cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
169
Views
5
Helpful
1
Replies
Participant

Geolocation discrepencies

Hi there,


We're running FMC v6.3.04(44) with Geolocation update 2019-07-18-003.

 

We have noticed that some IP addresses get identified by FMC as originating from the US, but many other online sources when queried for the same IP address show the address being located in Russia.  This is an issue for us as we have policies in place to specifically to block traffic to and from this country, as well as some others.  These policies break in this case, allowing the traffic to pass.


A sample IP is 93.158.161.26 .

 

Is this a bug, or is something else going on here?  Please advise.

 

Thanks.

 

Everyone's tags (1)
1 ACCEPTED SOLUTION

Accepted Solutions
Hall of Fame Master

Re: Geolocation discrepencies

The Cisco Geolocation feed is reporting the correct public registration information per the RIPE registrar:

https://apps.db.ripe.net/db-web-ui/#/query?searchtext=93.158.161.26

It appears this Russian company has changed the registration or is otherwise somehow getting attributed as being USA-based.

I just confirmed the same issue myself. My FMC is 6.4.0.3 running the latest Geolocation database (same version as yours). FMC reports the address as USA (consistent with the RIPE registrar).

 

Notably Cisco's Umbrella Investigate shows it as Russian.

 

FMC Geolocation.PNGFMC GeolocationFMC Status.PNGFMC StatusUmbrella Investigate.PNGUmbrella Investigate Report

1 REPLY 1
Hall of Fame Master

Re: Geolocation discrepencies

The Cisco Geolocation feed is reporting the correct public registration information per the RIPE registrar:

https://apps.db.ripe.net/db-web-ui/#/query?searchtext=93.158.161.26

It appears this Russian company has changed the registration or is otherwise somehow getting attributed as being USA-based.

I just confirmed the same issue myself. My FMC is 6.4.0.3 running the latest Geolocation database (same version as yours). FMC reports the address as USA (consistent with the RIPE registrar).

 

Notably Cisco's Umbrella Investigate shows it as Russian.

 

FMC Geolocation.PNGFMC GeolocationFMC Status.PNGFMC StatusUmbrella Investigate.PNGUmbrella Investigate Report