Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Disable action does not work ?

    Scheduled Pinned Locked Moved pfBlockerNG
    33 Posts 3 Posters 3.9k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • GertjanG Offline
      Gertjan @chudak
      last edited by

      My turn :

      I went to GeoIP
      I enabled a feed

      Like this :

      9fc101f6-6d8e-440a-b9f3-3910390f6f9d-image.png

      Saved
      Ran force reload

      I had these 4 new firewall rules on my Floating page :

      0433eb32-743d-4821-866a-2addce489531-image.png

      I removed the GEOP feed, saved, ran force reload.

      The four firewall rules (see above) on the floating page were gone.

      Btw : Normally, I do not use the GEOIP feeds, as I'm not hosting any web or mail server / I'm not letting anything in (well, I do, but these are limited using known source IP addresses).

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      chudakC 1 Reply Last reply Reply Quote 0
      • chudakC Offline
        chudak @Gertjan
        last edited by

        @gertjan

        I removed the GEOP feed, saved, ran force reload.

        Ho did you "remove" it? I see only option to "disable" for GeoIP (unlike for IPv4 they can be deleted)

        GertjanG 1 Reply Last reply Reply Quote 0
        • GertjanG Offline
          Gertjan @chudak
          last edited by

          ff4cd3e0-b291-4b87-933e-bc88c102f464-image.png

          Disabled is like removed (for me).

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          chudakC 1 Reply Last reply Reply Quote 0
          • chudakC Offline
            chudak @Gertjan
            last edited by

            @gertjan said in Disable action does not work ?:

            Disabled is like removed (for me).

            Got it! That's helpful.
            Just to confirm - after you disabled GeoIP feed the corresponding FW rules were removed as well ?

            This is what I expect, but don't see happening!

            GertjanG 1 Reply Last reply Reply Quote 0
            • GertjanG Offline
              Gertjan @chudak
              last edited by Gertjan

              @chudak said in Disable action does not work ?:

              Just to confirm - after you disabled GeoIP feed the corresponding FW rules were removed as well ?

              I confirm.

              Did you hit the save button(see image above) ?

              edit : this button :

              20d6e91d-c70e-4320-b028-8a77ca0d5aab-image.png

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              chudakC 2 Replies Last reply Reply Quote 0
              • chudakC Offline
                chudak @Gertjan
                last edited by chudak

                @gertjan

                That reminds me

                My Cousin Vinny

                on 0:17

                "I am positive"

                :)
                @BBcan177 FYI

                1 Reply Last reply Reply Quote 0
                • chudakC Offline
                  chudak @Gertjan
                  last edited by

                  @gertjan

                  Confirmed the same problem on 2.5.1-RELEASE/pfBlockerNG-devel 3.0.0_16

                  Disable GeoIP Europe + update/reload -> does not remove pfB_NAmerica_v4 FW rule !

                  RonpfSR 1 Reply Last reply Reply Quote 0
                  • RonpfSR Offline
                    RonpfS @chudak
                    last edited by RonpfS

                    @chudak Maybe post pfblockerng.log, we can't see much without that.

                    2.4.5-RELEASE-p1 (amd64)
                    Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                    Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                    chudakC 1 Reply Last reply Reply Quote 0
                    • chudakC Offline
                      chudak @RonpfS
                      last edited by

                      @ronpfs said in Disable action does not work ?:

                      @chudak Maybe post pfblockerng.log, we can see much without that.

                      https://pastebin.ubuntu.com/p/SHnvfgm2xN/

                      Please take a look !
                      Thx!

                      RonpfSR 1 Reply Last reply Reply Quote 0
                      • RonpfSR Offline
                        RonpfS @chudak
                        last edited by

                        @chudak Did you ran a Force Update or a Force Reload All after disabling the GeoIP group?

                        2.4.5-RELEASE-p1 (amd64)
                        Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                        Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                        chudakC 1 Reply Last reply Reply Quote 0
                        • chudakC Offline
                          chudak @RonpfS
                          last edited by

                          @ronpfs said in Disable action does not work ?:

                          @chudak Did you ran a Force Update or a Force Reload All after disabling the GeoIP group?

