rcooper83
asked on
ASA 5510 bulk acl blocking
Is there a way to block multiple IP subnets on the asa 5510. Trying to block all traffic from china and dont want to enter all those subnets into the ACL one at a time. Any suggestions would be nice
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
answer was one way to solve problem but not what I was looking for
Or you can aggregate IP blocks to block numerous smaller blocks
so for instance you want to block 8 /24s 10.1.0.0/24, 10.1.32.0/24,10.1.64/24, 10.1.96/24,10.1.128/24,10.
or you could just block;
10.1.0.0/21
So you can aggregate smaller IP blocks into supernets if the blocks are aggregatable, they need to be contigous blocks to do so.
harbor235 ;}
harbor235 ;}