• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Allow only some websites through pfBlockerng

Scheduled Pinned Locked Moved pfBlockerNG
17 Posts 3 Posters 2.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • A
    abanet
    last edited by Nov 20, 2023, 8:42 AM

    Hi! I need some help with pfsense and pfBlockerng.

    I'm trying configure pfsense + pfBlockerng. I use feeds and categories, but I need permit some IP's from my LAN access to some websites. For example:

    I have my LAN with static ip 192.168.8.0 and I need to allow access Facebook from device with static IP 192.168.8.80. How can I do this?

    At this moment I can bypass pfblocker and permit all device from this LAN access to internet, but I need do it only for some websites.

    Thanks a lot!

    G 1 Reply Last reply Nov 20, 2023, 10:02 AM Reply Quote 0
    • G
      greenlight @abanet
      last edited by Nov 20, 2023, 10:02 AM

      @abanet Create a group for these devices. Then, write a pass rule that includes this group in the rules section and move it above the pfblockerng rules.

      A 1 Reply Last reply Nov 20, 2023, 10:11 AM Reply Quote 1
      • A
        abanet @greenlight
        last edited by Nov 20, 2023, 10:11 AM

        @greenlight Thanks for your answer. I use floating rules, where must I create the rule? floating rules or lan rules?

        G 1 Reply Last reply Nov 20, 2023, 11:07 AM Reply Quote 0
        • G
          greenlight @abanet
          last edited by Nov 20, 2023, 11:07 AM

          @abanet Can you share a screenshot of your lan rules? I guess you created rules on the LAN side to prevent access and you need to add the new rule on top of these rules.

          A 1 Reply Last reply Nov 20, 2023, 11:11 AM Reply Quote 0
          • A
            abanet @greenlight
            last edited by Nov 20, 2023, 11:11 AM

            @greenlight It's a clean installation. I have defaults rules

            G 1 Reply Last reply Nov 20, 2023, 12:32 PM Reply Quote 1
            • G
              greenlight @abanet
              last edited by greenlight Nov 20, 2023, 1:34 PM Nov 20, 2023, 12:32 PM

              https://forum.netgate.com/topic/150084/is-pfblockerng-able-to-block-all-outbound-traffic-except-whitelistet-sites/17

              You can follow the steps in this link without pfblockerng.

              I also prepared a visual for you. I tried it myself and it works this way. You must only specify a static IP address for the device you will use. After then

              1.png
              Create an aliases for websites with permissions

              2.png
              Create aliases for devices that you allow and whose IP addresses you fix. The marked IP address belongs to my device. You'll probably type 192.168.8.80 there.

              3.png
              You will create a rule to block internet access for all devices.

              4.png
              By selecting the aliases you created here, you will define the devices and the addresses they will connect to.

              5.png
              Your rules should look like this.

              Finally, reload the filters. You can make additions or deletions for both aliases groups. Doing this on the Aliases side will be enough.

              The main way pfblockerng works is to block external connections to pfsense. Of course, connections can be blocked in both directions. Very useful for interface based restrictions. But the rules are more favorable for restrictions within the subnet.

              A 2 Replies Last reply Nov 21, 2023, 10:57 AM Reply Quote 1
              • A
                abanet @greenlight
                last edited by Nov 21, 2023, 10:57 AM

                @greenlight I will try this way and tell you something

                Thanks a lot for your help!

                1 Reply Last reply Reply Quote 0
                • A
                  abanet @greenlight
                  last edited by Nov 24, 2023, 7:21 AM

                  @greenlight said in Allow only some websites through pfBlockerng:

                  https://forum.netgate.com/topic/150084/is-pfblockerng-able-to-block-all-outbound-traffic-except-whitelistet-sites/17

                  You can follow the steps in this link without pfblockerng.

                  I also prepared a visual for you. I tried it myself and it works this way. You must only specify a static IP address for the device you will use. After then

                  1.png
                  Create an aliases for websites with permissions

                  2.png
                  Create aliases for devices that you allow and whose IP addresses you fix. The marked IP address belongs to my device. You'll probably type 192.168.8.80 there.

                  3.png
                  You will create a rule to block internet access for all devices.

                  4.png
                  By selecting the aliases you created here, you will define the devices and the addresses they will connect to.

