Blocking foreign subnets

Blocking foreign subnets

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Blocking foreign subnets John 04-12-2005
Posted by John on April 12, 2005, 4:01 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Does anyone know of a way to easily block foreign subnets? i.e. I only
want our firewall to answer to US based subnets. Our logs show that
most attacks are coming from foreign sources. Ideally, I'd like to
have them broken down by country, and I've found databases online for
sale. Are there any reliable free subnet/country databases available?
And, what are your thoughts on something like this?

On that note, does anyone know of a firewall with this feature built
in? Or would the blocking firewall still be susceptible to attacks?

John



Posted by Ken on April 12, 2005, 8:57 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi John -


>Does anyone know of a way to easily block foreign subnets? i.e. I only
>want our firewall to answer to US based subnets. Our logs show that
>most attacks are coming from foreign sources. Ideally, I'd like to
>have them broken down by country, and I've found databases online for
>sale. Are there any reliable free subnet/country databases available?
>And, what are your thoughts on something like this?

You can get that information free from ARIN via FTP. ARIN is the
American Registry for Internet Numbers. They handle the allocation of
blocks of IP addresses to ISPs for the U.S., Canada, and some other
areas, but they also make available the information from the other
Regional Internet Registries.

FTP to ftp.arin.net
Go to /pub/stats
Go into the apnic, arin, lacnic, and ripencc directories and pick up
the most recent "delegated" file from each, selecting the large file
from each set (hundreds of thousands of bytes). Be sure to transfer
in ASCII mode as they are text files. They don't have an extension to
clue your FTP client to automatically select ASCII mode if it has that
capability.

--
Ken
http://www.ke9nr.net/


Posted by Walter Roberson on April 12, 2005, 11:19 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
:Does anyone know of a way to easily block foreign subnets? i.e. I only
:want our firewall to answer to US based subnets.

Some of the messages in the thread starting from the following may
be of interest to you:

http://groups.google.ca/groups?selm=5hf45111umvrga1utqh82r7oplkoeglmv7%404ax.com


--
Beware of bugs in the above code; I have only proved it correct,
not tried it. -- Donald Knuth


Similar ThreadsPosted
Multiple Subnets with Sonicwall May 9, 2008, 5:30 pm
Secure subnets and bandwidth control October 26, 2005, 2:26 am
VPN with conflicting subnets with Netscreen-50 and ZyWALL 70 June 14, 2006, 6:11 am
Blocking internet sharing in LAN without blocking file sharing May 10, 2006, 12:55 am
blocking gator December 2, 2004, 11:41 am
Blocking Warez P2P January 15, 2005, 7:19 pm
Selective blocking February 20, 2005, 12:30 am
ZA blocking ISP pings? March 14, 2005, 12:48 am
blocking MSN using watchguard March 16, 2005, 2:38 am
Win2003 IP blocking March 28, 2005, 4:44 pm

The site map in XML format XML site map

Contact Us | Privacy Policy