Not able to whitelist a particular IP
-
hello,
I need some help here. I have pfsnese + with pfblockerNG + Snort installed. I do have some basic configurations and rules. But I do have an ip address that, it doesn't matter what I do (created rules, put on very top, whitelisted within pfgblock) and nothing, I cannot have this website to open. the ip for this address is: 71.19.251.70. Could anybody help me, please?
-
You were able to visit that site with pfSense, and now you've added some tools and you can't visit the site ?
pfBlockerng shows what IP it blocked.
pfBlockerng, by itself, when you install it, does nothing. When you start to add IP lists (that contain the IP of the site you want to visit) and you then set up that list to be used to block connection going outside, then yeah, then you get what you are looking for.If you use DNSBL, visit Firewall > pfBlockerNG > Alerts and look up the host name of the site.
If you use IP lists, remove them all, and re add them one after the other. As soon as pfBlocker starts to block, you've found the list where you have to place your whitelist.
Or open every IP list, and look for the IP yourself.snort : that's way over my pay grade, that an expert filter tool, can't tell anything about that one.
-
@Gertjan Thanks for the reply. I was able to find this IP been blocked by the pfB_PRI1_v4. It doesn't matter adding that ip to the whitelist, it remains blocked.... Not Sure what to do anymore.... I will keep trying.
appreciate it. -
Normally, I don't use IP block lists, as I don't need a tool that forbids me to go somewhere, if I don't want to go there in the first place.
But ok - let's install pfB_PRI1_v4 :
and activate it so it block outbound connections :
After a Force reload :
all is set up : I've now a floating rule that blocks all IPv4 addresses/networks that are in the list :
Let's look at the list : https://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt
and take the very first IP (IP? not the network !) as an example :
I take a browser, and go to :
and sure enough, after some time :
The pfBlockerng alert tells me the same thing :
and under IP Block stats I see the same thing : my PC, 192.168.1.6, was blocked when it tried to access 1.10.16.1 :
Ok, I add this IP to the white list of this feed :
Click on the black round +symbol :
You are probably asked if a whitelist should be created, and if you want to add a comment, etc.
Now I wind up on this page :
and at the bottom I can see that "10.16.10.1" was added.
Save this page.When force reloading, I can see that I have the original feed, and the whitelist :
Sure enough, 10.16.10.1 wasn't a web server, so my browser, still can't connect to it, but this IP isn't blocked anymore.
When I visit it again, the IP block counter doesn't rise = the IP wasn't blocked by pfSense.edit :
Just to be sure, as this is not a click contest, but we're still managing a firewall the old classic way :
Check that the new Whitelist or permit rule is above the block rule.
My white list rule hs taken 'hits' :which means that the rule (with just one IP in it) matched outgoing traffic : that was me trying to contact 10.16.10.1 with my browser.