Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfBlocker alias join for NAT with source filter

    Scheduled Pinned Locked Moved NAT
    7 Posts 3 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      kaioh
      last edited by

      Hi everybody,
      I'd like to use GEOIP with PfBlocker to allow only one country for the IN traffic (NAT) for some firewall rules.

      The problem is that if I create ALIAS PERMIT groups with IPv4, IPv6 ans satellite subnets I get three ALIASES.

      I'd like to configure the NAT source field  with the join of these three aliases. Of course the firewall accepts only one rule for the NAT with same ports, so I don't know hot to manage this situation.

      NAT Example:


      Interface: WAN
      TCP/UDP VOIP PORTS
      Source: pfb_Europe_v4 <–-- Here I want to use multiple aliases

      Since obviously we are allowed to enter a single alias, I think I should tell pfBlocker to create only one ALIAS or maybe I should cron a script to join the aliases.

      Any suggestions?

      .: Kaioh :.

      1 Reply Last reply Reply Quote 0
      • V
        viragomann
        last edited by

        Create separate  NAT rules, one for each alias.

        1 Reply Last reply Reply Quote 0
        • BBcan177B
          BBcan177 Moderator
          last edited by

          You can goto the IPv4 tab and manually add the path to whatever GeoIP Countries you want. (/usr/local/share/GeoIP/cc/) Can also intermingle other lists as required in the same Alias.

          Click the blue "Infoblock" Icons in the IPv4 tab for more details.

          "Experience is something you don't get until just after you need it."

          Website: http://pfBlockerNG.com
          Twitter: @BBcan177  #pfBlockerNG
          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

          1 Reply Last reply Reply Quote 0
          • K
            kaioh
            last edited by

            @viragomann:

            Create separate  NAT rules, one for each alias.

            How is this possible for the same ports?

            .: Kaioh :.

            1 Reply Last reply Reply Quote 0
            • K
              kaioh
              last edited by

              @BBcan177:

              You can goto the IPv4 tab and manually add the path to whatever GeoIP Countries you want. (/usr/local/share/GeoIP/cc/) Can also intermingle other lists as required in the same Alias.

              Click the blue "Infoblock" Icons in the IPv4 tab for more details.

              Thank you very much for the solution.

              .: Kaioh :.

              1 Reply Last reply Reply Quote 0
              • K
                kaioh
                last edited by

                Just another question: what's the _rev_v4.txt file content?

                .: Kaioh :.

                1 Reply Last reply Reply Quote 0
                • BBcan177B
                  BBcan177 Moderator
                  last edited by

                  See the following:
                  https://forum.pfsense.org/index.php?topic=117744.0

                  Also you won't be able to mix IPv4 and 6 in the same Alias unfortunately.

                  "Experience is something you don't get until just after you need it."

                  Website: http://pfBlockerNG.com
                  Twitter: @BBcan177  #pfBlockerNG
                  Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.