Discussion: Where’s the Best Place For Country Blocks?

By Daniel Miessler on June 12th, 2009: Tagged as Information Security
  • tv

    i prefer an intelligent whitelist obviously allowing for business requirements. it should be enforced on the appropriate device(s) that have the horsepower to house them and where they are relatively easy to admin.

  • CSiedsma

    If you want to blacklist entire countries a good place to identify the IPs you need to block can be found at :

    China
    http://www.infosyssec.com/cgi-bin/iptocountry.c

    Russia
    http://www.infosyssec.com/cgi-bin/iptocountry.c

    North Korea
    http://www.infosyssec.com/cgi-bin/iptocountry.c

    Brazil
    http://www.infosyssec.com/cgi-bin/iptocountry.c

    Similar list are there also for all other countries. Be sure to block out Spain and the Netherlands ( because nothing comes out of those countries except e-mail harvesters for spamming ). And definitely block out Nigeria ( yes 419ers actually do operate from Nigeria ).

  • tv

    I would recommend going straight to the RIRs.

    No chance for mistakes and tasty summarization for your config pleasures.


Top

Popular

Information Security / Technology

Politics

Philosophy & Religion

Technology & Science

Culture & Society

Miscellaneous

Arguments

Projects

Collections

Twitter

What I'm Reading

Favorite Books and Essays

Top Blog Categories

Inputs