Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Note about "Bogon Network" blocking.

    Scheduled Pinned Locked Moved Firewalling
    9 Posts 5 Posters 4.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F Offline
      FJSchrankJr
      last edited by

      Not sure about pfSense 2.0-RC1 but the the bogon network blocking rule for pfSense 1.2.3-RELEASE should be updated (IPv4). We just had a India based ISP contact us because their new IP allocation of 1.22.0.0 was blocked automatically by this rule and their users could not access our network.

      Those rules are in place to prevent unassigned/reserved networks from accessing you which is great but because of the IPv4 shortage more and more IPs from these bogon IP blocks are being assigned so it either needs to be updated or removed in certain cases like ours.

      FJS - Embedded Systems Engineer
      Pictures are worth a thousand words, but <u>posting config.xml backups are worth 10,000</u>.  Alter the IPs, change anything revealing but leave subnets intact. Use find and replace. Please try to keep it brief on the description.
      ALWAYS disable TSO  & LRO EXCEPT CHKSUM IF SUPPORTED. TSO/LRO breaks traffic, pf scrub and this goes for any passive device inline

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG Offline
        GruensFroeschli
        last edited by

        It automatically updates once a month.

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • F Offline
          FJSchrankJr
          last edited by

          @GruensFroeschli:

          It automatically updates once a month.

          In 2.0-RC1 or 1.2.3-RELEASE? or, both? Thank you.

          FJS - Embedded Systems Engineer
          Pictures are worth a thousand words, but <u>posting config.xml backups are worth 10,000</u>.  Alter the IPs, change anything revealing but leave subnets intact. Use find and replace. Please try to keep it brief on the description.
          ALWAYS disable TSO  & LRO EXCEPT CHKSUM IF SUPPORTED. TSO/LRO breaks traffic, pf scrub and this goes for any passive device inline

          1 Reply Last reply Reply Quote 0
          • GruensFroeschliG Offline
            GruensFroeschli
            last edited by

            The same on 1.2.3 and 2.0

            Go to YourPfSense/status.php and search for the <cron>tag.
            You should see somewhere this:
                    <minute>1</minute>
                        <hour>3</hour>
                        <mday>1</mday>
                        <month></month>
                        <wday>
            </wday>
                        <who>root</who>
                        <command></command>/usr/bin/nice -n20 /etc/rc.update_bogons.sh</cron>

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            • F Offline
              FJSchrankJr
              last edited by

              @GruensFroeschli:

              The same on 1.2.3 and 2.0

              Go to YourPfSense/status.php and search for the <cron>tag.
              You should see somewhere this:
                      <minute>1</minute>
                         <hour>3</hour>
                         <mday>1</mday>
                         <month></month>
                         <wday>
              </wday>
                         <who>root</who>
                         <command></command>/usr/bin/nice -n20 /etc/rc.update_bogons.sh</cron>

              I had no idea there was a cron job for that. I will manually run that script and change the timing on the job, thanks.

              btw: "No I will not fix your computer!", That drives me nuts people assume you will fix their computer because you are involved with I.T. stuff… The more you know, the more they ask. I am going to start telling people I work at Burger King.

              FJS - Embedded Systems Engineer
              Pictures are worth a thousand words, but <u>posting config.xml backups are worth 10,000</u>.  Alter the IPs, change anything revealing but leave subnets intact. Use find and replace. Please try to keep it brief on the description.
              ALWAYS disable TSO  & LRO EXCEPT CHKSUM IF SUPPORTED. TSO/LRO breaks traffic, pf scrub and this goes for any passive device inline

              1 Reply Last reply Reply Quote 0
              • AhnHELA Offline
                AhnHEL
                last edited by

                In the 2.0 Web GUI, you can go to Diagnostics/Tables and select Bogons from the Tables drop down menu.  Hit the download button to update manually without changing the Cron job.

                AhnHEL (Angel)

                1 Reply Last reply Reply Quote 0
                • F Offline
                  FJSchrankJr
                  last edited by

                  @onhel:

                  In the 2.0 Web GUI, you can go to Diagnostics/Tables and select Bogons from the Tables drop down menu.  Hit the download button to update manually without changing the Cron job.

                  Great – thank you for that. I have not played around too much with 2.0-RC1 other then some testing.

                  FJS - Embedded Systems Engineer
                  Pictures are worth a thousand words, but <u>posting config.xml backups are worth 10,000</u>.  Alter the IPs, change anything revealing but leave subnets intact. Use find and replace. Please try to keep it brief on the description.
                  ALWAYS disable TSO  & LRO EXCEPT CHKSUM IF SUPPORTED. TSO/LRO breaks traffic, pf scrub and this goes for any passive device inline

                  1 Reply Last reply Reply Quote 0
                  • 9 Offline
                    900mhzdude
                    last edited by

                    sense we are on the Topic how do I get this option on my other 2 WAN's in pfsense 1.2.3?

                    I Can only get it on Primary WAN :(

                    1 Reply Last reply Reply Quote 0
                    • C Offline
                      cmb
                      last edited by

                      @900mhzdude:

                      sense we are on the Topic how do I get this option on my other 2 WAN's in pfsense 1.2.3?

                      you can't, 2.0 only.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.