Often we create firewall rules by for the whole network of an internet provider, not by IP address, not by hostname, but by looking up all IP ranges used by the ASN (Autonomous System Number). Only when the ISP is large, we only include the large blocks (which most often times contain the customer assigned IP addresses) and limit the network ranges to the required country (for example include NL and exclude EU), exclude the small blocks (which are often used by routers and other internal equipment of the ISP).
It would be nice if this process could be speed up (improve workflow) by having in input field at the Balance router, which looks up all IP ranges in the AS. Presenting that list to the Peplink administrator to select the desired ranges, having:
00. the list displayed in a table view,
0. columns for size of the block and country assignment,
- a check box in front of each IP range (to select/deselect),
- having one check box to mark select/deselect all network ranges,
- having sortable column headers (net block size, country assignment),
- keep the created rule grouped together,
- a memory which net ranges were select and which are not, when re-opening this rule, to have a update mechanism that even shows new and deleted ranges in the ASN.
An example: allow Tele2 Netherlands customers.
We have one of Tele2’s customers assigned IP addresses, which is: 18.104.22.168
We use that IP as an input, press Lookup ],
which returns that this IP is within AS13127,
which ASN is owned by Tele2 Nederland B.V.,
which consists of these netblocks:
Match Type Size Country Start IP End IP 1 /15 131,071 EU 22.214.171.124 126.96.36.199 2 /16 65,535 EU 188.8.131.52 184.108.40.206 3 /16 65,535 EU 220.127.116.11 18.104.22.168 4 /15 131,071 BE 22.214.171.124 126.96.36.199 5 /14 262,143 NL 188.8.131.52 184.108.40.206 6 /13 524,287 NL 220.127.116.11 18.104.22.168 7 /14 262,143 EU 22.214.171.124 126.96.36.199 8 /20 4,095 NL 188.8.131.52 184.108.40.206 9 /16 65,535 NL 220.127.116.11 18.104.22.168 10 /21 2,047 NL 22.214.171.124 126.96.36.199 11 /23 511 NL 188.8.131.52 184.108.40.206
Now the wish is to create a rule by selecting:
Match Type Size Country Start IP End IP 5 /14 262,143 NL 220.127.116.11 18.104.22.168 6 /13 524,287 NL 22.214.171.124 126.96.36.199 9 /16 65,535 NL 188.8.131.52 184.108.40.206