Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfBlocker

    Scheduled Pinned Locked Moved pfSense Packages
    896 Posts 143 Posters 1.4m Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • marcellocM
      marcelloc
      last edited by

      @taryezveb:

      Can you please explain. Does this mean if one is using Squid and pfBlocker. A floating rule for Squid is need in order for Squid to use the lists used in pfBlocker?

      Yes, read this topic.

      http://forum.pfsense.org/index.php/topic,44479.0.html

      Treinamentos de Elite: http://sys-squad.com

      Help a community developer! ;D

      1 Reply Last reply Reply Quote 0
      • T
        taryezveb
        last edited by

        @marcelloc:

        Yes, read this topic.

        http://forum.pfsense.org/index.php/topic,44479.0.html

        Thanks, just read it but do not fully understand. Maybe once I add the floating rule(s), I will.

        1 Reply Last reply Reply Quote 0
        • marcellocM
          marcelloc
          last edited by

          pfSense is a statefull firewall, so all rules are applied where connections begin.

          Squid does not use LAN or WAN rules but localhost rules as it starts communications to web servers locally.

          The only way to apply rules on localhost, is using floating rules.

          This way squid wil not be able to connect to any China web site if firewall is blocking access to China's ips.

          Treinamentos de Elite: http://sys-squad.com

          Help a community developer! ;D

          1 Reply Last reply Reply Quote 0
          • T
            taryezveb
            last edited by

            Thanks for that explanation, I understand it better :) But I'm still not sure how the floating rule(s) show be properly created.

            Like this?:

            Action: Reject
            Interface: WAN
            Direction: any
            Protocol: any
            Source: any
            Destination: pfBlockerAliasname
            Description: pfBlockerAliasname-Squid

            Sorry if these are obvious questions.

            1 Reply Last reply Reply Quote 0
            • marcellocM
              marcelloc
              last edited by

              Change interface to any and direction to out.

              Treinamentos de Elite: http://sys-squad.com

              Help a community developer! ;D

              1 Reply Last reply Reply Quote 0
              • T
                taryezveb
                last edited by

                Ok, Thanks a lot for your help! :)

                1 Reply Last reply Reply Quote 0
                • F
                  fsavoir
                  last edited by

                  Hi,
                  I'm new to this list…. But great work on pfSense and all packages.
                  On my french install system pfBlocker never and any rules to firewall any tips? to track this down?
                  pfSense 2.0.1 and pfBlock 1.0.1

                  Thanks.

                  Fred

                  1 Reply Last reply Reply Quote 0
                  • marcellocM
                    marcelloc
                    last edited by

                    You need at least one firewall rule on interface you want to configure pfBlocker.

                    Treinamentos de Elite: http://sys-squad.com

                    Help a community developer! ;D

                    1 Reply Last reply Reply Quote 0
                    • F
                      fsavoir
                      last edited by

                      Hi,

                      Thanks for your reply… I did have the default rules...... Isn't enough ?
                      "

                      • RFC 1918 networks * * * * * Block private networks
                      • Reserved/not assigned by IANA * * * * * * Block bogon networks
                        "

                      Thanks.

                      Fred

                      1 Reply Last reply Reply Quote 0
                      • marcellocM
                        marcelloc
                        last edited by

                        Default rules are not saved on interface rules config XML.

                        Create a rule and then apply pfBlocker config.

                        Treinamentos de Elite: http://sys-squad.com

                        Help a community developer! ;D

                        1 Reply Last reply Reply Quote 0
                        • F
                          fsavoir
                          last edited by

                          Thanks again for your reply,

                          Could we be more specific? I need to add a rule in Firewall -> Rules then Lan or Wan ?

                          Such a dummy rules?

                          Thanks again.

                          Fred

                          1 Reply Last reply Reply Quote 0
                          • marcellocM
                            marcelloc
                            last edited by

                            Lan has a default rule, you will see pfBlocker rules there if you apply deny outbound action on your lists.

                            If you have no wan rules, you do not need deny inbound action on pfblocker lists as you are already blocking everything.

                            Treinamentos de Elite: http://sys-squad.com

                            Help a community developer! ;D

                            1 Reply Last reply Reply Quote 0
                            • F
                              fsavoir
                              last edited by

                              ok may be I don't explain well enough… But pfblocker never add any rules in any tabs (lan, wan, floating) of the firewall.
                              So even If I had one in floating ... then select turn on pfblocker and add top country spammers... always a red down arrow :( and no rules anywear.

