Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How can I use "bogons" as an alias?

    Firewalling
    6
    10
    2.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      ConfusedUser
      last edited by

      Hello,

      I'm trying to set up a rule which utilizes the contents of the "bogons" table. In the rule I used "Single host or alias" and in the "Address" line below I put in "bogons".

      When I want to save I get the following message:
      The following input errors were detected: bogons is not a valid destination IP address or alias.

      Is there a workaround for this? In pf it seems to be a normal table so it should work exactly the same way as a self-created alias but somehow I can't add it to my rules.

      1 Reply Last reply Reply Quote 0
      • D
        doktornotor Banned
        last edited by

        No. Create your own.

        https://files.pfsense.org/lists/fullbogons-ipv4.txt
        https://files.pfsense.org/lists/fullbogons-ipv6.txt

        Certainly NOT recommended to use as-is anywhere on LAN interfaces, at least while things like all the RFC1918, 0.0.0.0/0 or 8000::/1 are there.

        1 Reply Last reply Reply Quote 0
        • C
          ConfusedUser
          last edited by

          Thank you!
          Since a modified file (without private addresses) is sitting in /etc/bogons is there a way to use the contents of this file in an alias?

          1 Reply Last reply Reply Quote 0
          • KOMK
            KOM
            last edited by

            Look at URL table aliases.

            1 Reply Last reply Reply Quote 0
            • C
              ConfusedUser
              last edited by

              @KOM:

              Look at URL table aliases.

              Thank you, I know the URL table aliases and I frequently use them.
              But… How can I access the local file in the /etc folder?

              1 Reply Last reply Reply Quote 0
              • D
                doktornotor Banned
                last edited by

                It works in pfBlockerNG. Other than that, if file:// does not work, then kindly use the URLs provided, instead of local files.

                1 Reply Last reply Reply Quote 0
                • BBcan177B
                  BBcan177 Moderator
                  last edited by

                  Here are the Bogon lists from the Original Source - Team Cymru

                  http://www.team-cymru.org/Services/Bogons/fullbogons-ipv4.txt

                  http://www.team-cymru.org/Services/Bogons/fullbogons-ipv6.txt

                  "Experience is something you don't get until just after you need it."

                  Website: http://pfBlockerNG.com
                  Twitter: @BBcan177  #pfBlockerNG
                  Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                  1 Reply Last reply Reply Quote 0
                  • N
                    NOYB
                    last edited by

                    Great.  Download them twice and keep two copies.  Plus if I'm not mistake the download copy will need to be modified if private networks are not acceptable to block on the interface it's used on.

                    Don't get the inclusion of private space in bogons list.  Private space is pretty well defined and static.  It shouldn't be in a dynamic bogons list.

                    1 Reply Last reply Reply Quote 0
                    • P
                      phil.davis
                      last edited by

                      The name "bogons" is already banned as an ordinary alias name. So there will be no installs that have a user-created alias called "bogons".
                      Thus there should be no problem in principle to make "bogons" a pseudo-alias that is not in the user-created alias list, but does appear in the alias names matching list when making rules… that can use an alias.
                      Then the back-end code just has to know about "pseudo-aliases" like that and make the rules concerned refer to the "bogons" table that is already made.

                      Same logic also applies to IPv6 bogons, if anyone cares.

                      I wonder how hard that would be to code?...

                      As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
                      If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

                      1 Reply Last reply Reply Quote 0
                      • N
                        NOYB
                        last edited by

                        @phil.davis:

                        I wonder how hard that would be to code?…

                        Go for it.  Though keep in mind that the bogons list as-is contains the local identification networks (0.0.0.0/8) which will impact DHCP if the list is used to block LAN In bound based on source.  Though that would seem sort of silly to need to block bogons sources on your LAN.

                        I've made a patch that adds an option to alias types url and urltable to exclude the private space ( IPv4: 192.168.0.0/16, 172.16.0.0/12, 10.0.0.0/8 ) ( IPv6: fc00::/7 ) and/or local identification space ( IPv4: 0.0.0.0/8 ) (0.0.0.0 used for DHCP discover/request source).

                        ![Firewall Aliases Edit.png](/public/imported_attachments/1/Firewall Aliases Edit.png)
                        ![Firewall Aliases Edit.png_thumb](/public/imported_attachments/1/Firewall Aliases Edit.png_thumb)

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.