                          Yes

                          RonpfSR 1 Reply Last reply Reply Quote 0
                          • RonpfSR Offline
                            RonpfS @chudak
                            last edited by RonpfS

                            @chudak So you ran both ? timestamp of the Force Update ?

                            2.4.5-RELEASE-p1 (amd64)
                            Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                            Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                            chudakC 1 Reply Last reply Reply Quote 0
                            • chudakC Offline
                              chudak @RonpfS
                              last edited by

                              @ronpfs

                              You know I need to play with a bit and produce a good log. Will update later.

                              Thx for looking !

                              RonpfSR 1 Reply Last reply Reply Quote 0
                              • RonpfSR Offline
                                RonpfS @chudak
                                last edited by

                                @chudak said in Disable action does not work ?:

                                You know I need to play with a bit and produce a good log. Will update later.
                                Thx for looking !

                                Start by enable only on GeoIP group check if things change with a Force Update, then run a Force Reload IP or ALL.

                                Disable that GeoIP group, Update, Reload IP.

                                2.4.5-RELEASE-p1 (amd64)
                                Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                chudakC 1 Reply Last reply Reply Quote 0
                                • chudakC Offline
                                  chudak @RonpfS
                                  last edited by

                                  @ronpfs

                                  It looks like it was my bad and disable in fact does work.

                                  My apologies !

                                  Can I ask you kinda related-unrelated question.

                                  When I look at my Whitelist I see:

                                  54b748ac-560a-4789-bede-dbe7cfcabb7b-image.png

                                  and corresponding FW rule:

                                  2418589b-a757-472d-a62d-59e88fac0b45-image.png

                                  Do White_List_hosts and White_List_ports have to be used? Can they be removed ?

                                  RonpfSR 1 Reply Last reply Reply Quote 0
                                  • RonpfSR Offline
                                    RonpfS @chudak
                                    last edited by

                                    @chudak said in Disable action does not work ?:

                                    Do White_List_hosts and White_List_ports have to be used? Can they be removed ?

                                    When was this settings configured ? Look at both aliases to see if they are still relevant.

                                    2.4.5-RELEASE-p1 (amd64)
                                    Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                    Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                    chudakC 1 Reply Last reply Reply Quote 0
                                    • chudakC Offline
                                      chudak @RonpfS
                                      last edited by

                                      @ronpfs said in Disable action does not work ?:

                                      When was this settings configured ? Look at both aliases to see if they are still relevant.

                                      The problem is I don;t actually remember when and how :)

                                      So I'd say no need for them. But when I try to disable "Custom DST Port" and "Custom Destination" and Save I get:

                                      56605d6b-1ffd-486d-b7d5-b7335ba7d06c-image.png

                                      ???

                                      What do you see there ?

                                      RonpfSR 1 Reply Last reply Reply Quote 0
                                      • RonpfSR Offline
                                        RonpfS @chudak
                                        last edited by

                                        @chudak Strange. You are sure you untick both boxes, save, etc ?

                                        2.4.5-RELEASE-p1 (amd64)
                                        Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                        Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                        chudakC 1 Reply Last reply Reply Quote 0
                                        • chudakC Offline
                                          chudak @RonpfS
                                          last edited by

                                          @ronpfs said in Disable action does not work ?:

                                          @chudak Strange. You are sure you untick both boxes, save, etc ?

                                          Yup, unchecked both and on save that error.

                                          Do you have aliases in tee WL?

                                          RonpfSR 1 Reply Last reply Reply Quote 0
                                          • RonpfSR Offline
                                            RonpfS @chudak
                                            last edited by RonpfS

                                            @chudak And you did that in the Whitelist group ? not with the FW rules.
                                            I do have a Whitelist rules with both boxes unticked, maybe empty the field also.

                                            2.4.5-RELEASE-p1 (amd64)
                                            Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                            Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                            chudakC 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.