cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
26271
Views
6
Helpful
10
Replies

cisco asa geo blocking.

nilesh.dubey
Level 1
Level 1

Is there a way by which we can block all the connections from a country on Cisco ASA, without we manually defining a ACL.

Hardware- Cisco ASA5510-

Version - 9.0

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

No.

This sort of functionality is offered in the newer models (ASA 5500-X series) when you add the FirePOWER service modules with their associated license(s).

They can download and auto update a Geolocation database which you can use in your access policy.

View solution in original post

10 Replies 10

Marvin Rhoads
Hall of Fame
Hall of Fame

No.

This sort of functionality is offered in the newer models (ASA 5500-X series) when you add the FirePOWER service modules with their associated license(s).

They can download and auto update a Geolocation database which you can use in your access policy.

Hi Marvin,

Thanks!!,

So do i need to purchase license as well along with firewall ?

I believe if all you want to do is create a policy to allow or block certain countries, you can use the free Control license.

However, if you're going to the effort to configure and use the FirePOWER module NGIPS, it makes sense to buy at least the IPS license.

Available licenses are IPS (Protect), URL Filtering and Malware (Advanced Malware Protection or AMP).

Hi Marvin,

Thanks for your response.

Regards,

Nilesh

You're welcome.

Please mark your question as answered if it has been.

Is it possible to use firepower module to block , say China using geo location but allow certain IPs from that country.

Have you got any response for this?

I dont think this  ever worked 

You can insert rule(s) with PERMIT action above the rule for geoblocking the entire country. The first match (for action other than monitor) from the top down stops the processing of the rest of rules in the access control policy.

Hi

Is there a way to restrict AnyConnect users from certain countries? I have ASA's on Firepower 1140's.

Regards, Justin

 

Review Cisco Networking for a $25 gift card