Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Custom aliases using domain name

    Scheduled Pinned Locked Moved Off-Topic & Non-Support Discussion
    32 Posts 5 Posters 4.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NogBadTheBadN
      NogBadTheBad @Su30MKI
      last edited by

      @su30mki said in Custom aliases using domain name:

      @nogbadthebad Thank you for the wonderful representation. I am so happy for your effort. Can I assign host based blocking in the network with this method?

      Never used it but there's a bit at the bottom:-

      0_1542913706306_Screenshot 2018-11-22 at 19.07.04.png

      I still think you'd be better blocking by AS number.

      Andy

      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

      S 1 Reply Last reply Reply Quote 1
      • S
        Su30MKI
        last edited by

        This post is deleted!
        1 Reply Last reply Reply Quote 0
        • S
          Su30MKI @NogBadTheBad
          last edited by Su30MKI

          @nogbadthebad I understand that part. How to create an alias for blocking pfsense by pfblockerng? I am very new to pf blockerng. I also have paid blacklist service. Can I load that to pfblockerng?

          1 Reply Last reply Reply Quote 0
          • NogBadTheBadN
            NogBadTheBad
            last edited by NogBadTheBad

            • Instal lpfBlockerNG-devel

            • Run the setup wizard , define your inbound and outbound interface.

            • Create a rule Firewall -> pfBlockerNG -> IP -> IPv4 as per my screenshot but set it as deny outbound

            • Run update via Firewall -> pfBlockerNG -> Update, the firewall rules will automatically be created

            The rules will automatically be created on the inbound and outbound interfaces, give it a go, its quite easy.

            0_1542914881999_Screenshot 2018-11-22 at 19.25.49.png

            Re the paid block list you can, depending on the format, it basically creates tables that are used in firewall rules, check the tables out via Diagnostics -> Tables

            0_1542915086235_Screenshot 2018-11-22 at 19.31.13.png

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            S 1 Reply Last reply Reply Quote 1
            • S
              Su30MKI @NogBadTheBad
              last edited by

              @nogbadthebad Hello.. Thank you for your support. I am sorry for the delay in the reply. I was doing a whole new set up. I have multi wan failover setup done. So in PfblockerNG, The Inbound interface --> WAN1 & WAN2 and The outbound interface --> LAN. Is it the right method?

              NogBadTheBadN 1 Reply Last reply Reply Quote 0
              • NogBadTheBadN
                NogBadTheBad @Su30MKI
                last edited by

                @su30mki

                Yup sounds right.

                Andy

                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                S 1 Reply Last reply Reply Quote 1
                • S
                  Su30MKI @NogBadTheBad
                  last edited by

                  @nogbadthebad I am having multiple vlans created in pfsense. Then I think the outbound interface should be all the vlans.

                  NogBadTheBadN 1 Reply Last reply Reply Quote 0
                  • NogBadTheBadN
                    NogBadTheBad @Su30MKI
                    last edited by

                    @su30mki

                    Yes.

                    Andy

                    1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                    S 1 Reply Last reply Reply Quote 1
                    • S
                      Su30MKI @NogBadTheBad
                      last edited by Su30MKI

                      @nogbadthebad Hi, I tried doing it, But it is not blocking facebook. Please find the screenshots.1_1543414765834_IPv4-list-2.PNG 0_1543414765815_IPv4-list1.PNG

                      1 Reply Last reply Reply Quote 0
                      • NogBadTheBadN
                        NogBadTheBad
                        last edited by NogBadTheBad

                        It's deny outbound.

                        Get it working with ASN numbers they play with the social networking source after.

                        Andy

                        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                        1 Reply Last reply Reply Quote 0
                        • NogBadTheBadN
                          NogBadTheBad
                          last edited by NogBadTheBad

                          I've just tried it and its an issue with your block list as it doesn't contain valid IP addresses just 0.0.0.0 FQDN.

                          PfB_Test_v4 Table
                          IP Address
                          123.41.54.45
                          130.211.230.53
                          160.41.54.45
                          163.41.54.45
                          194.41.54.45

                          Rather than using IP try using the DBNS

                          0_1543416681468_Screenshot 2018-11-28 at 14.50.13.png

                          Andy

                          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                          1 Reply Last reply Reply Quote 1
                          • S
                            Su30MKI
                            last edited by

                            Can you please suggest any list?

                            NogBadTheBadN 1 Reply Last reply Reply Quote 0
                            • NogBadTheBadN
                              NogBadTheBad @Su30MKI
                              last edited by

                              @su30mki

                              Have you tried blocking facebook by ASN numbers or like I suggested try the using the list your using in the DBNSL section as per my screenshot.

                              Andy

                              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                              S 1 Reply Last reply Reply Quote 0
                              • S
                                Su30MKI @NogBadTheBad
                                last edited by

                                @nogbadthebad Thank you very much.. It is working. Saved my reputation.

                                NogBadTheBadN 1 Reply Last reply Reply Quote 0
                                • NogBadTheBadN
                                  NogBadTheBad @Su30MKI
                                  last edited by

                                  @su30mki said in Custom aliases using domain name:

                                  @nogbadthebad Thank you very much.. It is working. Saved my reputation.

                                  via IP and ASN number or DNSBL ?

                                  Andy

                                  1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                  S 1 Reply Last reply Reply Quote 1
                                  • S
                                    Su30MKI @NogBadTheBad
                                    last edited by

                                    @nogbadthebad Now how do I segregate different rules for different vlans?

                                    NogBadTheBadN 1 Reply Last reply Reply Quote 0
                                    • NogBadTheBadN
                                      NogBadTheBad @Su30MKI
                                      last edited by

                                      @su30mki

                                      Use alias permit, alias deny, alias match & alias native.

                                      That will just create an alias you can use in firewall rules.

                                      Andy

                                      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                      S 1 Reply Last reply Reply Quote 1
                                      • S
                                        Su30MKI @NogBadTheBad
                                        last edited by

                                        @nogbadthebad Can you please help me with a screenshot?

                                        1 Reply Last reply Reply Quote 0
                                        • NogBadTheBadN
                                          NogBadTheBad
                                          last edited by NogBadTheBad

                                          0_1543419206004_Screenshot 2018-11-28 at 15.32.37.png

                                          Only allow GB access to my SFTP server:-

                                          0_1543419347807_Screenshot 2018-11-28 at 15.33.03.png

                                          Andy

                                          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                          S 1 Reply Last reply Reply Quote 1
                                          • S
                                            Su30MKI @NogBadTheBad
                                            last edited by

                                            @nogbadthebad Thank you for your effort. But that is Geoip. Imagine I want to block facebook to one vlan and another vlan requires facebook access.. How do I do it? How can I do different rules for different vlan via DNSBL?

                                            A 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.