Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Country Block

    Scheduled Pinned Locked Moved pfSense Packages
    691 Posts 79 Posters 684.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      darklogic
      last edited by

      our domain name service provider is through network solutions. We reside in the US. I am not sure how you would be able to track down multiple DNS servers that the Blackberry's would end up using. I would image that our DNS servers are ok since browsing of our site and recieve incoming SMTP seems to be working ok, which would use our DNS. This problem seems to be somewhere along the lines of affecting BlackBerry devices that are connecting over owa using the Blackberry RIM service. Example of connection https://mail.ourdomain.com/owa

      As far as knowing if they are hitting out of US DNS servers, I am not really sure how to find that out.

      Thanks,

      Matt

      1 Reply Last reply Reply Quote 0
      • S
        Supermule Banned
        last edited by

        Try to traceroute the traffic from the blackberry. Could be so that they use a subvendor for specific traffic and he is located in one of the blocked countries.

        1 Reply Last reply Reply Quote 0
        • D
          dpg2
          last edited by

          Perhaps the following KB article from blackberry.com will help:

          http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB11036&sliceId=SAL_Public&dialogID=69199896&stateId=0%200%20692%2001325

          Are these blocks being blocked?

          1 Reply Last reply Reply Quote 0
          • D
            darklogic
            last edited by

            dpg2

            This was very helpful. I went to the countrysipblocks.net and checked the IP's by CIDR, and it looks as if all BlackBerry service goes to either United Kingdom or Canada, mostly Canada. And yes I have both of them blocked. I did not try a trace route yet. I am supprised to see that it appears all BlackBerry servers our not in the States, not one at all??? So if this is totally accurate how would I allow only those CIDRS and block the rest of the Country?

            Thanks,

            Matt

            1 Reply Last reply Reply Quote 0
            • D
              dpg2
              last edited by

              Research in Motion is a Canadian company with its headquarters in Waterloo, Ontario.

              I guess you need an 'allow' rule for the Blackberry blocks ahead of the 'deny' rules that the Country Block package puts in place. I'm not sure how flexible the Country Block package is for that sort of thing.

              I believe the 'URL Table Aliases' package may offer a solution since the address blocks can be handled as aliases and governed by rules directly in the web interface. Perhaps you could share a Blackberry IP list from an internal server (or the pfsense box itself) and access it via a local URL (or just add the BB blocks to a regular alias, there aren't that many of them), and do the same with a list copied from countrysipblocks.net.

              1 Reply Last reply Reply Quote 0
              • G
                g4m3c4ck
                last edited by

                I can not get country block to stay running for the life of me. I have cron running the script every five minutes and I know it is executing because I have the its output logged to a temporary file and the timestamp is correct. It seems to be working but it always says "not running" in red.

                1 Reply Last reply Reply Quote 0
                • S
                  Supermule Banned
                  last edited by

                  Use Firefox to see it.

                  1 Reply Last reply Reply Quote 0
                  • G
                    g4m3c4ck
                    last edited by

                    I was about to kick myself in the head because I have become so accustomed to chrome and I forget I am using it. However, firefox yields the same results for me.

                    1 Reply Last reply Reply Quote 0
                    • S
                      Supermule Banned
                      last edited by

                      Are you rendering the page in FF or IE??

                      1 Reply Last reply Reply Quote 0
                      • G
                        g4m3c4ck
                        last edited by

                        Ok this really goes in the DUR department. Refreshing the page works wonders lol. In both ff and chrome.

                        1 Reply Last reply Reply Quote 0
                        • S
                          Supermule Banned
                          last edited by

                          DUR?? Forgive for not beeing native to the lanquage ;)

                          @g4m3c4ck:

                          Ok this really goes in the DUR department. Refreshing the page works wonders lol. In both ff and chrome.

                          1 Reply Last reply Reply Quote 0
                          • S
                            simby
                            last edited by

                            not working on pfsense 2.0,.. can you please check?  ???

                            1 Reply Last reply Reply Quote 0
                            • T
                              tommyboy180
                              last edited by

                              I can't think of a reason why it wouldn't work, but then again I never bothered to test on 2.0 beta. Hopefully I will find sometime in the next couple of days to check it out.

                              I do need this package to work on 2.0 so I will get it working shortly.

                              -Tom Schaefer
                              SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

                              Please support pfBlocker | File Browser | Strikeback

                              1 Reply Last reply Reply Quote 0
                              • S
                                simby
                                last edited by

                                Thanks Tomy :)

                                1 Reply Last reply Reply Quote 0
                                • X
                                  XIII
                                  last edited by

                                  Really good package Tommy, thanks for your help.

                                  -Chris Stutzman
                                  Sys0:2.0.1: AMD Sempron 140 @2.7 1024M RAM 100GHD
                                  Sys1:2.0.1: Intel P4 @2.66 1024M RAM 40GHD
                                  freedns.afraid.org - Free DNS dynamic DNS subdomain and domain hosting.
                                  Check out the pfSense Wiki

                                  1 Reply Last reply Reply Quote 0
                                  • D
                                    darklogic
                                    last edited by

                                    I am currently running 1.2.3-RELEASE and thanks on the post with information on BlackBerry. I was able to find the CIDR range our BB are using for service. The only thing I am still trying to figure out is how to block the rest of the Country without manually creating an ALIAS list of CANADA IP's? I noticed that the texted is correct under the package interface when making a change to the firewall, that you must save/update the Country Block package to get it running again everytime you make a firewall change. Country Block itself seems to run good without the help of cron. What I think would be neat is to be able to do a block all country and then input an unblock CIDR option under the selected country, that way the whole country would be blocked other than a specified CIDR or list of CIDR's and ranges. Something else I think would be cool is having a log or barnyard dump of data so you can see statistics on blocked country IP's and where the major attacks and brech attempts are comning from.

                                    The package itself is very cool and in early development, but yet is is so effective. I would love to see the Country Block package become a standard integrated part of the pfsense install along with a few other packages such as IP Block, SNORT, Deep Packet Inspection, and E-mail filtering forwarder.

                                    Thanks for all the support and help on this package.

                                    Matt

                                    1 Reply Last reply Reply Quote 0
                                    • G
                                      g4m3c4ck
                                      last edited by

                                      Why don't you locate the store for the canadian IPs on your local file system and remove the IP range in question?

                                      1 Reply Last reply Reply Quote 0
                                      • D
                                        darklogic
                                        last edited by

                                        g4m3c4ck

                                        Not sure how to go about doing this? ???

                                        Thanks,

                                        Matt

                                        1 Reply Last reply Reply Quote 0
                                        • K
                                          kapara
                                          last edited by

                                          Could it be setup so that those rules were applied at the end so that any allows above it in the firewall rules would allow the traffic.  I am ssuming 2 things of course.  1. That the rules apply top down… 2. That the package can be configured as such.

                                          Great package when I learned a couple of painful lessons....  ;D

                                          Skype ID:  Marinhd

                                          1 Reply Last reply Reply Quote 0
                                          • T
                                            tommyboy180
                                            last edited by

                                            @darklogic:

                                            g4m3c4ck

                                            Not sure how to go about doing this? ???

                                            Thanks,

                                            Matt

                                            Right now there is no really decent way to remove IPs from the countryblock table. I will have to make a whitelist addon for the package. Hopefully I can sit down and do that soon. I just haven't had the time.

                                            -Tom Schaefer
                                            SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

                                            Please support pfBlocker | File Browser | Strikeback

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.