<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[[SOLVED] Floating Rules&#x2F;Rule Order]]></title><description><![CDATA[<p dir="auto">I am looking for direction as there is a specific ruleset order I am attempted to accomplish. The default Rule Order's did now allow my setup without making a mess of the order I already had in place and so I set floating rules. I am running into an issue where I need the "Quick" option disabled as I would like to manage the list as an Alias in my WAN Rules. I looked for a few obvious fixes but it does not look like you can use pfBlocker in this way? Unless there is another way I am looking to edit the following file to disable quick by default but it does does not seem to be working. At this time I only need the lists to update without editing the rules that are in place. Please advise.</p>
]]></description><link>https://forum.netgate.com/topic/105266/solved-floating-rules-rule-order</link><generator>RSS for Node</generator><lastBuildDate>Tue, 14 Apr 2026 06:48:53 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/105266.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 11 Sep 2016 19:35:29 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to [SOLVED] Floating Rules&#x2F;Rule Order on Mon, 12 Sep 2016 03:03:37 GMT]]></title><description><![CDATA[<p dir="auto">Everything is starting to come together. This makes perfect sense! Exactly what I was looking for. At first I had no idea what you were saying but it was that I never fully read to understand these settings on these pages. Sorry to waste your time and thank you!</p>
]]></description><link>https://forum.netgate.com/post/648954</link><guid isPermaLink="true">https://forum.netgate.com/post/648954</guid><dc:creator><![CDATA[zilla]]></dc:creator><pubDate>Mon, 12 Sep 2016 03:03:37 GMT</pubDate></item><item><title><![CDATA[Reply to [SOLVED] Floating Rules&#x2F;Rule Order on Mon, 12 Sep 2016 00:55:38 GMT]]></title><description><![CDATA[<p dir="auto">When you click on the  <img src="http://i.imgur.com/Yxodhwt.jpg" alt="" class=" img-fluid img-markdown" /> infoblock  for <strong>List Action</strong> in the <strong>IPv4/IPv6/GeoIP</strong> tabs, it opens to this:</p>
<p dir="auto"><img src="http://i.imgur.com/7SETnD4.png?1" alt="" class=" img-fluid img-markdown" /></p>
<p dir="auto">If you select the <strong>Deny_Inbound, Deny_Outbound or Deny_Both</strong> type options, it will <strong>AUTO</strong> create the Firewall Rules for you, using the <strong>Rule Order</strong> setting that you configured in the General Tab… These are typical-use scenario <strong>Auto-Rule</strong> ordering options…</p>
<p dir="auto">These <strong>Auto Rules</strong>, <strong>might not fit</strong> with your network requirements, so instead you can select the <strong>Alias Type</strong> options which are highlighted above in the red boxes. These <strong>Alias Type</strong> options <strong>WILL NOT</strong> create any Firewall rules…</p>
<p dir="auto">With <strong>Alias Type</strong> settings, you will need to manually create all of the Firewall Rules, so that it fits with your network requirements… Review one of the Auto-Created rules as an example of how to manually create these Firewall Rules…</p>
<p dir="auto">Also, ensure that you read the last NOTE above, and prefix these pfBlockerNG manually created rules with <strong>pfb_</strong> ( lowercase )…  This is required so that the Widget knows which rules are for pfBlockerNG.</p>
<p dir="auto">Hope that helps!</p>
]]></description><link>https://forum.netgate.com/post/648936</link><guid isPermaLink="true">https://forum.netgate.com/post/648936</guid><dc:creator><![CDATA[BBcan177]]></dc:creator><pubDate>Mon, 12 Sep 2016 00:55:38 GMT</pubDate></item><item><title><![CDATA[Reply to [SOLVED] Floating Rules&#x2F;Rule Order on Mon, 12 Sep 2016 00:14:34 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/bbcan177">@<bdi>BBcan177</bdi></a>:</p>
<blockquote>
<p dir="auto">I already provided your solution above.</p>
<p dir="auto">Select the "Alias type" options in the "List Action" settings. (IPv4/6/GeoIP etc). Then you can manually create the rules as you require and reference the applicable alias table that the package creates.</p>
<p dir="auto">Click the blue infoblock icons for additional details.</p>
</blockquote>
