Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IP Country Block {Now $150}

    Scheduled Pinned Locked Moved Expired/Withdrawn Bounties
    14 Posts 9 Posters 17.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      kapara
      last edited by

      Your reasoning makes sense.  ;D

      Skype ID:  Marinhd

      1 Reply Last reply Reply Quote 0
      • J
        jigpe
        last edited by

        Is this possible in pfsense 1.2.2?

        jigp
        Davao City

        1 Reply Last reply Reply Quote 0
        • E
          eri--
          last edited by

          I would do a package for this when i find time.

          1 Reply Last reply Reply Quote 0
          • 0
            0tt0
            last edited by

            @Farsheed:

            One very helpful feature will be to create firewall rules based on a country's IP address. I am currently using aliases to do this but this is a tedious work specially since there is a limit in the number entries in an alias. So if someone can create a module for this I am willing to put $100 into it. I imagine the UI would have a drop down option to pick a country. It would be great for the list of IPs to be editable so it can be updated if needed. I currently use the following website http://www.countryIPblocks.net/ to get my IP list and it seems to be very accurate.

            Is such a service really correct enough?

            1 Reply Last reply Reply Quote 0
            • F
              Farsheed
              last edited by

              To the best of my knowledge it is. IANA assigns address blocks to Regional Internet Registries. ISP's then apply for their IP block from their Local Internet Registry http://www.iana.org/numbers/. Such allocation is kept in a database (updated regularly) which can be downloaded from the appropriate Regional Registry ftp://ftp.arin.net/pub/stats/.

              1 Reply Last reply Reply Quote 0
              • 0
                0tt0
                last edited by

                @Farsheed:

                To the best of my knowledge it is. IANA assigns address blocks to Regional Internet Registries. ISP's then apply for their IP block from their Local Internet Registry http://www.iana.org/numbers/. Such allocation is kept in a database (updated regularly) which can be downloaded from the appropriate Regional Registry ftp://ftp.arin.net/pub/stats/.

                Ok, if this works not only in theory but also in practice it's obviously a very handy feature for any FW-admin.

                Cheers,

                1 Reply Last reply Reply Quote 0
                • C
                  cheesyboofs
                  last edited by

                  +1 for this feature,

                  Spam is my biggest bug bare ATM, I can filter it out but not stop the initial connection to my graylist server - this feature would help greatly.

                  I could imagine a GUI page of flags where by you would tick a check box next to the flag of the countries you would like to block.

                  Cheers

                  Author of pfSense themes:

                  DARK-ORANGE

                  CODE-RED

                  1 Reply Last reply Reply Quote 0
                  • ?
                    Guest
                    last edited by

                    Please do not make feature requests or comments on the bounty unless you are contributing money to the bounty.

                    1 Reply Last reply Reply Quote 0
                    • C
                      cheesyboofs
                      last edited by

                      OK + {$50} then.

                      Author of pfSense themes:

                      DARK-ORANGE

                      CODE-RED

                      1 Reply Last reply Reply Quote 0
                      • J
                        jamesdean
                        last edited by

                        Perfect timing…..

                        Right now I have scripts that do what you guys want.
                        My scripts download blacklists and inject them into the firewall.

                        OpenBSD keeps a country black list somewhere, I could easily add those.
                        For example they have a black list of all of China and Korea.

                        I could make it into a package with a gui if you guys want, I'm really busy with work right now so I cant give you a date.

                        James

                        1 Reply Last reply Reply Quote 0
                        • T
                          tommyboy180
                          last edited by

                          This bounty is complete with the countryblock package

                          -Tom Schaefer
                          SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

                          Please support pfBlocker | File Browser | Strikeback

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.