Add the abilty to block IPs by country

Post Reply
silver_2000
Junior Member
Posts: 115
Joined: 18 Dec 2006, 01:55

Add the abilty to block IPs by country

Post by silver_2000 »

Id love to see a built in applet that would make it easy for us newbies to select and block regions of the world by IP range

My servers serve mostly a US based auto enthusiast audience.

While CSF does a nice job of of blocking repeated attacks, after getting repeated attacks from China, Tiawan and some of the "stans" it would be easier to simply block them entirely.

I used to use an applet called ip to country that I still have somewhere that generates a list that can be added to the Iptables BUT it appears the way CSF manages the IP tables wipes the ranges added by the app
chirpy
Moderator
Posts: 3537
Joined: 09 Dec 2006, 18:13

Post by chirpy »

This is coming in the next release.
silver_2000
Junior Member
Posts: 115
Joined: 18 Dec 2006, 01:55

Post by silver_2000 »

Excellent ...
silver_2000
Junior Member
Posts: 115
Joined: 18 Dec 2006, 01:55

Post by silver_2000 »

in the conf file it says this
# Warning: These lists are never 100% accurate and some ISP's (e.g. AOL) use
# non-geographic IP address designations for their clients
#
# Warning: Some of the CIDR lists are huge and each one requires a rule within
# the incoming iptables chain. This can result in significant performance
# overheads and could render the server inaccessible in some circumstances. For
# this reason (amongst others) we do not recommend using these options
#
# Warning: Due to the resource constraints on VPS servers this feature should
# not be used on such systems unless you choose very small CC zones
What are the other reasons for not using these options ?
chirpy
Moderator
Posts: 3537
Joined: 09 Dec 2006, 18:13

Post by chirpy »

Mainly that they're arbitrary and not necessarily accurate. Also, the statistics tend to show that most attacks don't come from the sources many people expect.
Post Reply