• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

How to create alias with *large* number of hosts?

Scheduled Pinned Locked Moved Firewalling
6 Posts 3 Posters 828 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • V
    victorhooi
    last edited by Mar 10, 2018, 7:56 AM

    (X-post from Reddit - https://www.reddit.com/r/PFSENSE/comments/81egao/alias_for_large_number_of_hosts/).

    Hi,

    I'm trying to setup some firewall/traffic shaping rules for a large number of hosts (e.g. IP ranges associated with a cloud provider).

    The IP ranges are unlikely to change frequently.

    What's the recommended way of creating an alias for these?

    I did try creating a normal alias in pfSense, with the ranges added as CIDR ranges. For example, one of the CIDR addresses is a /14, and so around 200,000+ IP addresses. However, once I hit submit it seems to cause the webUI to simply hang (I waited for over 10 minutes).

    Is there some trick to it?

    Thanks,
    Victor

    1 Reply Last reply Reply Quote 0
    • D
      Derelict LAYER 8 Netgate
      last edited by Mar 10, 2018, 8:40 AM

      Why would you not just make a network alias for the /14? That would be one CIDR entry, not 200K different addresses.

      See URL Table Type aliases for truly large lists.

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • J
        johnpoz LAYER 8 Global Moderator
        last edited by Mar 10, 2018, 9:35 AM

        ^Exactly… I have rfc1918 alias that has all of them in it, which include 10/8 and 172.16/12

        My plex alias which allows in the netblocks that plex uses to check if you have remote access and my son's and friends IPs has multiple /12s some /15s and even a new /10 they started using.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        1 Reply Last reply Reply Quote 0
        • V
          victorhooi
          last edited by Mar 10, 2018, 6:06 PM

          When you say Network Alias - do you mean going in via Firewalls, Aliases, IP, then clicking on the green "Add" button?

          This is exactly where I went in before, and tried to enter in a few large CIDR ranges - which is when the pfSense WebUI hung on me, as soon as I clicked Save.

          Hence, why I didn't know if there was perhaps another place that I should be entering in large ranges?

          1 Reply Last reply Reply Quote 0
          • D
            Derelict LAYER 8 Netgate
            last edited by Mar 10, 2018, 8:28 PM

            You have several choices for the TYPE of alias to create there. One of them is Network. One of them is URL Table.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • J
              johnpoz LAYER 8 Global Moderator
              last edited by Mar 11, 2018, 11:31 AM

              Hit the type dropdown and change to networks..

              dropdownnetwork.png
              dropdownnetwork.png_thumb

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              1 Reply Last reply Reply Quote 0
              1 out of 6
              • First post
                1/6
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received