Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Issue with pfBlocker GEOIP

    pfBlockerNG
    4
    11
    1.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator @Abramelin
      last edited by johnpoz

      @Abramelin Not exactly sure what your hoping to accomplish.. But little advice, its much easier to allow than to try and block everything else..

      I use geoip aliases to allow inbound into my services I have open to the public, but I limit it to US ips.. and some others that I have created.

      This is much smaller list than trying to block the planet.

      allow.jpg

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

      A 1 Reply Last reply Reply Quote 0
      • A
        Abramelin @johnpoz
        last edited by

        @johnpoz Thanks sir i will do that!

        S 1 Reply Last reply Reply Quote 0
        • S
          SteveITS Galactic Empire @Abramelin
          last edited by

          @Abramelin I’d think this problem would apply to pfBlocker as well:
          https://forum.netgate.com/topic/186065/heads-up-new-suricata-7-0-3-package-is-coming-soon
          …might need an update to it.

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote 👍 helpful posts!

          T 1 Reply Last reply Reply Quote 0
          • T
            tieskekiggen @SteveITS
            last edited by

            @SteveITS
            I have the same issue as the TS with GeoIP.
            The link to the post you sent gives me access denied even though I am logged into the forum.
            042660a9-2cd3-4bf6-b4d0-392d3e8fe1fb-image.png
            What was the problem/fix given therein?
            Thanks in advance!

            johnpozJ 1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @tieskekiggen
              last edited by

              @tieskekiggen that post was deleted because it was release, here is the release notes

              https://forum.netgate.com/topic/186071/suricata-package-v7-0-3-available-here-are-the-release-notes

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              T 1 Reply Last reply Reply Quote 0
              • T
                tieskekiggen @johnpoz
                last edited by

                @johnpoz
                Thanks for the reply.
                But I don't think that is the issue because the lists are downloading to the system and contain IP information.
                pfblocker.png
                It seems to be an issue in pfBlocker.
                This is a fresh installation of pfBlocker on the machine.
                I've put all continents on deny inbound except Europe.
                4752561b-6a4e-4064-9a49-7b06933dbbe9-image.png
                After an update/reload the aliases for the continents are not created, but the default block list is working.
                213f662b-2f1a-47b8-81d8-51dd68dfa261-image.png
                Any idea what it could be?

                johnpozJ 1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @tieskekiggen
                  last edited by

                  @tieskekiggen I already went over my suggestion.. You shouldn't be trying to block the world.. If all you want to allow is EU, then just allow that..

                  There is little point to blocking the whole planet, when there is a default deny.. If you do not allow it, its blocked anyway. Create your rules with the allow in them. See my screenshot above.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                  T 1 Reply Last reply Reply Quote 0
                  • T
                    tieskekiggen @johnpoz
                    last edited by

                    @johnpoz
                    Yes I understand that, when I get it working, I will implement it differently too. This was purely for testing.
                    But the problem I am running into now is that the aliases it is supposed to create are not creating.
                    Hence my question as to how it could be that it doesn't work.
                    It seems to be nothing with the MaxMind license because I see the downloaded files in the /usr/local/share/GeoIP folder. Only pfBlocker is not creating the needed aliases.

                    johnpozJ 1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator @tieskekiggen
                      last edited by

                      @tieskekiggen look in your table to validate the alias is populated.

                      table.jpg

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                      T 1 Reply Last reply Reply Quote 0
                      • T
                        tieskekiggen @johnpoz
                        last edited by

                        @johnpoz
                        Found the issue, I didn't choose the countries within the continent.
                        Therefore, it was not creating the alias.
                        Thanks for your quick responses anyway!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.