Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Using pfBlockerNG Alias as source for NAT rule

    NAT
    3
    6
    1.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      bradyrf
      last edited by

      I am trying to use pfblockerng to create an alias of the US IP space so I can use that as a source in my NAT rule.
      I have created an alias match under GEOIP North America as well as created an alias under IPV4 pointing at the source /usr/local/share/GeoIP/cc/US_v4.txt. When I go into the NAT rule the aliases I have created do not show up.

      Am I missing something, maybe misunderstanding the pfblockerng / nat connection or is there a better way to accomplish this?

      Thanks in advance.

      1 Reply Last reply Reply Quote 1
      • NogBadTheBadN
        NogBadTheBad
        last edited by

        Here is how I allow the access to my SFTP server using GEOIP:-

        NB I use any on the NAT rule so I can quickly change the firewall rule if needed.

        Screenshot 2019-03-18 at 18.54.41.png

        Screenshot 2019-03-18 at 18.55.13.png

        Screenshot 2019-03-18 at 18.55.42.png

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        1 Reply Last reply Reply Quote 2
        • B
          bradyrf
          last edited by

          Thanks much for the help my friend. I got it working.
          Its weird about an hour after i was working on it the alias's popped up as an available alias in the NAT source alias.

          Always appreciate your time. Im sure this will help many folks.
          Have a great day.
          B

          GrimsonG NogBadTheBadN 2 Replies Last reply Reply Quote 0
          • GrimsonG
            Grimson Banned @bradyrf
            last edited by

            @bradyrf said in Using pfBlockerNG Alias as source for NAT rule:

            Its weird about an hour after i was working on it the alias's popped up as an available alias in the NAT source alias.

            RTFM:
            pfB-rtfm.jpg

            1 Reply Last reply Reply Quote 0
            • NogBadTheBadN
              NogBadTheBad @bradyrf
              last edited by NogBadTheBad

              @bradyrf

              Don't create the alias using Firewall -> pfBlockerNG -> IP -> GeoIP as it will tie up the North America rule.

              Better to use Firewall -> pfBlockerNG -> IP -> IPv4 & IPv6 as you can name the alias whatever you want.

              You can force an update of the aliases via Firewall -> pfBlockerNG -> Update

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              1 Reply Last reply Reply Quote 0
              • B
                bradyrf
                last edited by

                Thank you kind sir.
                I appreciate the advice.
                B

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.