• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

network alias blocks more than defined

Firewalling
3
16
393
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • N
    nopanic
    last edited by Dec 27, 2024, 12:15 PM

    Hello all,

    Im having a chinese attack and want to stop them. I created a network alias and worked with the pfsense-log, whois and ipcalc. Now I have about ~150 nets in my blacklist. But Im no longer getting mails from debian mailinglist, ubuntu mailing-list or xing. Checking the log it tells me that my blacklist is blocking.
    I searched multiple times but can not find these nets in my blacklist,

    Whats wrong? Is pfsense here not correct working?
    Can I debug this?
    Can someone help?

    Tia
    Stefan

    J S 2 Replies Last reply Dec 27, 2024, 3:12 PM Reply Quote 0
    • J
      johnpoz LAYER 8 Global Moderator @nopanic
      last edited by Dec 27, 2024, 3:12 PM

      @nopanic what IPs are being blocked exactly, and what nets are in your alias - if rule is blocking that has your alias, then clearly you have that network in your alias.. You need to validate your using the correct masks for your networks for the networks you want to block.

      For example you might have something like 192.168.0.0/23 vs a /24 and now 192.168.1.x address would also be blocked but you might not notice that in a visual scan of your alias networks.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

      N 1 Reply Last reply Dec 27, 2024, 3:46 PM Reply Quote 0
      • N
        nopanic @johnpoz
        last edited by Dec 27, 2024, 3:46 PM

        @johnpoz thanks for your reply,

        yes you are correct. Im sure that the masks are okay, casue I checked with whois and ipcalc which gives me the correct masks!
        I also had a look to higher mask, I had the same suspicion as you. But I can not find such net.

        Do I have to do a new alias and copy step by step from old to new one if its running or not.
        Or are there other methods to debug this?

        thanks!
        Stefan

        J 1 Reply Last reply Dec 27, 2024, 3:59 PM Reply Quote 0
        • S
          SteveITS Galactic Empire @nopanic
          last edited by Dec 27, 2024, 3:47 PM

          @nopanic So you are hosting your own email server? I suggest:

          • use a third party spam filtering service, and only allow the service's IPs to connect to your mail server

          or

          • use pfBlocker and enable block lists such as Spamhaus and other PR1 feeds (the "top spammers" GeoIP list/page blocks entire countries, I suggest ignoring that part of the GUI)

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote 👍 helpful posts!

          1 Reply Last reply Reply Quote 0
          • J
            johnpoz LAYER 8 Global Moderator @nopanic
            last edited by johnpoz Dec 27, 2024, 4:00 PM Dec 27, 2024, 3:59 PM

            @nopanic said in network alias blocks more than defined:

            casue I checked with whois and ipcalc which gives me the correct masks!

            that doesn't mean your not blocking more than what you want to block..

            Whois can give a large block, but maybe the who you want to block is using just a portion of that.

            Please post up your alias and the block your seeing in the log for the IP.

            You can export your alias, and then attach the file.

            login-to-view

            rfc1918.txt

            See my export of my rfc1918 alias as example.

            If pfsense is blocking per a rule you have with alias of networks - then the IP is in there.. So either you have a wrong mask or your blocking a larger network than what you want to block.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            N 2 Replies Last reply Dec 27, 2024, 4:24 PM Reply Quote 0
            • N
              nopanic @johnpoz
              last edited by Dec 27, 2024, 4:24 PM

              @johnpoz
              okay
              thanks I attach the file.

              @SteveITS yes, my own mailserver which is very secure. The ip's are blocked on firewall....

              thanks!
              Stefan
              1_badguys_most_china_assholes.txt

              1 Reply Last reply Reply Quote 0
              • N
                nopanic @johnpoz
                last edited by Dec 27, 2024, 4:29 PM

                @johnpoz inthe attached file: china is beginninbg with inetnum in discription

                Thanks Stefan

                J 1 Reply Last reply Dec 27, 2024, 4:35 PM Reply Quote 0
                • J
                  johnpoz LAYER 8 Global Moderator @nopanic
                  last edited by Dec 27, 2024, 4:35 PM

                  @nopanic and which specific IP is being blocked and logged that you feel is wrong?

