Blocking traffic to / from Russia?

Solved
tantony
Head in the Cloud

Blocking traffic to / from Russia?

Anyone here blocking traffic to / from Russia on their Meraki especially with high risk of cyber attack from Russia?

 

Even if I block traffic from Russia with MX layer 7, what would happen if an actual hacker from Russia uses VPN to be in 'US'?

 

Is Meraki smart enough to 'unmask' the VPN from Russia pretending to be from US?

1 Accepted Solution
BrandonS
Kind of a big deal

Is Meraki smart enough to 'unmask' the VPN from Russia pretending to be from US?”. No. 

Geoblocking is pretty basic and just blocks IP addresses well known to be assigned in Russia.

 

if you are honestly concerned about attacks from Russia you should probably have the FBI or DHS (assuming you are in the US) or some federal agencies involved. Otherwise, just carry on with current best practices for business network security. 

- Ex community all-star (⌐⊙_⊙)

View solution in original post

3 Replies 3
BrandonS
Kind of a big deal

Is Meraki smart enough to 'unmask' the VPN from Russia pretending to be from US?”. No. 

Geoblocking is pretty basic and just blocks IP addresses well known to be assigned in Russia.

 

if you are honestly concerned about attacks from Russia you should probably have the FBI or DHS (assuming you are in the US) or some federal agencies involved. Otherwise, just carry on with current best practices for business network security. 

- Ex community all-star (⌐⊙_⊙)
CptnCrnch
Kind of a big deal
Kind of a big deal

If you're really catching attackers with Geo-blocking, they possibly wouldn't have made it past your perimeter nonetheless. With AWS, Azure, GCP etc. in place, Geo IP is not very much useful anymore from a defenders perspective.

tantony
Head in the Cloud

Thanks, that's what I thought, but I guess better safe than sorry.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels