Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IP-Blocklist

    Scheduled Pinned Locked Moved pfSense Packages
    496 Posts 86 Posters 498.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      firbc
      last edited by

      Hi,

      is there any why to allow connection to blocked IP's on port 80? And if there is any way to manualy add my own IP's to whitelist? Let says that I like to unlock only one specific IP which is in blocklist.

      1 Reply Last reply Reply Quote 0
      • T
        tommyboy180
        last edited by

        That will be in a future release.

        -Tom Schaefer
        SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

        Please support pfBlocker | File Browser | Strikeback

        1 Reply Last reply Reply Quote 0
        • F
          firbc
          last edited by

          Hi again,

          Will it be possible to enable blocking only for some IP's on local network? Let say that you want to allow or denied different blocklists for different IP's on network. So one IP on local network can access everything and another would be blocked according to blocklist.

          1 Reply Last reply Reply Quote 0
          • T
            tommyboy180
            last edited by

            @firbc:

            Hi again,

            Will it be possible to enable blocking only for some IP's on local network? Let say that you want to allow or denied different blocklists for different IP's on network. So one IP on local network can access everything and another would be blocked according to blocklist.

            It's possible now. Take a loot at the interface options. If you create another network then you can allow/deny lists to a specific network.

            -Tom Schaefer
            SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

            Please support pfBlocker | File Browser | Strikeback

            1 Reply Last reply Reply Quote 0
            • F
              firbc
              last edited by

              So if I understand you correctly, blocklists will work for specific computer on local network?

              example:

              1 Reply Last reply Reply Quote 0
              • T
                tommyboy180
                last edited by

                Yes, if that computer is on a separate interface.

                -Tom Schaefer
                SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

                Please support pfBlocker | File Browser | Strikeback

                1 Reply Last reply Reply Quote 0
                • L
                  lhchia
                  last edited by

                  use browser GC or MF to reinstall.

                  IP-Blocklist Version 3.5 released!

                  blocklists are saved on system to ease updates
                  Corrected issues with uninstall
                  available for pfsense 2.0

                  1 Reply Last reply Reply Quote 0
                  • L
                    lhchia
                    last edited by

                    i need to unblock facebook.com from iblock list.

                    i vi to usr/local/www/pakages/iblocklist/list/bt_level2.gz

                    del favebook inc: <ip address="">save / update

                    but squid still show block.

                    please guide.

                    many thanks</ip>

                    1 Reply Last reply Reply Quote 0
                    • T
                      tommyboy180
                      last edited by

                      @lhchia:

                      i need to unblock facebook.com from iblock list.

                      i vi to usr/local/www/pakages/iblocklist/list/bt_level2.gz

                      del favebook inc: <ip address="">save / update

                      but squid still show block.

                      please guide.

                      many thanks</ip>

                      Why not just create a whitelist with all Facebook IP's.

                      -Tom Schaefer
                      SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

                      Please support pfBlocker | File Browser | Strikeback

                      1 Reply Last reply Reply Quote 0
                      • L
                        lhchia
                        last edited by

                        @tommyboy180:

                        @lhchia:

                        i need to unblock facebook.com from iblock list.

                        i vi to usr/local/www/pakages/iblocklist/list/bt_level2.gz

                        del favebook inc: <ip address="">save / update

                        but squid still show block.

                        please guide.

                        many thanks</ip>

                        Why not just create a whitelist with all Facebook IP's.

                        hi tommy , how to create the white list ? please help many thanks.
                        example .

                        1 Reply Last reply Reply Quote 0
                        • T
                          tommyboy180
                          last edited by

                          It's the same format as the blacklist.```
                          DESCRIPTION:xxx.xxx.xxx.xxx-xxx.xxx.xxx.xxx

                          Example:```
                          Facebook:66.220.144.0-66.220.159.255 
                          

                          Store the whiltelist as a .txt on a webserver or the pfsense box and add it.

                          -Tom Schaefer
                          SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

                          Please support pfBlocker | File Browser | Strikeback

                          1 Reply Last reply Reply Quote 0
                          • S
                            slagr
                            last edited by

                            I have read all thread regarding to ipblocklist package, but didn't find the solution for the issue appeared some time here.

                            Have 2 pfsense boxes 2.0 and 1.2.3. Installed on both ipblocklist package. On 1.2.3 it works just fine, on 2.0 I got this error:

                            Current Status = NOT running
                            /tmp/rules.debug:31: Rules must be in order: options, normalization, queueing, translation, filtering
                            You are blocking 0 Networks/IPs

                            I don't know how to get that fixed, as I'm not a bsd expert. I deinstalled the package, rebooted, installed it back - got the same result.
                            Any advise to right direction of getting it working to pfsense 2.0 ?