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                  N 1 Reply Last reply Dec 27, 2024, 4:37 PM Reply Quote 0
                  • N
                    nopanic @johnpoz
                    last edited by Dec 27, 2024, 4:37 PM

                    @johnpoz ex. the mailinglist server of debian:

                    ;; ANSWER SECTION:
                    bendel.debian.org. 600 IN A 82.195.75.100

                    thanks
                    Stefan

                    J 1 Reply Last reply Dec 27, 2024, 4:40 PM Reply Quote 0
                    • J
                      johnpoz LAYER 8 Global Moderator @nopanic
                      last edited by johnpoz Dec 27, 2024, 5:09 PM Dec 27, 2024, 4:40 PM

                      @nopanic that is in your log? that 82.195.75.100 IP - just because that is what the A record and dns shows - doesn't mean that is the IP that actually sending email - please show the log where a specific IP was blocked.

                      there is no 82.x in that alias list you posted.

                      example: here are some IPs that were blocked by different rules I have with aliases

                      login-to-view

                      login-to-view

                      Also notice that not allowed rule is a ! rule, so the stuff it blocks would be IPs that are NOT listed in the alias/table

                      edit2: dude - this entry would block that

                      64.0.0.0/2

                      Which would be this huge range that 82.x falls into
                      64.0.0.0 - 127.255.255.255

                      That for sure can not be correct..

                      You also have a 128.0.0.0/2 which is also huge
                      128.0.0.0 - 191.255.255.255

                      I think something went wrong why does the 64/2 show this for text?

                      64.0.0.0/2 inetnum: 58.56.0.0 - 58.59.127.255 netname:

                      These don't seem correct for sure

                      login-to-view

                      edit3: just a quick scan, and you have lots of them in there that are way to big for what the text says it should be blocking

                      27.115.0.0/17 inetnum: 27.115.5.0 - 27.115.5.7 netname:

                      that /17 would block all ips between 27.115.0.0 - 27.115.127.255, not just what the text says 27.115.5.0 - 27.115.5.7

                      edit4: another one that is just huge compared to the text

                      36.192.0.0/11 inetnum: 36.212.0.0 - 36.215.255.255 netname:

                      36.192/11 would block 36.192.0.0 - 36.223.255.255, not that 36.212-215 range. If you wanted to block 36.212 to 36.215 that would be a 36.212.0.0/14 mask. not a 36.192/11

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                      N 2 Replies Last reply Dec 27, 2024, 5:01 PM Reply Quote 0
                      • N
                        nopanic @johnpoz
                        last edited by Dec 27, 2024, 5:01 PM

                        @johnpoz ahh okay thanks!!!

                        I attach the screenshot of the block:
                        login-to-view

                        S J 2 Replies Last reply Dec 27, 2024, 5:19 PM Reply Quote 0
                        • N
                          nopanic @johnpoz
                          last edited by Dec 27, 2024, 5:13 PM

                          @johnpoz

                          I get the inetnum from whois. ipcalc deaggrigate some nets so I have same discription ....

                          tia
                          Stefan

                          J 1 Reply Last reply Dec 27, 2024, 5:25 PM Reply Quote 0
                          • S
                            SteveITS Galactic Empire @nopanic
                            last edited by Dec 27, 2024, 5:19 PM

                            @nopanic 10.x.x.x is a private IP range...?

                            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                            Upvote 👍 helpful posts!

                            1 Reply Last reply Reply Quote 0
                            • J
                              johnpoz LAYER 8 Global Moderator @nopanic
                              last edited by johnpoz Dec 27, 2024, 5:23 PM Dec 27, 2024, 5:21 PM

                              @nopanic you might want to start over - there is a lot of wrong stuff in there for sure

                              8.0.0.0/8 net 8 Alibaba Cloud

                              Not sure how that is Alibaba Cloud, the 8/8 is owned by multiple different companies.

                              NetRange:       8.0.0.0 - 8.8.3.255
                              CIDR:           8.0.0.0/13, 8.8.0.0/22
                              Organization:   Level 3 Parent, LLC (LPL-141)
                              

                              I show

                              inetnum:        8.128.0.0 - 8.159.255.255
                              netname:        ALICLOUD
                              

                              So you can not block 8/8 without blocking a whole bunch of stuff you prob don't want to block.

                              edit: If you are wanting to block whole countries, etc. you might want to look into pfblocker as someone else mentioned.. It allows you to create aliases based on countries - so you could block china and korea, etc. etc..

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                              1 Reply Last reply Reply Quote 0
                              • J
                                johnpoz LAYER 8 Global Moderator @nopanic
                                last edited by Dec 27, 2024, 5:25 PM

                                @nopanic however your creating these netblocks - your blocking way more than just the netblock of the bad guy.. I mean that 64.0.0.0/2 is a HUGE amount of addresses - HUGE!!

                                An intelligent man is sometimes forced to be drunk to spend time with his fools
                                If you get confused: Listen to the Music Play
                                Please don't Chat/PM me for help, unless mod related
                                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                N 1 Reply Last reply Dec 27, 2024, 5:40 PM Reply Quote 0
                                • N
                                  nopanic @johnpoz
                                  last edited by Dec 27, 2024, 5:40 PM

                                  @johnpoz super!
                                  you helped my a lot.I will have a look to pfblocker and I check the alias again.

                                  Thanks for help!
                                  Stefan

                                  1 Reply Last reply Reply Quote 0
                                  2 out of 16
                                  • First post
                                    2/16
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.