Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfBlocker - Prevent rules from re-sorting

    Scheduled Pinned Locked Moved pfBlockerNG
    5 Posts 2 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      spittlbm
      last edited by

      I've created an alias of IP's I'd like to allow that would otherwise be blocked by pfblocker (exceptions).  I've moved this list above pfBlocker because I want the rest of that continent blocked.  Every time pfBlocker updates (CRON), it re-sorts my alias under/after pfBlocker.

      Is there any way to 1) keep it from changing the sort or 2) add a rule order of "manual sort" or is there a 3) this functionality already exists and I've just missed it?

      1 Reply Last reply Reply Quote 0
      • BBcan177B
        BBcan177 Moderator
        last edited by

        Select the "Rule Order" option in the General Tab.

        "Experience is something you don't get until just after you need it."

        Website: http://pfBlockerNG.com
        Twitter: @BBcan177  #pfBlockerNG
        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

        1 Reply Last reply Reply Quote 0
        • S
          spittlbm
          last edited by

          Nope.  All settings re-order with each CRON update.  So there's no way that I can find to set a bypass alias above pfblocker and leave it there permanently.

          1 Reply Last reply Reply Quote 0
          • BBcan177B
            BBcan177 Moderator
            last edited by

            Did you select one of these Rule Order options?

            How did you create this Exception list? Best to create a new pfBlockerNG "Permit Outbound" alias.
            Are you using Floating rules?

            "Experience is something you don't get until just after you need it."

            Website: http://pfBlockerNG.com
            Twitter: @BBcan177  #pfBlockerNG
            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

            1 Reply Last reply Reply Quote 0
            • S
              spittlbm
              last edited by

              I chose the first rule.

              I also created an alias (pfsense, not pfbng) to allow the particular IP's I want and put that as the first rule. Everything works like a charm for an hour, then the CRON job resorts to the Rule Order.

              Looks like I can accomplish the same thing through pfbng's alias system.  Wasn't aware that's what the ipv4 and ipv6 tabs were for.

              btw, the help link on the ipv4 tab is broken (https://<url to="" pfsense="">/help.php?page=/pfblockerng/pfblockerng_v4lists.xml)

              Thanks for your help - I'll tinker from here until I get it.</url>

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.