<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IP Blocking by Country? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ip-blocking-by-country/m-p/957880#M940062</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Chuck-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have never found a really good way to block by Country, so I try and maintain a list. I send the network to null0 so it doesn't affect performance too much. Here are some resources that may help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bogon List&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cymru.com/Documents/bogon-dd.html" target="_blank"&gt;http://www.cymru.com/Documents/bogon-dd.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACL for DIACAP&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://kb.packetpros.com/?View=entry&amp;amp;EntryID=10" target="_blank"&gt;http://kb.packetpros.com/?View=entry&amp;amp;EntryID=10&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A site I used for building my list&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.unixhub.com/block.html" target="_blank"&gt;http://www.unixhub.com/block.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My list w/o Bogons&lt;/P&gt;&lt;P&gt;ip route 219.0.0.0 255.0.0.0 null0&lt;/P&gt;&lt;P&gt;ip route 22255.255.255.255 255.0.0.0 null0&lt;/P&gt;&lt;P&gt;ip route 221.0.0.0 255.0.0.0 null0&lt;/P&gt;&lt;P&gt;ip route 21255.255.255.255 255.0.0.0 null0&lt;/P&gt;&lt;P&gt;ip route 211.0.0.0 255.0.0.0 null0&lt;/P&gt;&lt;P&gt;ip route 20255.255.255.255 255.0.0.0 null0&lt;/P&gt;&lt;P&gt;ip route 209.67.38.99  255.255.255.255 null0&lt;/P&gt;&lt;P&gt;ip route 204.178.112.170  255.255.255.255 null0&lt;/P&gt;&lt;P&gt;ip route 205.138.3.62   255.255.255.255 null0&lt;/P&gt;&lt;P&gt;ip route 199.95.207.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 199.95.208.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 216.52.13.39  255.255.255.255 null0&lt;/P&gt;&lt;P&gt;ip route 216.52.13.23  255.255.255.255 null0&lt;/P&gt;&lt;P&gt;ip route 207.79.74.222 255.255.255.255 null0&lt;/P&gt;&lt;P&gt;ip route 209.122.130.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 207.134.171.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 62.253.164.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 155.247.210.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 61.77.78.0 255.255.255.0     null0&lt;/P&gt;&lt;P&gt;ip route 200.42.0.0 255.255.255.0     null0&lt;/P&gt;&lt;P&gt;ip route 193.252.19.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 193.110.136.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 67.96.136.0 255.255.255.0    null0&lt;/P&gt;&lt;P&gt;ip route 61.11.48.0 255.255.255.0     null0&lt;/P&gt;&lt;P&gt;ip route 209.63.68.0 255.255.255.0    null0&lt;/P&gt;&lt;P&gt;ip route 216.191.203.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 209.125.37.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 66.70.14.0 255.255.255.0     null0&lt;/P&gt;&lt;P&gt;ip route 64.80.217.0 255.255.255.0    null0&lt;/P&gt;&lt;P&gt;ip route 64.80.218.0 255.255.255.0    null0&lt;/P&gt;&lt;P&gt;ip route 202.108.44.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 209.73.162.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 66.7.131.0 255.255.255.0     null0&lt;/P&gt;&lt;P&gt;ip route 216.32.64.0 255.255.255.0    null0&lt;/P&gt;&lt;P&gt;ip route 168.95.4.0 255.255.255.0     null0&lt;/P&gt;&lt;P&gt;ip route 163.32.96.0 255.255.255.0    null0&lt;/P&gt;&lt;P&gt;ip route 207.253.100.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 203.251.180.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 195.53.182.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 207.79.74.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 200.212.99.0 255.255.255.0 null0&lt;/P&gt;&lt;P&gt;ip route 64.28.74.0 255.255.255.0 null0&lt;/P&gt;&lt;P&gt;ip route 210.145.137.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 209.185.149.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 216.33.104.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 209.183.236.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 202.219.52.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 63.20.240.0 255.255.255.0    null0&lt;/P&gt;&lt;P&gt;ip route 210.123.152.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 200.241.80.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 194.21.74.0 255.255.255.0    null0&lt;/P&gt;&lt;P&gt;ip route 210.59.228.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 150.57.60.0 255.255.255.0    null0&lt;/P&gt;&lt;P&gt;ip route 64.28.75.0 255.255.255.0     null0&lt;/P&gt;&lt;P&gt;ip route 209.121.135.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 212.210.15.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 216.35.159.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 210.59.144.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 192.106.88.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 211.20.142.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 202.96.194.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 216.251.232.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 202.242.18.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 202.166.255.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 206.190.171.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 64.71.132.0 255.255.255.0    null0&lt;/P&gt;&lt;P&gt;ip route 64.1.242.0 255.255.255.0     null0&lt;/P&gt;&lt;P&gt;ip route 216.233.51.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 216.233.69.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 206.130.106.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 01 Apr 2008 13:36:49 GMT</pubDate>
    <dc:creator>Collin Clark</dc:creator>
    <dc:date>2008-04-01T13:36:49Z</dc:date>
    <item>
      <title>IP Blocking by Country?</title>
      <link>https://community.cisco.com/t5/network-security/ip-blocking-by-country/m-p/957879#M940061</link>
      <description>&lt;P&gt;We are considering a strategy of blacklisting or whitelisting IP by country. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Is there an easier method than adding lots of IP ranges (i.e. just specify a country)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) What would be the performance considerations? i.e. how big of a list of IP ranges has to get before it starts to impact network throughput beyond neglible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Are there better ways of achieving this objective, such as blocks at our ISP (AT&amp;amp;T) level, or specialized network appliances? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your answers in advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:24:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-blocking-by-country/m-p/957879#M940061</guid>
