<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Rob, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-5505-filtering-non-us-ips/m-p/2826818#M174536</link>
    <description>&lt;P&gt;Hi Rob,&lt;/P&gt;
&lt;P&gt;What is the size of the RAM in your ASA? is it 1GB?&lt;/P&gt;
&lt;P&gt;The ASA devices does not have limit as such to number of the ASA but each Access list element takes small byte from the RAM. So if you have very large amount of the access list element then you may face performance issue such as high memory. So for ASA5505 recommended access lsit elements are 25k.&lt;/P&gt;
&lt;P&gt;Since you have to block around 10k it should not be any problem.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show access-list | inc element will show the number of access list elements.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Shivapramod M&lt;BR /&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
    <pubDate>Thu, 26 Nov 2015 05:40:39 GMT</pubDate>
    <dc:creator>Shivapramod M</dc:creator>
    <dc:date>2015-11-26T05:40:39Z</dc:date>
    <item>
      <title>Cisco ASA 5505 - Filtering Non-US IPs?</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5505-filtering-non-us-ips/m-p/2826817#M174535</link>
      <description>I would like to filter all inbound Non-US IPv4 addresses at my Cisco ASA 5505’s outside interface.</description>
      <pubDate>Tue, 12 Mar 2019 06:57:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5505-filtering-non-us-ips/m-p/2826817#M174535</guid>
      <dc:creator>robertramsey</dc:creator>
      <dc:date>2019-03-12T06:57:05Z</dc:date>
    </item>
    <item>
      <title>Hi Rob,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5505-filtering-non-us-ips/m-p/2826818#M174536</link>
      <description>&lt;P&gt;Hi Rob,&lt;/P&gt;
&lt;P&gt;What is the size of the RAM in your ASA? is it 1GB?&lt;/P&gt;
&lt;P&gt;The ASA devices does not have limit as such to number of the ASA but each Access list element takes small byte from the RAM. So if you have very large amount of the access list element then you may face performance issue such as high memory. So for ASA5505 recommended access lsit elements are 25k.&lt;/P&gt;
&lt;P&gt;Since you have to block around 10k it should not be any problem.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show access-list | inc element will show the number of access list elements.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Shivapramod M&lt;BR /&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2015 05:40:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5505-filtering-non-us-ips/m-p/2826818#M174536</guid>
      <dc:creator>Shivapramod M</dc:creator>
      <dc:date>2015-11-26T05:40:39Z</dc:date>
    </item>
    <item>
      <title>Hello Shivapramod,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5505-filtering-non-us-ips/m-p/2826819#M174537</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN&gt;Shivapramod,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Based on your response, you're suggesting that there is no better/easy method to permit only US traffic (or deny all non-US&amp;nbsp;traffic)? &amp;nbsp;Is there a way to automate adding and updating a ~&lt;SPAN&gt;8,286 line ACL to my ASA?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I found several websites that provided example methodology&amp;nbsp;and syntax for downloading and converting the raw Arin list into a format I can use to build my own ACL. &amp;nbsp;I can automate that part of the process with a Linux cron job. &amp;nbsp;However, I haven't found any methods to automatically update my ASA.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Do you have any suggestions on how to automate updating my ASA ACL config?&lt;/P&gt;
&lt;P&gt;To answer your question, my ASA has 512MB RAM. &amp;nbsp;I could upgrade it to 1GB if needed (memory is cheap). &amp;nbsp;Reguardless, I still have the problem of entering a&amp;nbsp;&lt;SPAN&gt;8,286 line ACL into my ASA's configuration.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Thanks in advance,&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2015 15:05:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5505-filtering-non-us-ips/m-p/2826819#M174537</guid>
      <dc:creator>robertramsey</dc:creator>
      <dc:date>2015-11-27T15:05:37Z</dc:date>
    </item>
  </channel>
</rss>