                              So I think I'm missing something here :(

                              I even added a rules to myself in the Lan... Still Red arrow.

                              Again thanks.

                              Fred

                              1 Reply Last reply Reply Quote 0
                              • F
                                fsavoir
                                last edited by

                                OK fixed…
                                I had to add by adding a floating rules to myself.... then all top spammers list.... Then active the pfblocker package.
                                then it works .... Thanks again for your great support and SUPER COOL package.
                                Cheers,

                                Fred

                                1 Reply Last reply Reply Quote 0
                                • F
                                  fsavoir
                                  last edited by

                                  Hi,

                                  I'm wondering if you know how to make pfBlocker XMLRPC with Denyhost site ?
                                  http://xmlrpc.denyhosts.net:9911

                                  Thanks.

                                  Fred

                                  1 Reply Last reply Reply Quote 0
                                  • F
                                    fsavoir
                                    last edited by

                                    What is list format that pfBlocker could handle ? Like  : P2P, DAT or CIDR ? in .gz, zip or txt ?

                                    Thanks one more for your support.

                                    Fred

                                    1 Reply Last reply Reply Quote 0
                                    • marcellocM
                                      marcelloc
                                      last edited by

                                      address list could be in

                                      • p2p

                                      • cidr (recommended)

                                      • ipaddress

                                      one per line

                                      The web site that host this list could send list in txt(plain) format or compressed with gz

                                      Treinamentos de Elite: http://sys-squad.com

                                      Help a community developer! ;D

                                      1 Reply Last reply Reply Quote 0
                                      • F
                                        fsavoir
                                        last edited by

                                        Thanks :)

                                        Any info about : pfBlocker XMLRPC ?

                                        Cheers,

                                        F.

                                        1 Reply Last reply Reply Quote 0
                                        • marcellocM
                                          marcelloc
                                          last edited by

                                          @fsavoir:

                                          Thanks :)

                                          Any info about : pfBlocker XMLRPC ?

                                          Cheers,

                                          F.

                                          No integration with http://xmlrpc.denyhosts.net:9911 for now.

                                          Treinamentos de Elite: http://sys-squad.com

                                          Help a community developer! ;D

                                          1 Reply Last reply Reply Quote 0
                                          • L
                                            LinuxTracker
                                            last edited by

                                            I'd like to offer up a copy of the Spam List I've been compiling for over a year.
                                            I began compiling it for use in IPBlocklist (used with Country IP Blocks). It's now optimized for pfBlocker.

                                            Here's the details/disclaimer:

                                            1. 505 CIDRs as of today.
                                            2. Based on spams received at the mail servers I care for.
                                            3. It's focused on US Spammers but includes CIDRs from some countries I couldn't block outright. Non-US CIDRs are noted.
                                              3a) A few countries I eventually gave up on and just country blocked outright (ie Poland, Peru); so there may be some inconsistency.
                                            4. I converted it to CIDR format 2 weeks ago. That took a long time (orig PG ranges were 1-254).
                                            5. For each spam IP, I carefully examined it's host to determine the appropriate range.
                                              5a) Criteria includes bot spams, dynIP ranges and scummy hosting companies.
                                              5b) For a single IP, it may take 15+ minutes of careful research before I can decide what range to block.
                                            6. I generally do 2-4 update sessions every month.
                                            7. Use At Your Own Risk.  I'd review it first for possible editing, if I were you.

                                            I've broken the list up into 3 because it became unwieldy.
                                            I've recently broken off corporate spam (ie: Linkedin, Constant Contact, exacttarget) into a fourth list. I prob still need to shift some IPs into it.

                                            I thought Pastebin (Private link - 1 Month expiration) would be the most transparent option for publishing this.

                                            SpamIPs_0-69  http://pastebin.com/MTds2fik
                                            SpamIPs_70-179 http://pastebin.com/w0ZDtMym
                                            SpamIPs_180-255 http://pastebin.com/QPi4PtMN
                                            CorporateSpam http://pastebin.com/95xvHnk9

                                            MODS: If this violates forum protocol, please delete the post and forgive me.
                                            If a mod wants the constantly updated live url (.gz format), please PM me.
                                            The update URL is under my personal domain so I can't otherwise distribute it. Sorry.

                                            Thanks.

                                            edit: added screencap - 8 Hours of spam hits - domain w/ ~10 email accounts.

                                            pfCustomSpamList = 3 SpamIP lists above.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.