Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Issue with pfBlocker GEOIP

    pfBlockerNG
    4
    11
    1.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      Abramelin
      last edited by

      Hello, guys!
      Can someone help me with this issue?
      The problem is that I'm trying to add countries in GEOIP block and enable it, but when I click on the IP tab and IPV4, this tab doesn't show the rules to be enabled.
      1978ad12-d922-42fd-a709-5ec10a980a29-image.png
      b7d0417a-9c33-44db-ae04-bdd458e98f01-image.png
      b78a384b-7d53-4524-b3e8-bd9b4c89827b-image.png

      I have checked the list of the GEOIPs using /usr/local/share/GeoIP/cc/, and I can see that some lists have no IP inside. So, I think that my issue is at this step, but I don't know how to force this update properly or if something in my firewall is blocking any MaxMind repository.

      I'm thinking of excluding all files from /usr/local/share/GeoIP/cc/ and trying to recreate it again with cron.

      Have you guys already faced this issue? If the answer is yes, what was the solution that you applied to it?

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @Abramelin
        last edited by johnpoz

        @Abramelin Not exactly sure what your hoping to accomplish.. But little advice, its much easier to allow than to try and block everything else..

        I use geoip aliases to allow inbound into my services I have open to the public, but I limit it to US ips.. and some others that I have created.

        This is much smaller list than trying to block the planet.

        allow.jpg

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        A 1 Reply Last reply Reply Quote 0
        • A
          Abramelin @johnpoz
          last edited by

          @johnpoz Thanks sir i will do that!

          S 1 Reply Last reply Reply Quote 0
          • S
            SteveITS Galactic Empire @Abramelin
            last edited by

            @Abramelin I’d think this problem would apply to pfBlocker as well:
            https://forum.netgate.com/topic/186065/heads-up-new-suricata-7-0-3-package-is-coming-soon
            …might need an update to it.

            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
            Upvote 👍 helpful posts!

            T 1 Reply Last reply Reply Quote 0
            • T
              tieskekiggen @SteveITS
              last edited by

              @SteveITS
              I have the same issue as the TS with GeoIP.
              The link to the post you sent gives me access denied even though I am logged into the forum.
              042660a9-2cd3-4bf6-b4d0-392d3e8fe1fb-image.png
              What was the problem/fix given therein?
              Thanks in advance!

              johnpozJ 1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator @tieskekiggen
                last edited by

                @tieskekiggen that post was deleted because it was release, here is the release notes

                https://forum.netgate.com/topic/186071/suricata-package-v7-0-3-available-here-are-the-release-notes

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                T 1 Reply Last reply Reply Quote 0
                • T
                  tieskekiggen @johnpoz
                  last edited by

                  @johnpoz
                  Thanks for the reply.
                  But I don't think that is the issue because the lists are downloading to the system and contain IP information.
                  pfblocker.png
                  It seems to be an issue in pfBlocker.
                  This is a fresh installation of pfBlocker on the machine.
                  I've put all continents on deny inbound except Europe.
                  4752561b-6a4e-4064-9a49-7b06933dbbe9-image.png
                  After an update/reload the aliases for the continents are not created, but the default block list is working.
                  213f662b-2f1a-47b8-81d8-51dd68dfa261-image.png
                  Any idea what it could be?

                  johnpozJ 1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator @tieskekiggen
                    last edited by

                    @tieskekiggen I already went over my suggestion.. You shouldn't be trying to block the world.. If all you want to allow is EU, then just allow that..

                    There is little point to blocking the whole planet, when there is a default deny.. If you do not allow it, its blocked anyway. Create your rules with the allow in them. See my screenshot above.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                    T 1 Reply Last reply Reply Quote 0
                    • T
                      tieskekiggen @johnpoz
                      last edited by

                      @johnpoz
                      Yes I understand that, when I get it working, I will implement it differently too. This was purely for testing.
                      But the problem I am running into now is that the aliases it is supposed to create are not creating.
                      Hence my question as to how it could be that it doesn't work.
                      It seems to be nothing with the MaxMind license because I see the downloaded files in the /usr/local/share/GeoIP folder. Only pfBlocker is not creating the needed aliases.

                      johnpozJ 1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator @tieskekiggen
                        last edited by

                        @tieskekiggen look in your table to validate the alias is populated.

                        table.jpg

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                        T 1 Reply Last reply Reply Quote 0
                        • T
                          tieskekiggen @johnpoz
                          last edited by

                          @johnpoz
                          Found the issue, I didn't choose the countries within the continent.
                          Therefore, it was not creating the alias.
                          Thanks for your quick responses anyway!

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.