Country IPs (GEO blocking)

  • DNS Benchmark v2 Release 5 with Consultant License
    Guest:
    If you own any earlier release of our DNS Benchmark you may immediately download its release #5 replacement. Running an earlier release will detect the new release and help you upgrade.

    Although this release is cosmetic, appearance matters and affects ease of use. The biggest change, as seen in the image above, is that the DNS Benchmark now has a traditional Windows application menu to more fully expose its many features. This release is also "Consultant License Aware" and GRC will now issue a Consultant version when owners have previously purchased four "Personal Use" licenses. If you have previously purchased four DNSB licenses, or if you wish to upgrade your "Personal Use" license to Consultant, GRC's purchase process will direct you through that process.
    /Steve.
  • Be sure to checkout “Tips & Tricks”
    Dear Guest Visitor → Once you register and log-in please checkout the “Tips & Tricks” page for some very handy tips!

    /Steve.
  • BootAble – FreeDOS boot testing freeware

    To obtain direct, low-level access to a system's mass storage drives, SpinRite runs under a GRC-customized version of FreeDOS which has been modified to add compatibility with all file systems. In order to run SpinRite it must first be possible to boot FreeDOS.

    GRC's “BootAble” freeware allows anyone to easily create BIOS-bootable media in order to workout and confirm the details of getting a machine to boot FreeDOS through a BIOS. Once the means of doing that has been determined, the media created by SpinRite can be booted and run in the same way.

    The participants here, who have taken the time to share their knowledge and experience, their successes and some frustrations with booting their computers into FreeDOS, have created a valuable knowledgebase which will benefit everyone who follows.

    You may click on the image to the right to obtain your own copy of BootAble. Then use the knowledge and experience documented here to boot your computer(s) into FreeDOS. And please do not hesitate to ask questions – nowhere else can better answers be found.

    (You may permanently close this reminder with the 'X' in the upper right.)

bdub76

Active member
Oct 19, 2024
30
10
Is there a good source, where I can obtains IPs by country, so I can setup tables and block a subset of countries?
 
There are services that offer such an ability for routers, but I've never looked into how its done. I presume the IP allocation of each global/region/national IP issuing body/registry is visible somewhere so it should be possible to build such a list, but it would be forever out of date unless you were constantly focused on list maintenance. Have a look at this site though https://lite.ip2location.com/ip-address-ranges-by-country
 
Is there a good source, where I can obtains IPs by country, so I can setup tables and block a subset of countries?
If you have Outlook you can go to the "Junk Email Options" and block by country TLD. the two-letter domain IDs are listed there. You could use *.<tld> shown there in other applications. Other email programs may offer a similar feature.
 
I found two sources of this information so far:



I started running a test yesterday, where I'm blocking on egress in and out (ipv4 and ipv6) to the China block since I currently run dual stack. I'm more interested about packets going out then packets coming in since I have a default block all on my egress interface.

I've added to my monthly.local a script to update the ipblocks once a month. Basically, I write the addresses down to a txt file, and I load the file as a table into pf. And then I block that table.

This is an experiment for now.

What is interesting is that I did find one of my devices communicating with a Chinese IP when I logged the outgoing traffic that I'm now blocking. My AP identifies the device as Shenzhen Bilian Electronic Co. I see two devices with that company name on my network. But I'm only blocking outgoing packets for one of the two. The other isn't sending outgoing packets. I'll track it down. It's an interesting experiment.

Some more information. The device is reaching out to the following IPs:


This is blocked for now.
 
Last edited:
Thanks for all the info.

So I have only one device that really, really wants to connect to China. It's so weird because I have two identical devices. One wants to contact China. The other doesn't. I don't get it. But I'm glad to be blocking now.
 
Thanks for all the info.

So I have only one device that really, really wants to connect to China. It's so weird because I have two identical devices. One wants to contact China. The other doesn't. I don't get it. But I'm glad to be blocking now.
So it wants to connect (egress) to China? That should be on a separate DMZ-like network.
 
Thanks for all the info.

So I have only one device that really, really wants to connect to China. It's so weird because I have two identical devices. One wants to contact China. The other doesn't. I don't get it. But I'm glad to be blocking now.
While they may be functionally identical, are the of a similar age, or could one be running a newer version of the software/firmware? "Phone home" may have been added or removed in different versions.

Just curious - what kind of device is it?
 
While they may be functionally identical, are the of a similar age, or could one be running a newer version of the software/firmware? "Phone home" may have been added or removed in different versions.

Just curious - what kind of device is it?
It's a Wopet camera to monitor my dog. No idea why it has to phone home to China. Turning off its ability to reach China doesn't impact its ability to work. It hasn't bricked itself.

I have confirmed that both devices have different firmware versions.