      <dc:creator>chuck.beach</dc:creator>
      <dc:date>2019-03-11T12:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: IP Blocking by Country?</title>
      <link>https://community.cisco.com/t5/network-security/ip-blocking-by-country/m-p/957880#M940062</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Chuck-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have never found a really good way to block by Country, so I try and maintain a list. I send the network to null0 so it doesn't affect performance too much. Here are some resources that may help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bogon List&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cymru.com/Documents/bogon-dd.html" target="_blank"&gt;http://www.cymru.com/Documents/bogon-dd.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACL for DIACAP&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://kb.packetpros.com/?View=entry&amp;amp;EntryID=10" target="_blank"&gt;http://kb.packetpros.com/?View=entry&amp;amp;EntryID=10&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A site I used for building my list&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.unixhub.com/block.html" target="_blank"&gt;http://www.unixhub.com/block.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My list w/o Bogons&lt;/P&gt;&lt;P&gt;ip route 219.0.0.0 255.0.0.0 null0&lt;/P&gt;&lt;P&gt;ip route 22255.255.255.255 255.0.0.0 null0&lt;/P&gt;&lt;P&gt;ip route 221.0.0.0 255.0.0.0 null0&lt;/P&gt;&lt;P&gt;ip route 21255.255.255.255 255.0.0.0 null0&lt;/P&gt;&lt;P&gt;ip route 211.0.0.0 255.0.0.0 null0&lt;/P&gt;&lt;P&gt;ip route 20255.255.255.255 255.0.0.0 null0&lt;/P&gt;&lt;P&gt;ip route 209.67.38.99  255.255.255.255 null0&lt;/P&gt;&lt;P&gt;ip route 204.178.112.170  255.255.255.255 null0&lt;/P&gt;&lt;P&gt;ip route 205.138.3.62   255.255.255.255 null0&lt;/P&gt;&lt;P&gt;ip route 199.95.207.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 199.95.208.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 216.52.13.39  255.255.255.255 null0&lt;/P&gt;&lt;P&gt;ip route 216.52.13.23  255.255.255.255 null0&lt;/P&gt;&lt;P&gt;ip route 207.79.74.222 255.255.255.255 null0&lt;/P&gt;&lt;P&gt;ip route 209.122.130.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 207.134.171.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 62.253.164.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 155.247.210.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 61.77.78.0 255.255.255.0     null0&lt;/P&gt;&lt;P&gt;ip route 200.42.0.0 255.255.255.0     null0&lt;/P&gt;&lt;P&gt;ip route 193.252.19.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 193.110.136.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 67.96.136.0 255.255.255.0    null0&lt;/P&gt;&lt;P&gt;ip route 61.11.48.0 255.255.255.0     null0&lt;/P&gt;&lt;P&gt;ip route 209.63.68.0 255.255.255.0    null0&lt;/P&gt;&lt;P&gt;ip route 216.191.203.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 209.125.37.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 66.70.14.0 255.255.255.0     null0&lt;/P&gt;&lt;P&gt;ip route 64.80.217.0 255.255.255.0    null0&lt;/P&gt;&lt;P&gt;ip route 64.80.218.0 255.255.255.0    null0&lt;/P&gt;&lt;P&gt;ip route 202.108.44.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 209.73.162.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 66.7.131.0 255.255.255.0     null0&lt;/P&gt;&lt;P&gt;ip route 216.32.64.0 255.255.255.0    null0&lt;/P&gt;&lt;P&gt;ip route 168.95.4.0 255.255.255.0     null0&lt;/P&gt;&lt;P&gt;ip route 163.32.96.0 255.255.255.0    null0&lt;/P&gt;&lt;P&gt;ip route 207.253.100.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 203.251.180.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 195.53.182.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 207.79.74.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 200.212.99.0 255.255.255.0 null0&lt;/P&gt;&lt;P&gt;ip route 64.28.74.0 255.255.255.0 null0&lt;/P&gt;&lt;P&gt;ip route 210.145.137.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 209.185.149.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 216.33.104.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 209.183.236.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 202.219.52.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 63.20.240.0 255.255.255.0    null0&lt;/P&gt;&lt;P&gt;ip route 210.123.152.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 200.241.80.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 194.21.74.0 255.255.255.0    null0&lt;/P&gt;&lt;P&gt;ip route 210.59.228.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 150.57.60.0 255.255.255.0    null0&lt;/P&gt;&lt;P&gt;ip route 64.28.75.0 255.255.255.0     null0&lt;/P&gt;&lt;P&gt;ip route 209.121.135.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 212.210.15.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 216.35.159.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 210.59.144.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 192.106.88.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 211.20.142.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 202.96.194.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 216.251.232.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 202.242.18.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 202.166.255.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 206.190.171.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;ip route 64.71.132.0 255.255.255.0    null0&lt;/P&gt;&lt;P&gt;ip route 64.1.242.0 255.255.255.0     null0&lt;/P&gt;&lt;P&gt;ip route 216.233.51.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 216.233.69.0 255.255.255.0   null0&lt;/P&gt;&lt;P&gt;ip route 206.130.106.0 255.255.255.0  null0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Apr 2008 13:36:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-blocking-by-country/m-p/957880#M940062</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2008-04-01T13:36:49Z</dc:date>
    </item>
  </channel>
</rss>

