Quote from: CJ on March 06, 2024, 04:13:02 PM
What benefit does this provide over just creating an ASN alias for AWS? https://ipinfo.io/AS16509
A1: OP is solutioning for pass/allow rule(s), which, as i'm sure you'd agree, should be as conservative as possible.
A2: not creating a pass/allow rule for every range under jeffrey's jurisdiction.
A3: sourcing a known-good list of ranges directly from its controlling parties vs. $unknown_place_opnsense_gets_and_maintains_its_asn_ranges
A4: accounting for the manner in which amz publishes those ranges. see 'Note' in block at top of https://docs.aws.amazon.com/vpc/latest/userguide/aws-ip-ranges.html
do you even firewall bro? :P