<p dir="auto">Extremely sorry and I do not mean to be a novice but how would I also allow my rule order to work? I would need a way to not allow the default rules to be added to Floating/WAN rules and still update. Are you saying settle with a rule order of pfBlocker rules on bottom and re-reference my rules, duplicating the rules, allowed in the middle?</p>
]]></description><link>https://forum.netgate.com/post/648933</link><guid isPermaLink="true">https://forum.netgate.com/post/648933</guid><dc:creator><![CDATA[zilla]]></dc:creator><pubDate>Mon, 12 Sep 2016 00:14:34 GMT</pubDate></item><item><title><![CDATA[Reply to [SOLVED] Floating Rules&#x2F;Rule Order on Sun, 11 Sep 2016 23:57:27 GMT]]></title><description><![CDATA[<p dir="auto">I already provided your solution above.</p>
<p dir="auto">Select the "Alias type" options in the "List Action" settings. (IPv4/6/GeoIP etc). Then you can manually create the rules as you require and reference the applicable alias table that the package creates.</p>
<p dir="auto">Click the blue infoblock icons for additional details.</p>
]]></description><link>https://forum.netgate.com/post/648930</link><guid isPermaLink="true">https://forum.netgate.com/post/648930</guid><dc:creator><![CDATA[BBcan177]]></dc:creator><pubDate>Sun, 11 Sep 2016 23:57:27 GMT</pubDate></item><item><title><![CDATA[Reply to [SOLVED] Floating Rules&#x2F;Rule Order on Mon, 12 Sep 2016 05:02:05 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/bbcan177">@<bdi>BBcan177</bdi></a>:</p>
<blockquote>
<p dir="auto">In the General Tab, there are several different "Rule Order" options, did you try those?</p>
</blockquote>
<p dir="auto">-None of these options will allow all rules to work successfully as it will reorder improperly.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/bbcan177">@<bdi>BBcan177</bdi></a>:</p>
<blockquote>
<p dir="auto">You are not forced to use "Auto type" rules…. You can easily opt to use "Alias type" ( ie: Alias_Deny ) and manually create your own rules as you wish.... The pfBlockerNG package will collect the IPs and put them into alias tables, and these alias tables can be easily referenced in any manually created firewall rules...</p>
<p dir="auto">Please review the blue infoblock icon in the <strong>IPv4 Tab / List Action</strong>, for more details on this approach…</p>
</blockquote>
<p dir="auto">-How can I full advantage of GeoIP block lists and disable Floating Rules/Rule Order to incorporate  IPv4 Alias Rules?</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/bbcan177">@<bdi>BBcan177</bdi></a>:</p>
<blockquote>
<p dir="auto">I would think that with a "Floating" type rule, that you would want the "quick" option to be selected, since in the Floating Tab, the last rule that matches "wins"…. so the quick option halts that process when the rule is matched.</p>
</blockquote>
<p dir="auto">-This will allow some of the county lists to supersede specific allow rules or allow blanket allows to trump country denies.</p>
]]></description><link>https://forum.netgate.com/post/648929</link><guid isPermaLink="true">https://forum.netgate.com/post/648929</guid><dc:creator><![CDATA[zilla]]></dc:creator><pubDate>Mon, 12 Sep 2016 05:02:05 GMT</pubDate></item><item><title><![CDATA[Reply to [SOLVED] Floating Rules&#x2F;Rule Order on Sun, 11 Sep 2016 22:29:28 GMT]]></title><description><![CDATA[<p dir="auto">Hi zilla,</p>
<p dir="auto">In the General Tab, there are several different "Rule Order" options, did you try those?</p>
<p dir="auto">You are not forced to use "Auto type" rules…. You can easily opt to use "Alias type" ( ie: Alias_Deny ) and manually create your own rules as you wish.... The pfBlockerNG package will collect the IPs and put them into alias tables, and these alias tables can be easily referenced in any manually created firewall rules...</p>
<p dir="auto">Please review the blue infoblock icon in the <strong>IPv4 Tab / List Action</strong>, for more details on this approach…</p>
<p dir="auto">I would think that with a "Floating" type rule, that you would want the "quick" option to be selected, since in the Floating Tab, the last rule that matches "wins".... so the quick option halts that process when the rule is matched.</p>
]]></description><link>https://forum.netgate.com/post/648925</link><guid isPermaLink="true">https://forum.netgate.com/post/648925</guid><dc:creator><![CDATA[BBcan177]]></dc:creator><pubDate>Sun, 11 Sep 2016 22:29:28 GMT</pubDate></item></channel></rss>