Community discussions

MikroTik App
 
User avatar
sadjoe
just joined
Topic Author
Posts: 22
Joined: Fri Jan 05, 2024 10:15 pm

Block All countries except ...

Sat Mar 02, 2024 10:37 pm

Hi everyone,

Someone more familiar can you tell is it already available the following:
- fetch the latest data from RIPE (most secure place) - https://ftp.ripe.net/pub/stats/ripencc/2024/
- rewrite the file compatible for Mikrotik way - something like
"add address=1.0.0.0/24 comment="United States of America" list=GeoIPBlocked"
- block all type (TCP and UDP) incoming traffic (on all ports) to WAN for all countries except (for example Bulgaria, Germany and UK)
Google, NTP servers and so on can be excluded (don't know how)

Thank you in advance.
 
User avatar
baragoon
Member
Member
Posts: 310
Joined: Thu Jan 05, 2017 10:38 am
Location: Kyiv, UA
Contact:

Re: Block All countries except ...

Sun Mar 03, 2024 9:46 am

if your router is able to process a million of address list rules - it will work
https://mikrotikconfig.com/firewall/
 
sas2k
Frequent Visitor
Frequent Visitor
Posts: 81
Joined: Tue Jan 18, 2022 8:17 am

Re: Block All countries except ...

Sun Mar 03, 2024 12:10 pm

Hi everyone,

Someone more familiar can you tell is it already available the following:
- fetch the latest data from RIPE (most secure place) - https://ftp.ripe.net/pub/stats/ripencc/2024/
- rewrite the file compatible for Mikrotik way - something like
"add address=1.0.0.0/24 comment="United States of America" list=GeoIPBlocked"
- block all type (TCP and UDP) incoming traffic (on all ports) to WAN for all countries except (for example Bulgaria, Germany and UK)
Google, NTP servers and so on can be excluded (don't know how)

Thank you in advance.
Already done by other people.
https://blog.erben.sk/2014/02/06/countr ... ip-ranges/
 
User avatar
sadjoe
just joined
Topic Author
Posts: 22
Joined: Fri Jan 05, 2024 10:15 pm

Re: Block All countries except ...

Sun Mar 03, 2024 1:08 pm

if your router is able to process a million of address list rules - it will work
https://mikrotikconfig.com/firewall/
It's not work anymore.
Hi everyone,

Someone more familiar can you tell is it already available the following:
- fetch the latest data from RIPE (most secure place) - https://ftp.ripe.net/pub/stats/ripencc/2024/
- rewrite the file compatible for Mikrotik way - something like
"add address=1.0.0.0/24 comment="United States of America" list=GeoIPBlocked"
- block all type (TCP and UDP) incoming traffic (on all ports) to WAN for all countries except (for example Bulgaria, Germany and UK)
Google, NTP servers and so on can be excluded (don't know how)

Thank you in advance.
Already done by other people.
https://blog.erben.sk/2014/02/06/countr ... ip-ranges/
I am not sure where he gets the CIDRs and are they up-to-date.
 
msatter
Forum Guru
Forum Guru
Posts: 2912
Joined: Tue Feb 18, 2014 12:56 am
Location: Netherlands / Nīderlande

Re: Block All countries except ...

Sun Mar 03, 2024 1:16 pm

If the allow list is smaller than the block list, then allow followed by a general block entry.
 
User avatar
baragoon
Member
Member
Posts: 310
Joined: Thu Jan 05, 2017 10:38 am
Location: Kyiv, UA
Contact:

Re: Block All countries except ...

Sun Mar 03, 2024 1:19 pm

It's not work anymore.
that's not true, lists are successfully generated
 
User avatar
sadjoe
just joined
Topic Author
Posts: 22
Joined: Fri Jan 05, 2024 10:15 pm

Re: Block All countries except ...

Sun Mar 03, 2024 1:59 pm

It's not work anymore.
that's not true, lists are successfully generated
Yesterday checked generated all countries except 3.
Nothing happen so for me it's not working.
If the allow list is smaller than the block list, then allow followed by a general block entry.
This has nothing with what I am saying. CIDRs are changed any month and the real trustee here is only RIPE.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19409
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Block All countries except ...

Sun Mar 03, 2024 2:55 pm

What makes you think bad actors done use botnets is other countries. So for example if I was to attempt hacking I would do it from benign countries like Canada LOL.
My IP would not be north korea........
 
msatter
Forum Guru
Forum Guru
Posts: 2912
Joined: Tue Feb 18, 2014 12:56 am
Location: Netherlands / Nīderlande

Re: Block All countries except ...

Sun Mar 03, 2024 7:02 pm

If the allow list is smaller than the block list, then allow followed by a general block entry.
This has nothing with what I am saying. CIDRs are changed any month and the real trustee here is only RIPE.
OK, more simple then. Which list would be larger?

Three countries or all countries minus three countries.....

Who is online

Users browsing this forum: Bing [Bot], Google [Bot] and 39 guests