Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Firewall rule only for google recaptcha

    Firewalling
    2
    4
    3.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • SipriusPTS
      SipriusPT
      last edited by

      Hello everyone,

      I am trying to allow only google recaptcha without having to allow all or most google services (through google.com or www.google.com), to be used on a subnet that all internet is blocked, except certain websites.

      Anyone here, have a rule recipe for google recaptcha?

      Thanks in advance!

      1xSG-4860-1U
      1xSG-3100
      2xpfSense Virtual Machines

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @SipriusPT
        last edited by

        @sipriuspt said in Firewall rule only for google recaptcha:

        google recaptcha

        The "google recaptcha" is a script that runs on your web server. It uses a FQDN to access the Google's "google recaptcha" services.

        Using this FQDN as an alias, and use that alias as a with a pass rule probably won't work well, as this FQDN can point to many IP addresses.

        So, you mission is, if you accept it, is to find out what all these IP addresses are, put them in an aliases, and use that alias in your firewall rule.

        edit : Oops : https://www.google.com/recaptcha/api/ ..... "google.com" has thousands (more) IP's ...

        Btw : as you might have guessed / already know : firewall rules work only with IP addresses, not host names.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        SipriusPTS 1 Reply Last reply Reply Quote 1
        • SipriusPTS
          SipriusPT @Gertjan
          last edited by SipriusPT

          @gertjan The fact that they didnt dedicate a hand of IPs or even a sub DN or a DN dedicated to recaptchas, it turns filtering google recaptchas a real pain in the a**, through firewall rules.

          1xSG-4860-1U
          1xSG-3100
          2xpfSense Virtual Machines

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan @SipriusPT
            last edited by Gertjan

            @sipriuspt

            Google captchas functionality is put in place by an web server admin.
            Using other words : if you install a captcha on a web server, it needs an access to Google's API.
            It will not visit other web sites.
            So, why (firewall) filter connections initiated by a web server itself ??
            You - the admin - control the web server. It's not some device with controlled by a a person.

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.