<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Block multiple IP's at firewall level in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/block-multiple-ip-s-at-firewall-level/m-p/2914281#M154860</link>
    <description>&lt;P&gt;Hope I'm putting this int he right place. &amp;nbsp;We have an RV325 and I would like to set up rules to block a relatively large list of ipv4 IP addresses from accessing&amp;nbsp;our systems. &amp;nbsp;I obtained these IP addresses from security logs on to our email server, for example (numerous failed attempts to log in within relatively short periods of time). &amp;nbsp;Via the UI, it seems I can only enter one range at a time, which would be quite tedious in this instance.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Additionally, am I correct in assuming that&amp;nbsp;I need to block these IP's as "Source IP"?&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 07:36:45 GMT</pubDate>
    <dc:creator>gkuvin2016</dc:creator>
    <dc:date>2019-03-12T07:36:45Z</dc:date>
    <item>
      <title>Block multiple IP's at firewall level</title>
      <link>https://community.cisco.com/t5/network-security/block-multiple-ip-s-at-firewall-level/m-p/2914281#M154860</link>
      <description>&lt;P&gt;Hope I'm putting this int he right place. &amp;nbsp;We have an RV325 and I would like to set up rules to block a relatively large list of ipv4 IP addresses from accessing&amp;nbsp;our systems. &amp;nbsp;I obtained these IP addresses from security logs on to our email server, for example (numerous failed attempts to log in within relatively short periods of time). &amp;nbsp;Via the UI, it seems I can only enter one range at a time, which would be quite tedious in this instance.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Additionally, am I correct in assuming that&amp;nbsp;I need to block these IP's as "Source IP"?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:36:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-multiple-ip-s-at-firewall-level/m-p/2914281#M154860</guid>
      <dc:creator>gkuvin2016</dc:creator>
      <dc:date>2019-03-12T07:36:45Z</dc:date>
    </item>
    <item>
      <title>I'll answer this myself,</title>
      <link>https://community.cisco.com/t5/network-security/block-multiple-ip-s-at-firewall-level/m-p/2914282#M154861</link>
      <description>&lt;P&gt;I'll answer this myself, since I got no replies and have more or less figured this out.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;There are apparently ways to interact with the router at a level that will allow this kind of "batching", but I didn't have the time or patience to learn for myself. &amp;nbsp;I did try manually editing a configuration file myself to add additional access rules, but it threw an error when I tried to import. &amp;nbsp;So I ended up manually entering each of the ranges, which wasn't as bad as it seemed it would have been at first. &amp;nbsp;I have 34 ranges&amp;nbsp;set up, it took me less than an hour to get all this done.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;As for the "Source IP" question, and for anyone who needs help blocking specific IP's or IP ranges, here is how I am configuring mine:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Action: Deny&lt;/P&gt;
&lt;P&gt;Service: All Traffic [TCP&amp;amp;UDP/1~65535]&lt;/P&gt;
&lt;P&gt;Log: Log packets matching this rule&lt;/P&gt;
&lt;P&gt;Source Interface: ANY&lt;/P&gt;
&lt;P&gt;Source IP: (Single or Range, this will depend on your specific needs)&lt;/P&gt;
&lt;P&gt;Destination IP: ANY&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I don't do any scheduling, the rules I have put in place, need to be active 24/7. &amp;nbsp;But, that part should be pretty self-explanatory.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2016 20:33:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-multiple-ip-s-at-firewall-level/m-p/2914282#M154861</guid>
      <dc:creator>gkuvin2016</dc:creator>
      <dc:date>2016-07-07T20:33:02Z</dc:date>
    </item>
  </channel>
</rss>

