Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Configuration for Pfsense

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    8 Posts 2 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C Offline
      cyberalone
      last edited by

      Hello,

      I am very new so if I wrote my message to wrong place, I apologize. I am looking for a new load-balancer system for our website. The new load balancer needs to filter the traffic. We need some help for that. Can you help me? Is there any video or something that I can check ?

      Here is the settings we are looking for

      • if an IP has more than 200 open connections to the site, or more than 100 per second, we place it in  'slow traffic' queue (1mbps allocated) for 10 minutes
      • if an IP from the 'slow traffic' queue has more than 500 connections to the site, or more than 250 per second, we block it for 1 hour"

      The reason I am looking for this is we got too many spider bots crawling (comment bots etc.) our website. We need something to block it.

      Thanks.

      1 Reply Last reply Reply Quote 0
      • C Offline
        cyberalone
        last edited by

        I can pay for it if somebody can help to sort this out.

        1 Reply Last reply Reply Quote 0
        • B Offline
          brandur
          last edited by

          I'm no expert in this field, but the first thing that comes to mind, is HAProxy and you can install it as a plugin.

          And becouse you have quite specific requirements, I would suggest Commercial Support: http://www.haproxy.org/#supp

          Good luck  :D

          (let us know if it solves you're issue, so other people know that this is a possibility)

          SG-4860 w/128GB SSD & 8GB RAM

          1 Reply Last reply Reply Quote 0
          • C Offline
            cyberalone
            last edited by

            I used this configurations on a datancenter. I asked them to give me the configs but they didn't want to sell it so it is possible. The key is I need the load balancer to detect if an ip address exceed the limit we give. If yes block it for a certain time. I want to see that ip on a list. That's all.

            1 Reply Last reply Reply Quote 0
            • C Offline
              cyberalone
              last edited by

              At least I need something if an IP has more than 200 open connections to the site, or more than 100 per second, we block it for 1 hour. I contacted to HAproxy and waiting for respond. Do you think pfsense itself can't do this with some configs ?

              1 Reply Last reply Reply Quote 0
              • B Offline
                brandur
                last edited by

                I don't see how pfSense would be able to handle your scenario as is, without quite a bit of custom coding.
                I'm convinced that using a real proxy like HAProxy is the right way to go. It's supported on basically all platforms/architectures and it's heavily used by small and fortune 500 companies a like.

                It would surprise me, I'f paid HAProxy support can't help you with your desired setup(and remember that you can basically reuse the entire config in future setups/hardware and etc. or maybe just share it here, because I would like to see how HAProxy would actually handle such a setup  ;D )

                SG-4860 w/128GB SSD & 8GB RAM

                1 Reply Last reply Reply Quote 0
                • C Offline
                  cyberalone
                  last edited by

                  My friend managed to do

                  • if an IP has more than 200 open connections to the site, or more within 100 seconds, we block it.

                  but he can't find the blacklist and timeout. He just used Pfsense rules there are some advance options on pfsense so even you can do it..

                  If the ip is blocked where ip addresses are listed ? and if an ip blocked how do we put a timeout ?

                  1 Reply Last reply Reply Quote 0
                  • C Offline
                    cyberalone
                    last edited by

                    Finally we managed to sort things out. So conclusion it is possible to do this kind of configuration without paying hundreds of dollars to Haproxy. We are testing it at the moment to see if there is any problems.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.