Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    IPV4 White list before Geo IP

    pfBlockerNG
    2
    2
    366
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      pdrass last edited by

      I have a white list in the IPV4 tab that's worked perfectly for an untold amount of time.  Today, Microsoft in their infinite wisdom moved a bunch of stuff overseas and because I have Geo IP Block (Country Blocking) also enabled and configured it now seems that my IPV4 white list takes a back seat to the Geo IP Block list.

      I think it used to work differently.

      Used to be:

      IPV4 White List > Geo IP
      

      Now seems to be:

      Geo IP > IPV4 White List
      

      So if it matches the Geo IP it blocks it and never makes it to my IPV4 white list!!!

      If I'm blocking the EU (and all their countries) BUT I have specific EU based IP's like Microsoft's IP's in Italy, Netherlands, Finland, etc…it seems my white list is ignored in favor of the country.

      Can you confirm this behavior?

      Block message on the FW log:
      @115(1770004605) block return log quick on re0 inet from any to <pfb_europe_v4:120341>label "USER_RULE: pfB_Europe_v4 auto rule"

      My IP's in my white list:

      whois:  40.101.7.162
      
      White List:  40.125.0.0/17, 40.112.0.0/13, 40.96.0.0/12, 40.74.0.0/15, 40.124.0.0/16, 40.120.0.0/14, 40.80.0.0/12, 40.76.0.0/14
      

      Another interesting thing is if I look that IP address up on the SANS IP Country Lookup I get this:

      40.64.0.0/10 	US 	MICROSOFT-CORP-MSN-AS-BLOCK - Microsoft Corporation, US
      

      …that it's in the US and NOT in an EU country.  Is something wrong with the maxmind db perhaps?

      I'd also re-installed PFB to see if it would update something but it did not.  I kept all my old settings of course.

      Any insight into this issue would be helpful.  It seems two fold, rule order (which on the general tab is the default) between Geo IP v IPV4 and then the last issue of the maxmind db having incorrect country resolution.

      Thanks!</pfb_europe_v4:120341>

      1 Reply Last reply Reply Quote 0
      • BBcan177
        BBcan177 Moderator last edited by

        Check the Firewall rule order… To overcome a GeoIP blocklist, you need to have the Permit rules above the Block rules.  The Rule order setting is in the General tab.

        1 Reply Last reply Reply Quote 0
        • First post
          Last post

        Products

        • Platform Overview
        • TNSR
        • pfSense
        • Appliances

        Services

        • Training
        • Professional Services

        Support

        • Subscription Plans
        • Contact Support
        • Product Lifecycle
        • Documentation

        News

        • Media Coverage
        • Press
        • Events

        Resources

        • Blog
        • FAQ
        • Find a Partner
        • Resource Library
        • Security Information

        Company

        • About Us
        • Careers
        • Partners
        • Contact Us
        • Legal
        Our Mission

        We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

        Subscribe to our Newsletter

        Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

        © 2021 Rubicon Communications, LLC | Privacy Policy