wanted: cyveillance IP address blocks

Apr 25, 2005 20 Replies

For mail, whitelists are perfect. I've had that in place for about two years now. The other network services... well, I don't offer any, but some like to have a personal web page. That should have similar (harsh) limits on allowable IPs, and the rest of the connections are rejected.

As mentioned this subject comes up fairly often. Some claim that you can't filter on IPs for that reason - others point out that if you aren't ever going to do business with '(country|continent)' $FOO, you can filter that. My company has both regional offices and local representatives getting the mail (and web stuff) for '(region|country|continent)' $FOO, and to my knowledge doesn't see that much at the headshed (I'm in a R&D facility, so I'm not directly involved).

Your mention yesterday of .us addresses from APNIC pressed the 'interest' button. Last night, I did a quick scan of the RIR files. There are 34 countries (out of 192) who have allocations from two or more RIRs. Most seem to be historic allocations that I'd expect to be eventually transferred to the "appropriate" RIR, such as:

AR Argentina AT Austria AU Australia BE Belgium ARIN:1 ARIN:1 APNIC:4571 ARIN:4 LACNIC:228 RIPE:352 ARIN:3 RIPE:276

but a few are more intriguing. CH has one allocation from APNIC in addition to 6 from ARIN and 404 from RIPE. MU has 7 from AFRINIC and 1 from APNIC. The UK (which isn't an ISO3166 code but is widely accepted) has all 1523 allocations from RIPE, but there are _also_ 24 allocations from ARIN to 'GB' (which is the official ISO3166 code). Several appear to be .uk locations of .us entities (Sun Micro has four), and two are UK government that should probably be transferred to RIPE, but the others?

Old guy

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required