Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    (SOLVED) How to change pfBlockerNG rules order

    Scheduled Pinned Locked Moved pfBlockerNG
    6 Posts 3 Posters 2.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • SipriusPTS
      SipriusPT
      last edited by SipriusPT

      Hello everyone,

      I've setup pfBlockerNG to use GeoIP in our WAN interface uplink, to protect other ports that we have openned to outside .

      The thing is that we have several VPN's running, and I would like to avoid lockdowns (E.g. being using an IP in one of those blacklisted countries) of those VPN ports, so I have changed the order of those rules in that interface, but everytime it updates from Maxmind, it changes the order of those rules, moving all of pfBlockerNG rules to the top.

      Any of you knows (without using floating rules), how to lock those rules from changing their order?

      Thanks in advance!

      1xSG-4860-1U
      1xSG-3100
      2xpfSense Virtual Machines

      1 Reply Last reply Reply Quote 0
      • JeGrJ
        JeGr LAYER 8 Moderator
        last edited by

        If you have a bit more complex ruleset, I always advise to use pfBlocker as "supplier" for the Alias only. Just switch your IP lists from "Deny Inbound" (or any other setting) to "Alias Deny" (or Alias Native). That way pfBlocker supplies you with the IP list and the Alias as is now used in its rules like "pfB_PRI1_v4" but you can use it in your own rules like any other alias you might want. That way you can use blocklists in any rule or order you want without having to backcheck if the order has been reset/rearranged by pfBlocker.

        Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

        If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

        SipriusPTS 1 Reply Last reply Reply Quote 2
        • SipriusPTS
          SipriusPT @JeGr
          last edited by

          @JeGr Thanks a lot! Worked like a charm.

          1xSG-4860-1U
          1xSG-3100
          2xpfSense Virtual Machines

          1 Reply Last reply Reply Quote 0
          • JeGrJ
            JeGr LAYER 8 Moderator
            last edited by

            @SipriusPT said in (SOLVED) How to change pfBlockerNG rules order:

            @JeGr Thanks a lot! Worked like a charm.

            Glad it works, happy to assist.

            Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

            If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

            1 Reply Last reply Reply Quote 1
            • P
              psp
              last edited by psp

              Just one note: don't use the prefix pfB_ as first string on "Description" for your own rules with pfBlockerNG aliases. This will ensure that your rules will not be handled by pfBlockerNG during updates.

              SipriusPTS 1 Reply Last reply Reply Quote 1
              • SipriusPTS
                SipriusPT @psp
                last edited by SipriusPT

                @psp said in (SOLVED) How to change pfBlockerNG rules order:

                Just one note: don't use the prefix pfB_ as first string on "Description" for your own rules with pfBlockerNG aliases. This will ensure that your rules will not be handled by pfBlockerNG during updates.

                Thanks you for let me know.

                When @JeGr mentioned the 'alias Denys' option, I notice that there was a description on GeoIP explaining all available options, and notice that part.

                1xSG-4860-1U
                1xSG-3100
                2xpfSense Virtual Machines

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.