cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2966
Views
5
Helpful
2
Replies

Cisco ASA 5525 geoblocking

dotwell11
Level 1
Level 1

Hello,

 

I was curious to see if anybody has any recommendations/best practices for geoblocking IPs on a Cisco ASA 5525.  We'd like to block all foreign IPs, but not sure if this is a completely manual process or not.  And if it is manual, does anybody have any suggestions on how they've done this in the past?  Thank you in advance for any help.

 

Tom

2 Replies 2

ASA can not do this dynamically.  You would need a NGFW such as Firepower to do this.

Or you could lookup your country's assigned country IP addresses space and add a permit statement for that subnet and then deny all other traffic.  Then, if needed, you could add permit statements for select country IP address spaces if needed.

 

Personally, I have never done this type of thing manually.  We purchased a NGFW that will do this for use if needed.

--
Please remember to select a correct answer and rate helpful posts

Not having a NGFW, I do like Marius's replay above.

It would be easier to allow your origin country IP ranges and deny all others instead of trying to deny IP ranges from 247 countries.

However, I have recently hseard of two separate instances where using broad stroke Geo-Blocking has lead to unexpected outcomes.

In two separate case, an organizations blocked some of their cloud based services because they did not know that their hosting organization used pathways and services in countries other than what they had specifically allowed.

 

Also, mass Geo-Blocking may open the potential for performance lag on your ASA.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card