Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    1. Home
    2. Tags
    3. whitelist
    Log in to post
    • All categories
    • S

      DNSBL Auto whitelisting happing ?
      pfBlockerNG • whitelist dnsbl • • sesipod

      11
      0
      Votes
      11
      Posts
      664
      Views

      L

      @jot thanks for the info. You are right. Though I do not understand why to force whitelist google and yandex subdomains which are used for ads - ads.google.com|adservices.google.com. I just can not block ads if I enable safesearch option

    • Oceanwatcher

      Blocking everything except...
      General pfSense Questions • block all whitelist • • Oceanwatcher

      9
      0
      Votes
      9
      Posts
      298
      Views

      Oceanwatcher

      @stephenw10 said in Blocking everything except...:

      It might not be...

      That is correct 😉

    • K

      HAproxy backend whitelisting
      Cache/Proxy • haproxy whitelist blacklist • • keystroke

      9
      0
      Votes
      9
      Posts
      3179
      Views

      K

      That was it, thank you for your help!

    • M

      Whitelist-Ansatz für Windows- und Programmebene: Allen nicht explizit legitimierten (ausgehenden) Datenverkehr unterbinden
      Deutsch • whitelist windows firewall block • • M.i.t.M.X

      9
      0
      Votes
      9
      Posts
      689
      Views

      JeGr

      @m0nji said in Whitelist-Ansatz für Windows- und Programmebene: Allen nicht explizit legitimierten (ausgehenden) Datenverkehr unterbinden:

      @jegr said in Whitelist-Ansatz für Windows- und Programmebene: Allen nicht explizit legitimierten (ausgehenden) Datenverkehr unterbinden:

      Snort+OpenAppID

      Application Filtering on pfSense ist vollkommen an mir vorbei gegangen. Danke für die Richtigstellung.

      Kein Problem, gerne. Steht leider noch auf meinem ToDo Zettel zum Testen aber leider dank Krankheit und Arbeit noch nicht dazu gekommen ;)

    • newyork10023

      pfBlockerNG rule element modification and ordering
      pfBlockerNG • dnsbl whitelist rule ordering suspension pfblockerng • • newyork10023

      2
      0
      Votes
      2
      Posts
      584
      Views

      BBcan177

      @newyork10023 said in pfBlockerNG rule element modification and ordering:

      To begin, pfBlockerNG_devel 2.2.1_2 is awesome. Wow. Thanks.

      Thanks!

      Certain feeds are naughty. For example, adding RFC 1918 (Private Address Space), Multicast addresses, etc., etc., etc., is just BAD. Blocking possibly necessary system addresses, including multicast addresses, etc., is just NASTY. Adding a WhiteList is not going to fix this issue. These rule elements need to be culled from the list(s), and I mean permanently.

      By chance are you using Firehol Level1? That feed contains bogons and should not be used for Outbound blocking. You can also enable "Suppression" which will remove local/loopback addresss.

      A couple of feature suggestions for automatic rule insertion: use rule Separators to bind automatic rule insertion to specific places in the rules. (Indeed, one of my pet peeves is that automatic rules re-arrange Separator organization in seemingly random ways.). Another suggestion would be that automatic rule insertion should not re-arrange rule ordering AT ALL (after their initial placement). Subsequent rule updates should update rules IN PLACE. I like the possibility that Separators could be used to bind automatic rule insertion. But, disabling all automatic rule insertion needs to be an option for DNSBL.

      Firewall rule separators will be very difficult to implement with pfBlockerNG and auto rules...

    • S

      PfSense & Snort: Whitelist Domain
      IDS/IPS • pfsense snort whitelist domain url • • scpas

      1
      0
      Votes
      1
      Posts
      560
      Views

      No one has replied