Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Prevent countries access to specific hosted site

    Scheduled Pinned Locked Moved pfBlockerNG
    8 Posts 4 Posters 987 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      dbennett
      last edited by

      Greetings,

      My the company I work for host websites.  pfBlocker, for the most part allows access to ALL of our hosted websites.  We have a client that wants specific countries from accessing their website.  How do I allow both rule sets to function properly?

      Thanks ahead of time.

      1 Reply Last reply Reply Quote 0
      • D
        dbennett
        last edited by

        Is it possible to generate rules that focus on dynamic 'aliases' that focus on individual countries?

        1 Reply Last reply Reply Quote 0
        • N
          n3by
          last edited by

          have a look in:
          /usr/local/share/GeoIP/cc/
          and you will find the GeoIP country codes pfBlockerNG download from MaxMind.

          create alias only with country you need and use it as you want in a firewall rule allow/deny.
          for ex Poland:
          /usr/local/share/GeoIP/cc/PL_v4.txt
          /usr/local/share/GeoIP/cc/PL_v6.txt

          1 Reply Last reply Reply Quote 0
          • D
            dbennett
            last edited by

            OUTSTANDING!!  Thank you VERY much!!

            Actually question along the lines of using Alias Deny and De-Duplication.  When I created an Alias yesterday and created a rule, the alias under the rule only showed 1.1.1.1.  Is that normal?

            1 Reply Last reply Reply Quote 0
            • N
              n3by
              last edited by

              If you move the mouse on alias name in the rule ( interface ) it will show all IPs for that alias.
              If you have only one address 1.1.1.1 have a look at what's inside each file / link for that alias and try to figure if something is missing or not and why ( bad link/file, can't download link/file ??

              1 Reply Last reply Reply Quote 0
              • BBcan177B
                BBcan177 Moderator
                last edited by

                @dbennett:

                OUTSTANDING!!  Thank you VERY much!!

                Actually question along the lines of using Alias Deny and De-Duplication.  When I created an Alias yesterday and created a rule, the alias under the rule only showed 1.1.1.1.  Is that normal?

                Click on the blue infoblock icons in the IPv4 tab. It will detail how to achieve this…. When creating multiple GeoIP aliases with duplicated ISO, its best to use "Alias Native", so that deduplication does not take effect...

                "Experience is something you don't get until just after you need it."

                Website: http://pfBlockerNG.com
                Twitter: @BBcan177  #pfBlockerNG
                Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                1 Reply Last reply Reply Quote 0
                • D
                  dbennett
                  last edited by

                  Thanks to everyone for replying to my post.

                  I've located and added each of the country lists into a single alias and will be checking our webstats to see if the rule works.

                  Question:  What is the _rep_ipv4 lists for?

                  Thanks again for your input

                  1 Reply Last reply Reply Quote 0
                  • RonpfSR
                    RonpfS
                    last edited by

                    There is an Red url in the GeoIP tabs :

                    @ :

                    GeoIP data by MaxMind Inc. - GeoLite2
                    Click here for IMPORTANT info –> What new in GeoIP2

                    Country, Registered Country, and Represented Country

                    We now distinguish between several types of country data. The country is the country where the IP address is located. The registered_country is the country in which the IP is registered. These two may differ in some cases.

                    Finally, we also include a represented_country key for some records. This is used when the IP address belongs to something like a military base. The represented_country is the country that the base represents. This can be useful for managing content licensing, among other uses.

                    2.4.5-RELEASE-p1 (amd64)
                    Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                    Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.