Now this is something not new and in today’s world, if it takes you to block a country itself to avoid issues in your network then you’d have to go down that path. I read an article lately on SecurityFocus on blocking based on Countries. The author basically blocked the whole of China and his spam hits came down to 80% it seems.

 

For sure if the business I’m running has nothing to do with a country then I think it is not a bad idea considering the fact that you can’t let bad guys come in and do the damage, then you take an action on it. While this has mixed reviews I believe it is justified for the sole reason that it is my network and I choose what to come in here.

One of the commenter posted this site, http://www.countryipblocks.net/index.php

 

Beauty is that you can choose the entire ip data pertaining to a country. For example;

image

 

This is the list of IP range of IRAN. Just select and country and click to get the list of that country.

 

However, it still remains a challenge for your router/firewall to take a list of all rogue ip addresses and start blocking it for the mere horsepower that is required to process through it. Attributed to this if people start doing away by only allowing the country they are in (nowadays you can see every business have an internet connection, and the business is only to that country), then internet would be not be the internet we perceived in the first place!

 

Say an interior decorator working in a small state, doesn’t have to allow everybody in the world to see his site/resources, does he?