Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPV4 White list before Geo IP

    Scheduled Pinned Locked Moved pfBlockerNG
    2 Posts 2 Posters 582 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      pdrass
      last edited by

      I have a white list in the IPV4 tab that's worked perfectly for an untold amount of time.  Today, Microsoft in their infinite wisdom moved a bunch of stuff overseas and because I have Geo IP Block (Country Blocking) also enabled and configured it now seems that my IPV4 white list takes a back seat to the Geo IP Block list.

      I think it used to work differently.

      Used to be:

      IPV4 White List > Geo IP
      

      Now seems to be:

      Geo IP > IPV4 White List
      

      So if it matches the Geo IP it blocks it and never makes it to my IPV4 white list!!!

      If I'm blocking the EU (and all their countries) BUT I have specific EU based IP's like Microsoft's IP's in Italy, Netherlands, Finland, etc…it seems my white list is ignored in favor of the country.

      Can you confirm this behavior?

      Block message on the FW log:
      @115(1770004605) block return log quick on re0 inet from any to <pfb_europe_v4:120341>label "USER_RULE: pfB_Europe_v4 auto rule"

      My IP's in my white list:

      whois:  40.101.7.162
      
      White List:  40.125.0.0/17, 40.112.0.0/13, 40.96.0.0/12, 40.74.0.0/15, 40.124.0.0/16, 40.120.0.0/14, 40.80.0.0/12, 40.76.0.0/14
      

      Another interesting thing is if I look that IP address up on the SANS IP Country Lookup I get this:

      40.64.0.0/10 	US 	MICROSOFT-CORP-MSN-AS-BLOCK - Microsoft Corporation, US
      

      …that it's in the US and NOT in an EU country.  Is something wrong with the maxmind db perhaps?

      I'd also re-installed PFB to see if it would update something but it did not.  I kept all my old settings of course.

      Any insight into this issue would be helpful.  It seems two fold, rule order (which on the general tab is the default) between Geo IP v IPV4 and then the last issue of the maxmind db having incorrect country resolution.

      Thanks!</pfb_europe_v4:120341>

      1 Reply Last reply Reply Quote 0
      • BBcan177B
        BBcan177 Moderator
        last edited by

        Check the Firewall rule order… To overcome a GeoIP blocklist, you need to have the Permit rules above the Block rules.  The Rule order setting is in the General tab.

        "Experience is something you don't get until just after you need it."

        Website: http://pfBlockerNG.com
        Twitter: @BBcan177  #pfBlockerNG
        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.