Block by country

I have a Cisco 871 router with IOS 12.4 installed. I'm using SDM 2.5 to do most of my configuration. I want to set up the firewall capability to block incoming connections to my website from anywhere other than the United States.

Does anyone know a quick, easy way to write the firewall rules for this so I don't have to have an over long list of rules?

Thanks

Reply to
Walter Malde
Loading thread data ...

formatting link
you would have to obtain IP address for each regional registry except for ARIN (American Registry for Internet Numbers)

You are talking about a very large number of IP address.

Reply to
Artie Lange

formatting link
you would want to create ACL's for any entry for APNIC, RIPE, LACNIC

Reply to
Artie Lange

I was hoping someone would know a faster way than that. I knew about all the lists you pointed out, I was just trying to limit the number of firewall rules I needed.

Artie Lange wrote:

Reply to
Walter Malde

Nothing I am aware of, sorry.

Reply to
Artie Lange

Thanks for your time.

WM

Artie Lange wrote:

Reply to
Walter Malde

Maybe a starting point - there exists a DNSBL (DNS blocklist) - whether a given IP address resides in a given country - see

formatting link
and try (24.113.37.76 is the IP of NNTP-Posting-Host)

dig 76.37.113.24.zz.countries.nerd.dk any

which returns:

;; ANSWER SECTION:

76.37.113.24.zz.countries.nerd.dk. 2100 IN TXT "us" 76.37.113.24.zz.countries.nerd.dk. 2100 IN A 127.0.3.72
Reply to
Alfred Nagl

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.