Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Possible alias bug in pfBlockerNG?

    Scheduled Pinned Locked Moved Firewalling
    6 Posts 3 Posters 428 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F Offline
      fireix
      last edited by

      Or is it just me?

      I have an IP alias called K_customer that I try to enter under "Custom Destination".

      The auto-complete that normally suggest the alias once I start typing an alias when using the Firewall GUI, it doesn't appear when entering text in the "Custom Destination" input field. And if I just typed the alias directly, it doesn't store the value.

      inbound-filter.png

      Here is what I try to accomplish (I had to manually put in the !K_customer on the rule in the firewall instead of in the pfBlocker GUI. pfBlocker seems to remove it when it is updated):

      rule.png

      pfBlockerNG-devel 3.2.0_6 and pfSense 2.7.0

      Bob.DigB 1 Reply Last reply Reply Quote 0
      • Bob.DigB Offline
        Bob.Dig LAYER 8 @fireix
        last edited by

        @fireix It looks like it only takes Network(s)-aliases. Remember you can create your own rules and only use the aliases created by pfBlocker in those.

        F 1 Reply Last reply Reply Quote 1
        • F Offline
          fireix @Bob.Dig
          last edited by fireix

          @Bob-Dig Ah, so it will only accept aliases with a /28 and similar, not an alias with multiple single IPs.

          Yes, I guess you are correct, I can bypass it by creating the fw rule manually outside pfBlocker and reference the pfBlocker-alias from there instead. I'll do that for now.

          Bob.DigB johnpozJ 2 Replies Last reply Reply Quote 0
          • Bob.DigB Offline
            Bob.Dig LAYER 8 @fireix
            last edited by

            @fireix said in Possible alias bug in pfBlockerNG?:

            @Bob-Dig Ah, so it will only accept aliases with a /28 and similar, not an alias with multiple single IPs.

            Technically you could create those with /32.

            1 Reply Last reply Reply Quote 1
            • johnpozJ Offline
              johnpoz LAYER 8 Global Moderator @fireix
              last edited by

              @fireix said in Possible alias bug in pfBlockerNG?:

              I can bypass it by creating the fw rule manually outside pfBlocker and reference the pfBlocker-alias from there instead.

              This is how I use pfblocker - not really a fan of any sort of auto rules that might change either in scope or in location on the firewall. But the aliases features of pfblocker are far more flexible than the built in aliases you can do with just pfsense.

              So I just let pfblocker create native aliases, and then use those in my firewall rules on my own. It works quite well..

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 25.07.1 | Lab VMs 2.8, 25.07.1

              F 1 Reply Last reply Reply Quote 0
              • F Offline
                fireix @johnpoz
                last edited by

                @johnpoz Ok :) Work-around in place (the /32 thing also worked), thanks for the help!

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.