                  5.png
                  Your rules should look like this.

                  Finally, reload the filters. You can make additions or deletions for both aliases groups. Doing this on the Aliases side will be enough.

                  The main way pfblockerng works is to block external connections to pfsense. Of course, connections can be blocked in both directions. Very useful for interface based restrictions. But the rules are more favorable for restrictions within the subnet.

                  Hi again! I tried this solution but still is blocked. I see traffic on rule but still can't connect. Any suggestion?

                  G 1 Reply Last reply Nov 24, 2023, 7:57 AM Reply Quote 0
                  • G
                    greenlight @abanet
                    last edited by greenlight Nov 24, 2023, 7:57 AM Nov 24, 2023, 7:57 AM

                    @abanet hello, the pass rule should be in the first line. Did you notice this?

                    A 1 Reply Last reply Nov 24, 2023, 8:05 AM Reply Quote 0
                    • A
                      abanet @greenlight
                      last edited by abanet Nov 24, 2023, 8:06 AM Nov 24, 2023, 8:05 AM

                      @greenlight Hi! Yes. I put on top but didn't works. I tried create same rule in "floating rules" but still can access to web sites in "Adresses" alias

                      G 1 Reply Last reply Nov 24, 2023, 8:11 AM Reply Quote 0
                      • G
                        greenlight @abanet
                        last edited by greenlight Nov 24, 2023, 8:12 AM Nov 24, 2023, 8:11 AM

                        @abanet You must use LAN rules. Why are you trying Floating rules? I also tried this on my own system before creating the screenshots and it worked. A step you missed or something you previously configured might be preventing this from working.

                        A 1 Reply Last reply Nov 24, 2023, 8:33 AM Reply Quote 0
                        • A
                          abanet @greenlight
                          last edited by Nov 24, 2023, 8:33 AM

                          @greenlight Floating rules are enabling by pfBlocker. I tried disable this option in pfBlocker and put your rule on top but didn't work

                          G 1 Reply Last reply Nov 24, 2023, 9:10 AM Reply Quote 0
                          • G
                            greenlight @abanet
                            last edited by Nov 24, 2023, 9:10 AM

                            @abanet Disable pfblockerng and disable all its rules (including LAN and Floating).

                            Just follow the rules I have shown on the LAN side.

                            A 1 Reply Last reply Nov 24, 2023, 9:16 AM Reply Quote 0
                            • A
                              abanet @greenlight
                              last edited by Nov 24, 2023, 9:16 AM

                              @greenlight In that way works. But I need use pfBlockerng

                              G 1 Reply Last reply Nov 24, 2023, 9:21 AM Reply Quote 0
                              • G
                                greenlight @abanet
                                last edited by Nov 24, 2023, 9:21 AM

                                @abanet what is your pfsense version?

                                G 1 Reply Last reply Nov 24, 2023, 9:29 AM Reply Quote 0
                                • G
                                  Gertjan @greenlight
                                  last edited by Nov 24, 2023, 9:29 AM

                                  @greenlight

                                  Easy.
                                  2.7.1 (or 23.09).

                                  Those who use 2.7.0 or earlier and install pfBlockerng 'now' brake the rules : Never install packages before pfSense is on the latest version.

                                  The latest pfBlockerng is compiled against "OpenSSL 3.0", something pfSense 2.7.0 hasn't. It will fail right away.
                                  There is another thread, yesterday or so, that illustrates this situation.

                                  No "help me" PM's please. Use the forum, the community will thank you.
                                  Edit : and where are the logs ??

                                  A 1 Reply Last reply Nov 24, 2023, 9:39 AM Reply Quote 0
                                  • A
                                    abanet @Gertjan
                                    last edited by Nov 24, 2023, 9:39 AM

                                    @Gertjan said in Allow only some websites through pfBlockerng:

                                    2.7.1 (or 23.09).

                                    Those who use 2.7.0 or earlier and install pfBlockerng 'now' brake the rules : Never install packages before pfSense is on the latest version.

                                    Hi! I did a fresh installation yestarday, pfSense 2.7.1 and last pfBlockerng but still doesn't work

                                    1 Reply Last reply Reply Quote 0
                                    9 out of 17
                                    • First post
                                      9/17
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                      This community forum collects and processes your personal information.
                                      consent.not_received