• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Is there anyway to whitelist?

pfBlockerNG
4
9
825
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    Smoothrunnings
    last edited by May 10, 2021, 6:45 PM

    Is there anyway to whitelist domains that are being blocked by pfBlockerNG?

    So I have all of China blocked but I have realized that my new Terramaster is made by a Chinese company. I don't really want to have to OPEN up China to my back door, so that's why I am asking to make sure if I can't avoid it great if not, well that I guess I am SOL.

    Thanks,

    N 1 Reply Last reply May 10, 2021, 7:33 PM Reply Quote 0
    • N
      NogBadTheBad @Smoothrunnings
      last edited by NogBadTheBad May 10, 2021, 7:40 PM May 10, 2021, 7:33 PM

      @smoothrunnings Are you blocking China outbound on your LAN interfaces, I'm guessing you are ?

      login-to-view

      You could create a alias using pfBlockerNG and the China alias and apply it to the WAN interface:-

      login-to-view

      login-to-view

      login-to-view

      Andy

      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

      S 1 Reply Last reply May 10, 2021, 7:51 PM Reply Quote 0
      • S
        Smoothrunnings @NogBadTheBad
        last edited by May 10, 2021, 7:51 PM

        @nogbadthebad No.

        Firewall/pfBlockerNG/IP/IPv4 - have IPv4 setup to deny Inbound.
        GeoIP Asia - deny inbound

        I want to block everything except for terra-mast.com which is a Chinese company that makes NAS units (similar to QNAP/Synology).

        Thanks,

        S N 2 Replies Last reply May 10, 2021, 8:12 PM Reply Quote 0
        • S
          SteveITS Galactic Empire @Smoothrunnings
          last edited by May 10, 2021, 8:12 PM

          @smoothrunnings If you change the Deny Inbound to Alias Native (and run an Update), it will create an alias that you can use in your own rules. Then do something like:

          allow from Terra Mast IPs
          block from Asia using the alias
          allow from other good IPs

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote 👍 helpful posts!

          1 Reply Last reply Reply Quote 1
          • N
            NogBadTheBad @Smoothrunnings
            last edited by NogBadTheBad May 10, 2021, 8:46 PM May 10, 2021, 8:46 PM

            @smoothrunnings said in Is there anyway to whitelist?:

            @nogbadthebad No.

            Firewall/pfBlockerNG/IP/IPv4 - have IPv4 setup to deny Inbound.
            GeoIP Asia - deny inbound

            I want to block everything except for terra-mast.com which is a Chinese company that makes NAS units (similar to QNAP/Synology).

            Thanks,

            Why the heck would you want them to have unsolicited inbound access to your NAS, you should just need NAS -> terra-mast.com

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            G S 2 Replies Last reply May 11, 2021, 8:07 AM Reply Quote 0
            • G
              Gertjan @NogBadTheBad
              last edited by May 11, 2021, 8:07 AM

              And for my onwn curiosity : why block inbound traffic ?
              Outbound maybe ....
              I try to sell you the 'don't contact the Chinese, so they won't contact you' but 'incoming' is already hitting the wall anyway.
              Exception may that 'VPN in' 1194 UDP port. Well, let them tickle that VPN port. its designed to do so.

              SFTP/SSH on WAN is something of the past.

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              S 1 Reply Last reply May 11, 2021, 11:36 AM Reply Quote 0
              • S
                Smoothrunnings @NogBadTheBad
                last edited by May 11, 2021, 11:33 AM

                @nogbadthebad I think maybe you are missing the point there. Terra-master.com which is a Chinese company who makes the TerraMaster NAS box mail servers are all behind the great firewall of China. For me to get onto their forum requires me to open a connection to China with them.

                The NAS box, just like my Seagate 4bay NAS boxes let folks know when there is a FW update, it does this by talking to home base everyone once in while. Its also what pfSense does, to let you when when there is an update to your firewall OS.

                N 1 Reply Last reply May 11, 2021, 4:30 PM Reply Quote 0
                • S
                  Smoothrunnings @Gertjan
                  last edited by May 11, 2021, 11:36 AM

                  @gertjan For starters this is my homelab, I don't want to block everything as my wife uses the internet to access her work stuff, and you know that saying... Happy wife, happy life .. right? :)

                  1 Reply Last reply Reply Quote 0
                  • N
                    NogBadTheBad @Smoothrunnings
                    last edited by May 11, 2021, 4:30 PM

                    @smoothrunnings said in Is there anyway to whitelist?:

                    @nogbadthebad I think maybe you are missing the point there. Terra-master.com which is a Chinese company who makes the TerraMaster NAS box mail servers are all behind the great firewall of China. For me to get onto their forum requires me to open a connection to China with them.

                    The NAS box, just like my Seagate 4bay NAS boxes let folks know when there is a FW update, it does this by talking to home base everyone once in while. Its also what pfSense does, to let you when when there is an update to your firewall OS.

                    I'd be very wary opening an inbound connection that would possibly allow them access to the NAS that then has full access to the LAN.

                    FYI I get informed of updates from Synology without having to open an inbound connection, the device polls their server.

                    Andy

                    1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                    1 Reply Last reply Reply Quote 0
                    6 out of 9
                    • First post
                      6/9
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.