0
Votes

Allow the creation of more Location Groups

 
0
Votes

Allow the creation of more Location Groups

Allow the creation of more Location Groups
Allow the creation of more Location Groups
2 weeks ago
Tags: #Location Group
Model: ER707-M2  
Hardware Version: V1
Firmware Version: 1.2.3

According to Wikipedia, The United Nations geoscheme is a system that divides 248 countries and territories in the world into six continental regions, 22 geographical subregions, and two intermediary regions.

 

I wanted to create a Location Group for each of these 22 geographical regions but hit a limit. Either the router or the controller only allows the creation of 15 Location Groups.

 

For now I grouped some subregions together, but it would be nice to be able to create more Location Groups which would make for easier and clearly-defined geo-blocking capabilities.

#1
Options
4 Reply
Re:Allow the creation of more Location Groups
2 weeks ago

Hi @Matva 

Thanks for posting in our business forum.

The more granular your rule is, the greater the burden on the CPU.

Would the x86 server or a firewall be suitable for such a job?

You know, each rule is a set of CIDRs, and your router gotta locate more resources for it.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
#2
Options
Re:Allow the creation of more Location Groups
Yesterday

  @Clive_A 

 

Hi. I understand. Right now I am using the maximum number of location groups, blocking pretty much the entire world except for a few regions, with the CPU idling around 3% and the memory around 16%. So it seems there's still plenty of room to spare.

 

 

But I understand this isn´t particularly high on the features list ;) Combining some geolocation groups works for me.

#3
Options
Re:Allow the creation of more Location Groups
12 hours ago - last edited 12 hours ago

Hi @Matva 

Thanks for posting in our business forum.

Matva wrote

  @Clive_A 

 

Hi. I understand. Right now I am using the maximum number of location groups, blocking pretty much the entire world except for a few regions, with the CPU idling around 3% and the memory around 16%. So it seems there's still plenty of room to spare.

 

 

 

But I understand this isn´t particularly high on the features list ;) Combining some geolocation groups works for me.

Yes, I know that you may see a low usage in that.

But when it is triggered, that may not be the case. And the system is reserved for some redundancy.

As we used to have the switch that experienced the ACL limit. It hits the limit and will not be able to break it. And the explanation from the team is the hardware limit.


I can submit this as an optimization. But no guarantee this is ever gonna be implemented. It depends on the dev evaluation.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
#4
Options
Re:Allow the creation of more Location Groups
8 hours ago

 Wouldnt a better way of optimising this be to allow a !location_group, like we can on the 5.15 adapted firmwares with !network and !ip_group ?

 

Then you only have to have the regions you want to allow in the list, and its easier for the CPU to compare against that and drop everything else rather than parse a massive list of CIDRs ?

 

Currently i employ a location group WAN in block, with every single entry enabled apart form the UK, thats 249 individual rules it has to parse for every incoming connection attempt.  It works, but what i suggest seems like a decent way to optimise this.

Main: ER8411 x1, SG3428X x1, SG3452 x1, SG2428LP x1, SG3210 x1, SG2218P x1, SG2008P x1, ES205G x2, EAP650 x6 Remotes: ER605 v2 x3, SG2008P x2, EAP650 x2 VPN Server: ER7206 v2 Controller: OC300
#5
Options