<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Block all Russia Public IP Addresses in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/block-all-russia-public-ip-addresses/m-p/2094303#M394725</link>
    <description>&lt;P&gt;Recently we have been taksed buy C level executives to block all ip communication to Russia. They are about 65,000 (CIDR aggregated) public ip addresses in China. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont want to manage an ACL with 65,000 entries not to mention how much larger it gets to add other countries. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions out there?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you &lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 00:32:25 GMT</pubDate>
    <dc:creator>efrazee</dc:creator>
    <dc:date>2019-03-12T00:32:25Z</dc:date>
    <item>
      <title>Block all Russia Public IP Addresses</title>
      <link>https://community.cisco.com/t5/network-security/block-all-russia-public-ip-addresses/m-p/2094303#M394725</link>
      <description>&lt;P&gt;Recently we have been taksed buy C level executives to block all ip communication to Russia. They are about 65,000 (CIDR aggregated) public ip addresses in China. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont want to manage an ACL with 65,000 entries not to mention how much larger it gets to add other countries. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions out there?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:32:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-all-russia-public-ip-addresses/m-p/2094303#M394725</guid>
      <dc:creator>efrazee</dc:creator>
      <dc:date>2019-03-12T00:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: Block all Russia Public IP Addresses</title>
      <link>https://community.cisco.com/t5/network-security/block-all-russia-public-ip-addresses/m-p/2094304#M394726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Duplicate post #2.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2012 01:56:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-all-russia-public-ip-addresses/m-p/2094304#M394726</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2012-12-05T01:56:06Z</dc:date>
    </item>
    <item>
      <title>Block all Russia Public IP Addresses</title>
      <link>https://community.cisco.com/t5/network-security/block-all-russia-public-ip-addresses/m-p/2094305#M394727</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if you have full bgp view so you can block&amp;nbsp; all russian as&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2012 05:00:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-all-russia-public-ip-addresses/m-p/2094305#M394727</guid>
      <dc:creator>Tagir Temirgaliyev</dc:creator>
      <dc:date>2012-12-05T05:00:44Z</dc:date>
    </item>
    <item>
      <title>Re: Block all Russia Public IP Addresses</title>
      <link>https://community.cisco.com/t5/network-security/block-all-russia-public-ip-addresses/m-p/2094306#M394728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check out the CountryIPBlock website. Here is a link to this cool feature where you put in a country and it can otput a Cisco router ACL for you &lt;A href="https://www.countryipblocks.net/country_selection.php" rel="nofollow"&gt;https://www.countryipblocks.net/country_selection.php&lt;/A&gt;. About a month ago I was instructed to block China and Iran on our Internet facing 2851's. I was concerned about what this would do to latency but we have no issues. When I was doing my research I found that Cisco uses a more efficient algorithm as of (I believe) 12.3T. I forget the details but it appears to be similiar to the turbo ACL feature that the PIX firewalls used. Except it works by default (like current ASA's do) and you do not have to manually compile the ACL. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just select the country, copy the text to notepad and you are ready to create the ACL on your router. I pasted the output for Russia in an Excel spreadsheet and got about 6500 lines.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2012 05:00:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-all-russia-public-ip-addresses/m-p/2094306#M394728</guid>
      <dc:creator>k-schwartz</dc:creator>
      <dc:date>2012-12-05T05:00:51Z</dc:date>
    </item>
    <item>
      <title>Re: Block all Russia Public IP Addresses</title>
      <link>https://community.cisco.com/t5/network-security/block-all-russia-public-ip-addresses/m-p/2094307#M394729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you K. I have see that tool and have been evaluating this option. We have concerns that the 100,000 ACL entries on the internet facing 3925's will be to much of a performance hit. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2012 16:21:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-all-russia-public-ip-addresses/m-p/2094307#M394729</guid>
      <dc:creator>efrazee</dc:creator>
      <dc:date>2012-12-05T16:21:10Z</dc:date>
    </item>
    <item>
      <title>Re: Block all Russia Public IP Addresses</title>
      <link>https://community.cisco.com/t5/network-security/block-all-russia-public-ip-addresses/m-p/2094308#M394730</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If it is just Russia it should be about 6500 lines. Blocking Iran and China was about 3900 lines. We implemented this on our 2851's and it cost about 1ms in latency. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2012 17:13:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-all-russia-public-ip-addresses/m-p/2094308#M394730</guid>
      <dc:creator>k-schwartz</dc:creator>
      <dc:date>2012-12-05T17:13:47Z</dc:date>
    </item>
    <item>
      <title>Re: Block all Russia Public IP Addresses</title>
      <link>https://community.cisco.com/t5/network-security/block-all-russia-public-ip-addresses/m-p/2094309#M394731</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;At Country IP Blocks our response to the problems associated with large Access Control Lists was to design a Network Aggregation Module as an add-on to our membership plans.Using this module usually results in some very significant reductions in the size of Country Specific ACLs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Examples (as of April 17, 2103 11:49 AM GMT -0700)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Aggregating networks in China reduces the overall list size by 25% (from 3,596 to 2,694 networks).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Russian aggregation reduces the list size to 5,906 networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Aggregation becomes more significant when you select multiple countries with more contiguous networks. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Combining networks in the United States and Canada:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Non-Aggregated Network: 50,282&lt;/P&gt;&lt;P&gt;Aggregated Networks: 12,751&lt;/P&gt;&lt;P&gt;Size Reduction: 74.64%&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our Network Aggregation Module reduces the number of networks within a selection of countries by first combining all the contiguous networks into the largest possible ranges and then processing that data to create an ACL with the fewest number of legal networks possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You can find out more about it by visiting our website at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.countryipblocks.net" rel="nofollow"&gt;http://www.countryipblocks.net&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we can be of further help please let us know.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Apr 2013 18:56:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-all-russia-public-ip-addresses/m-p/2094309#M394731</guid>
      <dc:creator>CountryIPBlocks</dc:creator>
      <dc:date>2013-04-17T18:56:00Z</dc:date>
    </item>
    <item>
      <title>Can you post a scrubbed copy</title>
      <link>https://community.cisco.com/t5/network-security/block-all-russia-public-ip-addresses/m-p/2094310#M394732</link>
      <description>&lt;P&gt;Can you post a scrubbed copy of the config?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2016 03:57:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-all-russia-public-ip-addresses/m-p/2094310#M394732</guid>
      <dc:creator>William Reed</dc:creator>
      <dc:date>2016-01-07T03:57:24Z</dc:date>
    </item>
  </channel>
</rss>

