Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlockerNG not blocking some foreign sites using geoip

    Scheduled Pinned Locked Moved pfBlockerNG
    10 Posts 4 Posters 797 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      Willever
      last edited by

      I am using pfBlockerNG vs 3.2.0_7 on a netgate box with pfsense 23.05.1-RELEASE (arm).

      I use GEOIP to only alias permit access to the 2 US and 2 CA selections -- nothing outside of those 4 items are permitted.

      All of my rules refer to pfB_NAmerica_v4 and indeed most traffic is blocked from outside of the US.

      However I still see some traffic coming from UK, BE, HK, BR -- here is some of the geoip log.

      2024-02-01_08-22-40.png

      Am I not doing something wrong or is this common or do I need to do something else

      here are some of my rules
      2024-02-01_08-27-57.png

      thanks in advance for your help

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @Willever
        last edited by

        @Willever where is the rule that would allow that traffic. I don't see any rules that would allow inbound traffic 443 or 80? Which from whatever it is you posted I take that is the destination port?

        Do you have some rule on floating?

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        W 1 Reply Last reply Reply Quote 0
        • W
          Willever @johnpoz
          last edited by

          @johnpoz 2024-02-01_11-02-05.png

          here is screenshot with most of the rules -- port 80 is contained in a group called Main PC Ports

          Bob.DigB 1 Reply Last reply Reply Quote 0
          • Bob.DigB
            Bob.Dig LAYER 8 @Willever
            last edited by Bob.Dig

            @Willever You have a negative value there, maybe recreate that rule.

            I would use VPN though.

            W S 2 Replies Last reply Reply Quote 0
            • W
              Willever @Bob.Dig
              last edited by

              I did recreate the rule and now it looks normal

              2024-02-01_12-56-29.png

              I also used a norton VPN to connect to Australia and went to my web site and it shows in the log file as shown below
              2024-02-01_12-55-10.png

              johnpozJ 1 Reply Last reply Reply Quote 0
              • S
                SteveITS Galactic Empire @Bob.Dig
                last edited by

                @Bob-Dig if it’s a 3100 that’s a known issue with the number wrapping to -2T because 32 bit. It was fixed somewhere along the line I thought. OP is a version behind .

                And also I could be wrong but I thought _7 was for 23.09. OP do not upgrade packages for the wrong version; see my sig.

                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                Upvote 👍 helpful posts!

                1 Reply Last reply Reply Quote 1
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @Willever
                  last edited by

                  @Willever well that looks like that network 13.210.0.0/15 is included in your list..

                  And yeah its listed as being in the AU.

                  I don't use any of the pfblocker country lists like north america, etc. Not sure how some AU would of been added to that list.. I create my own lists.. I allow US for example..

                  But looking in my lists that has just US and US_reps in it.. And guess what, that is in there

                  lists.jpg

                  I removed the US_reps listing and its gone - that IP range is owned by amazon.. Who is registered US company.. So maybe that is how that gets in there.

                  amazon.jpg

                  It is broken out and registered to specific.. But the overall company lists that as their IP.

                  parent.jpg

                  The guy that could give us the real answer I would think would be @BBcan177

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  S 1 Reply Last reply Reply Quote 0
                  • S
                    SteveITS Galactic Empire @johnpoz
                    last edited by

                    IPv4 blocks move around as they are bought and sold, IIRC MaxMind updates once a month.

                    Another thing that can cause unexpected results is that if pfB deduplication is on, and any pfB-generated deny rules are enabled, pfBlocker will dedupe the lists across all rules not just within a list. That's probably not explaining it well as I'm in the middle of something but it can unexpectedly remove IPs from one alias. There was a long thread a year or two ago give or take.

                    Solution/workaround for that is to turn off dedupe, or IIRC use Alias Native and make your own rules.

                    Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                    When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                    Upvote 👍 helpful posts!

                    johnpozJ 1 Reply Last reply Reply Quote 1
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator @SteveITS
                      last edited by

                      @SteveITS said in pfBlockerNG not blocking some foreign sites using geoip:

                      or IIRC use Alias Native and make your own rules.

                      While I am a fan of that, and that is what I do - you will notice that US_reps contain that amazon space that is listed as being delegated to amazo-syd, which would be Sydney, AU which is where maxmind shows it to be..

                      My understand of the reps where to include like military bases, embassy's, etc. Representative of the US, but seems its way more inclusive that I thought.. And includes address space by US companies that is assigned elsewhere?

                      You can edit the NA listing in pfblocker to not include those..

                      usreps.jpg

                      If he is just looking to why they are allowed, that I believe is answered. Now the question would be does he want to actually allow those or not.. But looks like he can remove the us_rep from the NA list if he so desires..

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      W 1 Reply Last reply Reply Quote 1
                      • W
                        Willever @johnpoz
                        last edited by

                        When I was checking out the IPs - -I noticed quite often that amazon was involved. I unchecked the US reps and will see what happens.

                        I noticed that 85000 addresses were removed when PFB updated...

                        thank you!

                        No changes to Firewall rules, skipping Filter Reload

                        Updating: pfB_NAmerica_v4
                        85423 addresses deleted.

                        UPDATE PROCESS ENDED [ 02/2/24 06:12:41 ]

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.