Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    making changes to rules applied only after reboot

    Scheduled Pinned Locked Moved Firewalling
    22 Posts 2 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • O
      oren1031
      last edited by

      yes im using them to block incoming via geolocation.
      and i started getting some error that i was unable to fix about memory so i kept adding more to
      Firewall Maximum States
      and to Firewall Maximum Table Entries

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @oren1031
        last edited by

        @oren1031 said in making changes to rules applied only after reboot:

        error that i was unable to fix

        What was the specific error - yeah if you had issues with the memory and tables - that for sure could of caused issues with load of rules..

        Not talking about geoip, I use those in pfblocker - more talking about letting pfblocker auto create rules.. Which I don't use.. I just use it to create native aliases that I put in the rules.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • O
          oren1031
          last edited by

          Cannot allocate memory - The line in question reads [48]: table <pfB_NAmerica_v6> persist file "/var/db/aliastables/pfB_NAmerica_v6.txt"

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @oren1031
            last edited by johnpoz

            yeah that list is going to be freaking HUGE ;) NA v6...

            You need to up the table size.. if your going to use such a list. What do you have yours set to?

            set.png

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • O
              oren1031
              last edited by

              now i took it up to 2400000 for now im getting no error.

              1 Reply Last reply Reply Quote 0
              • O
                oren1031
                last edited by

                but look like pfblocker is doing its job...
                cc357ba2-2ac5-4b2e-be00-a46f8560050a-image.png

                johnpozJ 1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @oren1031
                  last edited by

                  Wouldn't it just be easier to allow what you want ;) Out of the box all is blocked anyway. Just use geoip list of what you want to allow to hit your port forward/exposed ports..

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • O
                    oren1031
                    last edited by

                    that is what i did. blocked all but what i want to be enabled.

                    johnpozJ 1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator @oren1031
                      last edited by johnpoz

                      Why are you loading the NA list then? Just for your picture of where IPs are from?

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      1 Reply Last reply Reply Quote 0
                      • O
                        oren1031
                        last edited by

                        im blocking all inbounds. from everywhere but my country.
                        isnt that the way to go? if i have a service i want to be accessed only from my country to minimize exposer?

                        johnpozJ 1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator @oren1031
                          last edited by johnpoz

                          Again just allow your country on your rule/port forward. All is blocked by default.. There is little reason to load up some table of all NA v6, when ALL is blocked by default. And your allow is only your country list of IP ranges.

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          1 Reply Last reply Reply Quote 0
                          • O
                            oren1031
                            last edited by

                            so when allowing only 1 country all others will be blocked by pfblocker?
                            is that what you mean?
                            no need for block rules because all that is not allowed is blocked?

                            1 Reply Last reply Reply Quote 0
                            • O
                              oren1031
                              last edited by

                              what is the downside? of using it the way i do?
                              keeping in mind i have i3 with 8 gig ram. so its not really
                              working that hard.. its a home environment.

                              johnpozJ 1 Reply Last reply Reply Quote 0
                              • johnpozJ
                                johnpoz LAYER 8 Global Moderator @oren1031
                                last edited by

                                What trying to load every known IP on the planet to put in a list so you can block it? When ALL ips are blocked by default anyway ;)

                                An intelligent man is sometimes forced to be drunk to spend time with his fools
                                If you get confused: Listen to the Music Play
                                Please don't Chat/PM me for help, unless mod related
                                SG-4860 24.11 | Lab VMs 2.8, 24.11

                                1 Reply Last reply Reply Quote 0
                                • O
                                  oren1031
                                  last edited by

                                  ill try what you offer it is more logic. i was not aware that it block by default.
                                  also i like the picture :)

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.