Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IP Address in San Antonio, TX being blocked by pfB_SAmerica_v4

    Scheduled Pinned Locked Moved pfBlockerNG
    7 Posts 3 Posters 661 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      tim_co
      last edited by

      Hello,

      I have a wifi thermostat that is trying to contact 191.238.242.203 which I show as being located in San Antonio, TX. However, per the logs below, the IP is getting blocked by the pfB_SAmerica_v4 auto rule. If I allow outbound to  pfB_SAmerica_v4 the problem goes away. PFSense is showing pfblockerng to be on the latest package 2.1.1_11. PFSense is 2.4.0-RELEASE (amd64)

      Can anybody tell me why the IP is being blocked by pfB_SAmerica_v4 auto when it appears to be in TX? If there's not a fix, how can I isolate what country within the South America country list is flagging the IP so I can allow just that country?

      Any help is greatly appreciated.

      Regards,
      Tim in CO

      7 filterlog: 132,,,1770011309,igb2_vlan25,match,block,in,4,0x0,,64,10012,0,none,6,tcp,60,192.168.5.90,191.238.242.203,57579,80,0,S,3818633139,,2896,,mss;nop;wscale;nop;nop;TS

      Action Time Interface Source Destination Protocol
      Oct 17 08:57:16 VLAN25WIFIAPPLIANCES   192.168.5.90:58424   191.238.242.203:80 TCP:S
      pfB_SAmerica_v4 auto rule (1770011309)

      1 Reply Last reply Reply Quote 0
      • T
        tim_co
        last edited by

        Anyone, anyone?

        1 Reply Last reply Reply Quote 0
        • B
          biggsy
          last edited by

          http://www.dnsstuff.com/tools#whois|type=ipv4&&value=191.238.242.203

          Seems to be Microsoft Azure in Brazil.

          1 Reply Last reply Reply Quote 0
          • T
            tim_co
            last edited by

            Cool. Thank you. Based on the URL you posted I think i now see how you figured that out. I'll use dnsstuff.com in the future.

            Regards,
            Tim

            1 Reply Last reply Reply Quote 0
            • B
              biggsy
              last edited by

              I didn't check the URL in that post.  It got broken in the middle.

              However, I just noticed that pfSense's Diagnostics > DNS Lookup points to:

              IP WHOIS @ DNS Stuff
              and
              IP Info @ DNS Stuff

              neither of these seem to work now.

              1 Reply Last reply Reply Quote 0
              • T
                tim_co
                last edited by

                No worries. I got the information I was looking for. Thanks again.

                1 Reply Last reply Reply Quote 0
                • BBcan177B
                  BBcan177 Moderator
                  last edited by

                  @tim_co:

                  No worries. I got the information I was looking for. Thanks again.

                  As an FYI:

                  In the Alerts tab, you can click on the "I" infoblock icons and it will load a Threat Lookup page with several Threat Source lookup tools….

                  "Experience is something you don't get until just after you need it."

                  Website: http://pfBlockerNG.com
                  Twitter: @BBcan177  #pfBlockerNG
                  Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.