I have taken one offline for now, and I'm setting up a separate subnet this weekend. I'm going to use a cheap 5 port unmanaged switch along with an old WIFI 5 router that I have repurposed as an AP using DD-WRT. I will have to update my dhcpd.conf for the subnet, create another hostname.if file for a nic that I'm adding on via usb to rj45, and then I'll have to update my pf.conf to manage the traffic, so they're both on isolated networks that don't talk but still both properly NAT. This shouldn't take a lot of time. It's just a pain in the neck. I'm probably going to pull down US IPs and isolate the IOT devices to only be able to reach US IPs. And then I'll isolate it only to 2.4GHz band and make sure I don't create issues with my AP on the other subnet, and I'm not going to assign IPv6 to this subnet.

Fun times. I shouldn't need this complicated of a network for home use.
 
It's a Wopet camera to monitor my dog. No idea why it has to phone home to China. Turning off its ability to reach China doesn't impact its ability to work. It hasn't bricked itself.

I have confirmed that both devices have different firmware versions.

I have taken one offline for now, and I'm setting up a separate subnet this weekend. I'm going to use a cheap 5 port unmanaged switch along with an old WIFI 5 router that I have repurposed as an AP using DD-WRT. I will have to update my dhcpd.conf for the subnet, create another hostname.if file for a nic that I'm adding on via usb to rj45, and then I'll have to update my pf.conf to manage the traffic, so they're both on isolated networks that don't talk but still both properly NAT. This shouldn't take a lot of time. It's just a pain in the neck. I'm probably going to pull down US IPs and isolate the IOT devices to only be able to reach US IPs. And then I'll isolate it only to 2.4GHz band and make sure I don't create issues with my AP on the other subnet, and I'm not going to assign IPv6 to this subnet.

Fun times. I shouldn't need this complicated of a network for home use.
Whilst I agree completely on your last sentence, this is the world we now live in where the Internet evolved through a mix of insecure standards and rapid capital focused growth to the point the Internet as we know it is a very different beast from that of the 1990s. If we want to stay safe we have to take control of security in our own homes not only for the physical things but also in guarding what we allow the freedom to connect to the rest of the world.

A couple of things prompted me to reply here, even though it's obviously after the weekend you spoke of.

If this was me with a spare Franken-AccessPoint (running DD-WRT) I'd probably isolate this at Layer 2, setup a DHCP scope on the DD-WRT that serves a different IP subnet to the main home router, then configure it to only allow traffic from your main router Inbound to the DD-WRT router, thus allowing you to both manage it and inspect its logs for connection attempts to China or wherever. You can then re-use that DD-WRT for any IOT devices quite safely knowing they cannot connect to the internet at all. Smart bulbs spring to mind, particularly as most are 2.4 GHz WiFi only.

I'd also advise against using USB-NICs for the most part but maybe that was just my unfortunate experience trying to run a fileserver on TrueNAS for the homelab and repurposing an old laptop with adequate storage by adding a 2.5 Gbit USB-NIC to the mix … I was asking for the pain it caused I guess. Lesson learned 😂
 
Whilst I agree completely on your last sentence, this is the world we now live in where the Internet evolved through a mix of insecure standards and rapid capital focused growth to the point the Internet as we know it is a very different beast from that of the 1990s. If we want to stay safe we have to take control of security in our own homes not only for the physical things but also in guarding what we allow the freedom to connect to the rest of the world.

A couple of things prompted me to reply here, even though it's obviously after the weekend you spoke of.

If this was me with a spare Franken-AccessPoint (running DD-WRT) I'd probably isolate this at Layer 2, setup a DHCP scope on the DD-WRT that serves a different IP subnet to the main home router, then configure it to only allow traffic from your main router Inbound to the DD-WRT router, thus allowing you to both manage it and inspect its logs for connection attempts to China or wherever. You can then re-use that DD-WRT for any IOT devices quite safely knowing they cannot connect to the internet at all. Smart bulbs spring to mind, particularly as most are 2.4 GHz WiFi only.

I'd also advise against using USB-NICs for the most part but maybe that was just my unfortunate experience trying to run a fileserver on TrueNAS for the homelab and repurposing an old laptop with adequate storage by adding a 2.5 Gbit USB-NIC to the mix … I was asking for the pain it caused I guess. Lesson learned 😂
My NAS is wired.

I had to experiment to figure out the USB to rj45 to add a third NIC to mini PC that I'm using as router. The first one I bought failed. The second one works.

I'm going cheap on this bit. It's a $10 adapter connected to a $20 switch connected to an old AC router running DD-WRT in the equivalent of AP mode for only 2.4Ghz. I'm putting all of my IoT devices on that. And I'm blocking outgoing on that network to anywhere but the US. It's also isolated from my other network. The two don't talk. It was a pain to figure out the configuration files, but at this point it should just work until that USB to rj45 fails. It maxes out a 1Gbps. I don't need faster. The 2.5Gbps adapters in general have been a mess. Google Intel issues with 2.5Gbps NICs. You'll find a lot of problems.

I'm still working on my monthly update script for the IP ranges. I might change that to a weekly.