Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to create alias with *large* number of hosts?

    Scheduled Pinned Locked Moved Firewalling
    6 Posts 3 Posters 907 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      victorhooi
      last edited by

      (X-post from Reddit - https://www.reddit.com/r/PFSENSE/comments/81egao/alias_for_large_number_of_hosts/).

      Hi,

      I'm trying to setup some firewall/traffic shaping rules for a large number of hosts (e.g. IP ranges associated with a cloud provider).

      The IP ranges are unlikely to change frequently.

      What's the recommended way of creating an alias for these?

      I did try creating a normal alias in pfSense, with the ranges added as CIDR ranges. For example, one of the CIDR addresses is a /14, and so around 200,000+ IP addresses. However, once I hit submit it seems to cause the webUI to simply hang (I waited for over 10 minutes).

      Is there some trick to it?

      Thanks,
      Victor

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        Why would you not just make a network alias for the /14? That would be one CIDR entry, not 200K different addresses.

        See URL Table Type aliases for truly large lists.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          ^Exactly… I have rfc1918 alias that has all of them in it, which include 10/8 and 172.16/12

          My plex alias which allows in the netblocks that plex uses to check if you have remote access and my son's and friends IPs has multiple /12s some /15s and even a new /10 they started using.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • V
            victorhooi
            last edited by

            When you say Network Alias - do you mean going in via Firewalls, Aliases, IP, then clicking on the green "Add" button?

            This is exactly where I went in before, and tried to enter in a few large CIDR ranges - which is when the pfSense WebUI hung on me, as soon as I clicked Save.

            Hence, why I didn't know if there was perhaps another place that I should be entering in large ranges?

            1 Reply Last reply Reply Quote 0
            • DerelictD
              Derelict LAYER 8 Netgate
              last edited by

              You have several choices for the TYPE of alias to create there. One of them is Network. One of them is URL Table.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                Hit the type dropdown and change to networks..

                dropdownnetwork.png
                dropdownnetwork.png_thumb

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.