Often we create firewall rules by for the whole network of an internet provider, not by IP address, not by hostname, but by looking up all IP ranges used by the ASN (Autonomous System Number). Only when the ISP is large, we only include the large blocks (which most often times contain the customer assigned IP addresses) and limit the network ranges to the required country (for example include NL and exclude EU), exclude the small blocks (which are often used by routers and other internal equipment of the ISP).
It would be nice if this process could be speed up (improve workflow) by having in input field at the Balance router, which looks up all IP ranges in the AS. Presenting that list to the Peplink administrator to select the desired ranges, having:
00. the list displayed in a table view,
0. columns for size of the block and country assignment,
- a check box in front of each IP range (to select/deselect),
- having one check box to mark select/deselect all network ranges,
- having sortable column headers (net block size, country assignment),
- keep the created rule grouped together,
- a memory which net ranges were select and which are not, when re-opening this rule, to have a update mechanism that even shows new and deleted ranges in the ASN.
An example: allow Tele2 Netherlands customers.
We have one of Tele2’s customers assigned IP addresses, which is: 22.214.171.124
We use that IP as an input, press Lookup ],
which returns that this IP is within AS13127,
which ASN is owned by Tele2 Nederland B.V.,
which consists of these netblocks:
Match Type Size Country Start IP End IP 1 /15 131,071 EU 126.96.36.199 188.8.131.52 2 /16 65,535 EU 184.108.40.206 220.127.116.11 3 /16 65,535 EU 18.104.22.168 22.214.171.124 4 /15 131,071 BE 126.96.36.199 188.8.131.52 5 /14 262,143 NL 184.108.40.206 220.127.116.11 6 /13 524,287 NL 18.104.22.168 22.214.171.124 7 /14 262,143 EU 126.96.36.199 188.8.131.52 8 /20 4,095 NL 184.108.40.206 220.127.116.11 9 /16 65,535 NL 18.104.22.168 22.214.171.124 10 /21 2,047 NL 126.96.36.199 188.8.131.52 11 /23 511 NL 184.108.40.206 220.127.116.11
Now the wish is to create a rule by selecting:
Match Type Size Country Start IP End IP 5 /14 262,143 NL 18.104.22.168 22.214.171.124 6 /13 524,287 NL 126.96.36.199 188.8.131.52 9 /16 65,535 NL 184.108.40.206 220.127.116.11