yokoffing / Control-D-Config

Setup guide for Control D, a managed DNS service with superpowers.
https://controld.com/personal/
GNU General Public License v3.0
134 stars 2 forks source link

Recommendation: Add Guidelines for ASN-Based Geo Blocking Rules #13

Open groundcat opened 1 month ago

groundcat commented 1 month ago

Control-D now supports filtering by ASNs. For example:

In your method for identifying potentially malicious IPs, you listed all IPs from multiple countries as potentially (controversially) malicious, such as RU, CN, etc. However, I doubt that blocking target IPs in there would provide a decent level of protection, because many of their state-sponsored vendors or cloud providers more often use overseas infrastructure that typically have overseas IPs/CDN nodes but still belongs to their ASNs.

For example, to more effectively block China's state-sponsored cloud providers, use this GitHub repository, which contains a list of ASNs for all China-based providers/ISPs. This covers IPs not only in mainland China but also in other locations.

Converted to Control-D format: