Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Blocking with ipfilter.dat

    Scheduled Pinned Locked Moved Firewalling
    8 Posts 4 Posters 4.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mojo-chan
      last edited by

      Many P2P clients can make use of a file called ipfilter.dat, which can be found on the net. It's basically a huge blocklist of bad IP addresses belonging to the MAFIAA, spammers, ad servers, FBI etc. Is there some way to import this list into pfSense for blocking?

      1 Reply Last reply Reply Quote 0
      • D
        dhipo
        last edited by

        i think can be done ..
        create an alias and include the addresses

        create an drop rule to that alias..

        Dhix Networks
        Everything Secure

        http://www.dhix.com.br

        1 Reply Last reply Reply Quote 0
        • M
          mojo-chan
          last edited by

          The problem is that the text file containing the rules is 13 megs. Entering them manually would be impossible.

          1 Reply Last reply Reply Quote 0
          • GruensFroeschliG
            GruensFroeschli
            last edited by

            http://forum.pfsense.org/index.php/topic,6233.0.html

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            • M
              mojo-chan
              last edited by

              @GruensFroeschli:

              http://forum.pfsense.org/index.php/topic,6233.0.html

              Thanks, that sounds like it could be close to what I want, but I note that the alias system only allows single IP addresses, not ranges.

              Also, there is no simple way to update it, although that isn't such a big deal.

              1 Reply Last reply Reply Quote 0
              • GruensFroeschliG
                GruensFroeschli
                last edited by

                Aliases do allow ranges: –> Type of Alias: "Network"

                We do what we must, because we can.

                Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                1 Reply Last reply Reply Quote 0
                • F
                  fcapizzo
                  last edited by

                  I have a massive list I want to import also.  But after realizing that it would be stored in config.xml I feared that my list (~14MB in size) would slow down the pfSense box too much.

                  1 Reply Last reply Reply Quote 0
                  • GruensFroeschliG
                    GruensFroeschli
                    last edited by

                    I dont think so.
                    pfSense loads the xml at startup and after that runs from RAM. it only access the "slow" storage when you change something in the configuration.

                    (I think you would need REALLY REALLY many aliases to slow pfSense down)

                    We do what we must, because we can.

                    Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.