Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How do you block CHINESE hacks/intrusions/scans ?

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 3 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      j8TfzTcRopF
      last edited by

      Does pfSense automatically block Chinese hacking / intrusion? Or, is there a script or method that can be easily employed by a newbee? Thanks for your guidance.

      1 Reply Last reply Reply Quote 0
      • E Offline
        ericab
        last edited by

        you can block CIDR regions with an addon package called "Country Block"

        navigate to SYSTEM –> PACKAGES.

        1 Reply Last reply Reply Quote 0
        • J Offline
          j8TfzTcRopF
          last edited by

          @ericab:

          you can block CIDR regions with an addon package called "Country Block"

          navigate to SYSTEM –> PACKAGES.

          ericab, Thanks for your guidance. Could I simply allow only US, CA, AUS, NZ only and block rest of the world in easy way? Thanks again.

          1 Reply Last reply Reply Quote 0
          • C Offline
            Cino
            last edited by

            by default everything is blocked coming into you WAN interface. If you only want US, CA, AUS, NZ ranges, use Country Block. It has an option to Select every list, then you uncheck US, CA, AUS, NZ… They will block all the country ranges before the rules you add.

            You are looking at a lot of Aliases and inbound rules the other way if you want want to have lets say a web server behind the fw.

            1 Reply Last reply Reply Quote 0
            • J Offline
              j8TfzTcRopF
              last edited by

              @Cino:

              by default everything is blocked coming into you WAN interface. If you only want US, CA, AUS, NZ ranges, use Country Block. It has an option to Select every list, then you uncheck US, CA, AUS, NZ… They will block all the country ranges before the rules you add.

              You are looking at a lot of Aliases and inbound rules the other way if you want want to have lets say a web server behind the fw.

              Thank you all for guidance. This can be closed issue.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.