Blocking a country (mass iP Ranges), best practice for the actual block

Posted by kwiksand on Server Fault See other posts from Server Fault or by kwiksand
Published on 2011-03-05T14:07:09Z Indexed on 2011/03/05 15:26 UTC
Read the original article Hit count: 325

Filed under:
|
|

Hi all,

This question has obviously been asked many times in many different forms, but I can't find an actual answer to the specific plan I've got. We run a popular European Commercial deals site, and are getting a large amount of incoming registrations/traffic from countries who cannot even take part in the deals we offer (and many of the retailers aren't even known outside Western Europe).

I've identified the problem area to block a lot of this traffic, but (as expected) there are thousands of ip ranges required.

My question now (finally!). On a test server, I created a script to block each range within iptables, but the amount of time it took to add the rules was large, and then iptables was unresponsive after this (especially when attempting a iptables -L).

What is the most efficient way of blocking large numbers of ip ranges:

  • iptables? Or a plugin where I can preload them efficiantly?
  • hosts.deny?
  • .htaccess (nasty as I'd be running it in apache on every load balanced web server)?

Cheers

© Server Fault or respective owner

Related posts about firewall

Related posts about iptables