                            Thanks.

                            1 Reply Last reply Reply Quote 0
                            • T
                              tommyboy180
                              last edited by

                              @slagr:

                              I have read all thread regarding to ipblocklis package, but didn't find the solution for the issue appeared some time here.

                              Have 2 pfsense boxes 2.0 and 1.2.3. Installed on both ipblocklist package. On 1.2.3 it works just fine, on 2.0 I got this error:

                              Current Status = NOT running
                              /tmp/rules.debug:31: Rules must be in order: options, normalization, queueing, translation, filtering
                              You are blocking 0 Networks/IPs

                              I don't know how to get that fixed, as I'm not a bsd expert. I deinstalled the package, rebooted, installed it back - got the same result.
                              Any advise to right direction of getting it working to pfsense 2.0 ?

                              Thanks.

                              Try rebooting. If that doesn't work then list your installed packages.

                              -Tom Schaefer
                              SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

                              Please support pfBlocker | File Browser | Strikeback

                              1 Reply Last reply Reply Quote 0
                              • S
                                slagr
                                last edited by

                                @tommyboy180:

                                Try rebooting. If that doesn't work then list your installed packages.

                                Thanks Tom,

                                I tried to reboot as I stated in my post. Removed, rebooted, installed back - the same results. Did a few times.

                                Here is my installed packages list (a lot of them are not relevant to the problem I think):

                                GeoIP-1.4.8_1                                                                                                                                                
                                .. list of system packages was cut …
                                xproto-7.0.22

                                1 Reply Last reply Reply Quote 0
                                • T
                                  tommyboy180
                                  last edited by

                                  Sorry I meant to just list your installed pfsense packages.

                                  -Tom Schaefer
                                  SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

                                  Please support pfBlocker | File Browser | Strikeback

                                  1 Reply Last reply Reply Quote 0
                                  • S
                                    slagr
                                    last edited by

                                    @tommyboy180:

                                    Sorry I meant to just list your installed pfsense packages.

                                    Bandwithd, Cron, IP-Blocklist, snort, RRD Summary.

                                    1 Reply Last reply Reply Quote 0
                                    • S
                                      slagr
                                      last edited by

                                      @slagr:

                                      @tommyboy180:

                                      Sorry I meant to just list your installed pfsense packages.

                                      Bandwithd, Cron, IP-Blocklist, snort, RRD Summary.

                                      Anyone can advise of what's wrong with that setup ?  We run pfsense 2.0. Reboot didn't help. Thanks.

                                      1 Reply Last reply Reply Quote 0
                                      • T
                                        tommyboy180
                                        last edited by

                                        Sorry. I have plans to take a look at it. My work is undergoing an inspection that takes weeks so my priorities have temporarily shifted during this time. Hopefully I can take a look at it soon.

                                        -Tom Schaefer
                                        SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

                                        Please support pfBlocker | File Browser | Strikeback

                                        1 Reply Last reply Reply Quote 0
                                        • marcellocM
                                          marcelloc
                                          last edited by

                                          @firbc:

                                          Hi,

                                          is there any why to allow connection to blocked IP's on port 80? And if there is any way to manualy add my own IP's to whitelist? Let says that I like to unlock only one specific IP which is in blocklist.

                                          This feature is implemented in pfBlocker package.

                                          You can assign lists to populate an alias and then create your own rules if you want.

                                          Treinamentos de Elite: http://sys-squad.com

                                          Help a community developer! ;D

                                          1 Reply Last reply Reply Quote 0
                                          • marcellocM
                                            marcelloc
                                            last edited by

                                            @slagr:

                                            I have read all thread regarding to ipblocklist package, but didn't find the solution for the issue appeared some time here.

                                            Have 2 pfsense boxes 2.0 and 1.2.3. Installed on both ipblocklist package. On 1.2.3 it works just fine, on 2.0 I got this error:

                                            Current Status = NOT running
                                            /tmp/rules.debug:31: Rules must be in order: options, normalization, queueing, translation, filtering
                                            You are blocking 0 Networks/IPs

                                            I don't know how to get that fixed, as I'm not a bsd expert. I deinstalled the package, rebooted, installed it back - got the same result.
                                            Any advise to right direction of getting it working to pfsense 2.0 ?

                                            Thanks.

                                            Uninstall ipblocklist on 2.0 and try pfBlocker package.

                                            Treinamentos de Elite: http://sys-squad.com

                                            Help a community developer! ;D

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.