Prior to the ability to do Country Blocking, one of my clients had a blackhole DNAT with dozens of entries in the "Spammers" Network Group. The most-efficient is Network definitions that use CIDR notation. Small groups of those are usually best. Although Range definitions are possible, they are not efficient and are limited to subnets smaller than a /16.
Prior to the ability to do Country Blocking, one of my clients had a blackhole DNAT with dozens of entries in the "Spammers" Network Group. The most-efficient is Network definitions that use CIDR notation. Small groups of those are usually best. Although Range definitions are possible, they are not efficient and are limited to subnets smaller than a /16.