<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic To Block traffic base on country at Cisco ASA 5515-X in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/to-block-traffic-base-on-country-at-cisco-asa-5515-x/m-p/4737553#M1095881</link>
    <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;I would like to ask some help that i want to do deny policy at cisco ASA 5515-X base on country. i think it is layer 4 firewall, it is not possible, but i would like to make sure. Anyone can help for it? Thanks much.&lt;/P&gt;</description>
    <pubDate>Tue, 13 Dec 2022 04:04:12 GMT</pubDate>
    <dc:creator>journey jane</dc:creator>
    <dc:date>2022-12-13T04:04:12Z</dc:date>
    <item>
      <title>To Block traffic base on country at Cisco ASA 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/to-block-traffic-base-on-country-at-cisco-asa-5515-x/m-p/4737553#M1095881</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;I would like to ask some help that i want to do deny policy at cisco ASA 5515-X base on country. i think it is layer 4 firewall, it is not possible, but i would like to make sure. Anyone can help for it? Thanks much.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 04:04:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/to-block-traffic-base-on-country-at-cisco-asa-5515-x/m-p/4737553#M1095881</guid>
      <dc:creator>journey jane</dc:creator>
      <dc:date>2022-12-13T04:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: To Block traffic base on country at Cisco ASA 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/to-block-traffic-base-on-country-at-cisco-asa-5515-x/m-p/4737558#M1095882</link>
      <description>&lt;P&gt;you can do this by configuring firepower with ASA. do you have firepower module installed in ASA?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 05:11:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/to-block-traffic-base-on-country-at-cisco-asa-5515-x/m-p/4737558#M1095882</guid>
      <dc:creator>Kasun Bandara</dc:creator>
      <dc:date>2022-12-13T05:11:44Z</dc:date>
    </item>
    <item>
      <title>Re: To Block traffic base on country at Cisco ASA 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/to-block-traffic-base-on-country-at-cisco-asa-5515-x/m-p/4737561#M1095883</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/182793"&gt;@Kasun Bandara&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have no firepower module installed. it is just layer 4 firewall and managed by asdm. Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 05:29:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/to-block-traffic-base-on-country-at-cisco-asa-5515-x/m-p/4737561#M1095883</guid>
      <dc:creator>journey jane</dc:creator>
      <dc:date>2022-12-13T05:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: To Block traffic base on country at Cisco ASA 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/to-block-traffic-base-on-country-at-cisco-asa-5515-x/m-p/4737567#M1095884</link>
      <description>&lt;P&gt;in that case, its really hard because you need to find network blocks assigned for each country and create rules. recommended way is to use Firepower. or have&amp;nbsp; firewall with country list blocking/allow features&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 06:05:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/to-block-traffic-base-on-country-at-cisco-asa-5515-x/m-p/4737567#M1095884</guid>
      <dc:creator>Kasun Bandara</dc:creator>
      <dc:date>2022-12-13T06:05:42Z</dc:date>
    </item>
    <item>
      <title>Re: To Block traffic base on country at Cisco ASA 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/to-block-traffic-base-on-country-at-cisco-asa-5515-x/m-p/4737601#M1095887</link>
      <description>&lt;P&gt;See this site. If you are handy with Python or large text editing operations, you can massage the generated ACLs for direct input into the ASA. I have a script I can dig up possibly let me know if you need it.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.countryipblocks.net/acl.php" target="_blank"&gt;https://www.countryipblocks.net/acl.php&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You can build your own ACLs and import them into the ASA config&lt;/P&gt;&lt;P&gt;Depending on which ASA you have, performance can be an issue. Before Firepower, I implemented these for a few large countries and my ACL had 10,000 ACEs which was on a 5525. Just be aware you will want console access in case you overwhelm your ASA. Do not save the config until you test and determine performance.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 07:09:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/to-block-traffic-base-on-country-at-cisco-asa-5515-x/m-p/4737601#M1095887</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2022-12-13T07:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: To Block traffic base on country at Cisco ASA 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/to-block-traffic-base-on-country-at-cisco-asa-5515-x/m-p/4737639#M1095891</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/182793"&gt;@Kasun Bandara&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can i use whitelist for those ip addresses at asa 5515-x? May it work? coz i have never been before. thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 08:56:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/to-block-traffic-base-on-country-at-cisco-asa-5515-x/m-p/4737639#M1095891</guid>
      <dc:creator>journey jane</dc:creator>
      <dc:date>2022-12-13T08:56:28Z</dc:date>
    </item>
    <item>
      <title>Re: To Block traffic base on country at Cisco ASA 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/to-block-traffic-base-on-country-at-cisco-asa-5515-x/m-p/4737682#M1095892</link>
      <description>&lt;P&gt;you can create address groups for each country in ASDM which have IP address ranges for respective country. and use them in access lists to allow or deny traffic. but this is very difficult because 1st you need to find and list down IP address ranges related to countries (IPv4/IPv6) and create long lists of ranges in groups. also these mappings may change dynamically in future. so manually doing it is not recommended and not easy. if you know exact IPs to block or allow, you can configure them with access lists.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 09:19:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/to-block-traffic-base-on-country-at-cisco-asa-5515-x/m-p/4737682#M1095892</guid>
      <dc:creator>Kasun Bandara</dc:creator>
      <dc:date>2022-12-13T09:19:39Z</dc:date>
    </item>
    <item>
      <title>Re: To Block traffic base on country at Cisco ASA 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/to-block-traffic-base-on-country-at-cisco-asa-5515-x/m-p/4737877#M1095907</link>
      <description>&lt;P&gt;You can do this in theory as noted by the other responders in this thread. In practice, however, it is a losing proposition.&lt;/P&gt;
&lt;P&gt;It is much less work and much more effective to just get a proper modern firewall running FTD where this feature is built-in and requires on a few clicks to turn on.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 14:06:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/to-block-traffic-base-on-country-at-cisco-asa-5515-x/m-p/4737877#M1095907</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-12-13T14:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: To Block traffic base on country at Cisco ASA 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/to-block-traffic-base-on-country-at-cisco-asa-5515-x/m-p/4737900#M1095909</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/182793"&gt;@Kasun Bandara&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help. let me try with this way.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 14:54:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/to-block-traffic-base-on-country-at-cisco-asa-5515-x/m-p/4737900#M1095909</guid>
      <dc:creator>journey jane</dc:creator>
      <dc:date>2022-12-13T14:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: To Block traffic base on country at Cisco ASA 5515-X</title>
      <link>https://community.cisco.com/t5/network-security/to-block-traffic-base-on-country-at-cisco-asa-5515-x/m-p/4737904#M1095910</link>
      <description>&lt;P&gt;Your suggestion is valid. Thanks much.&amp;nbsp;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 14:57:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/to-block-traffic-base-on-country-at-cisco-asa-5515-x/m-p/4737904#M1095910</guid>
      <dc:creator>journey jane</dc:creator>
      <dc:date>2022-12-13T14:57:38Z</dc:date>
    </item>
  </channel>
</rss>

