- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: Autonomous System Number Updatable Object?
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Autonomous System Number Updatable Object?
Have a need come up where it would be useful to be able to import an AS Number that gets updated automatically. A specific AS number is just sending us garbage constantly and we want to block all 200,000+ IPs from it. Wasn't sure if there was anything that I missed for doing that?
For now, I'm scraping all the subnets from a place like https://www.ip2location.com/ and putting them in a network feed flat file. It should work but it's not dynamic.
Thanks!
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can refer to a specific AS with fwaccel dos and effectively block the traffic: https://support.checkpoint.com/results/sk/sk112454
Not sure there is an Updatable Object with this information, unfortunately.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can refer to a specific AS with fwaccel dos and effectively block the traffic: https://support.checkpoint.com/results/sk/sk112454
Not sure there is an Updatable Object with this information, unfortunately.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ah, very cool; will look into it. I assume this traffic won't be visible in the Smart Console logs and is handled at a lower level?
I don't understand this section in the SK you linked to though. Does this mean I can drop traffic, just not rate limit it?
- SecureXL Rate Limiting rules for DoS Mitigation do not support these parameters (Known Limitation PMTR-87460):
- cc:<COUNTRY_CODE>
- asn:<AUTONOMOUS_SYSTEM_NUMBER>
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It's handled in SecureXL and I believe you can also have it generate logs in SmartConsole.
Believe the limitation only applies to actual rate limiting rules as opposed to drop ones.
