb  8 18:03 APNIC.cidr
-rw-r--r-- 1 root root   13675 Feb  8 18:03 APNIC.conf
-rw-r--r-- 1 root root 3303673 Feb  8 18:03 APNIC.orig
-rw-r--r-- 1 root root    4248 Feb  8 18:03 country.list
-rwxrwxrwx 1 root root    8768 Feb  8 17:59 regional-asa.sh
root@eve-ng:~/asa# 
root@eve-ng:~/asa# more APNIC.conf&lt;BR /&gt;object network APNIC1&lt;BR /&gt;subnet 43.228.244.0 255.255.252.0&lt;BR /&gt;object network APNIC2&lt;BR /&gt;subnet 43.228.248.0 255.255.252.0&lt;BR /&gt;object network APNIC3&lt;BR /&gt;subnet 43.251.18.0 255.255.254.0&lt;BR /&gt;...&lt;BR /&gt;(omitted objects 4-153)&lt;BR /&gt;...&lt;BR /&gt;object network APNIC154&lt;BR /&gt;subnet 218.100.75.0 255.255.255.0&lt;BR /&gt;object-group network APNIC&lt;BR /&gt;network-object object APNIC1&lt;BR /&gt;network-object object APNIC2&lt;BR /&gt;network-object object APNIC3&lt;BR /&gt;network-object object APNIC4&lt;BR /&gt;...&lt;BR /&gt;(omitted the remaining objects in the object-group)&lt;BR /&gt;...&lt;BR /&gt;root@eve-ng:~/asa#
&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 16:19:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288106#M1078271</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-02-08T16:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: How best to block countries IP addresses via ASDM/ASA (5555)</title>
      <link>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288111#M1078272</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;See this for example. The idea is not to query per packet but rather&lt;BR /&gt;dowbload csv database daily, modify its format, then update ASA object&lt;BR /&gt;group. From ASA it looks as new config applied using reset, e.g.&lt;BR /&gt;blocked_loc_object. The script should decide which locations should be&lt;BR /&gt;updated im object group based on admin preference. I don't have anything&lt;BR /&gt;with me now but I remember testing it when reset was introduced in ASA&lt;BR /&gt;couple of years back.&lt;BR /&gt;&lt;BR /&gt;With reset and python on a Linux box you can make ASA do advanced stuff but&lt;BR /&gt;FTD made it out of the box&lt;BR /&gt;&lt;BR /&gt;***** please remember to rate useful posts&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.lir.services/blog/ip-geolocation/" target="_blank"&gt;https://www.lir.services/blog/ip-geolocation/&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 08 Feb 2021 16:21:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288111#M1078272</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2021-02-08T16:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: How best to block countries IP addresses via ASDM/ASA (5555)</title>
      <link>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288113#M1078273</link>
      <description>Thx &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt; for posting this. I was typing and didn't see your input&lt;BR /&gt;coming in. So we are on the same page &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 08 Feb 2021 16:23:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288113#M1078273</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2021-02-08T16:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: How best to block countries IP addresses via ASDM/ASA (5555)</title>
      <link>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288131#M1078275</link>
      <description>&lt;P&gt;Look up the past my suggested post has information.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 16:42:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4288131#M1078275</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-02-08T16:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: How best to block countries IP addresses via ASDM/ASA (5555)</title>
      <link>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4770521#M1097568</link>
      <description>&lt;P&gt;Hi Mohammed!&lt;/P&gt;&lt;P&gt;what do you mean by "&lt;SPAN&gt;With reset and python on a Linux box&lt;/SPAN&gt;"&lt;BR /&gt;i have the same task. block some&amp;nbsp; contries&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 15:51:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-best-to-block-countries-ip-addresses-via-asdm-asa-5555/m-p/4770521#M1097568</guid>
      <dc:creator>netmail</dc:creator>
      <dc:date>2023-02-07T15:51:34Z</dc:date>
    </item>
  </channel>
</rss>

