Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPv6 Alert SRC GeoIP Issue 2.2.5_19

    Scheduled Pinned Locked Moved pfBlockerNG
    7 Posts 3 Posters 923 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NogBadTheBadN
      NogBadTheBad
      last edited by NogBadTheBad

      The following is being blocked by a GeoIP block for Russia IPv4 & IPv6.

      0_1542011045744_Screenshot 2018-11-12 at 08.22.08.png

      0_1542011426495_Screenshot 2018-11-12 at 08.26.35.png

      The IP subnet is in the RU_v6.txt file.

      0_1542011060362_Screenshot 2018-11-12 at 08.22.31.png

      I'm in Great Britain and the traffic is comming from Russia

      Andy

      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

      GrimsonG 1 Reply Last reply Reply Quote 0
      • GrimsonG
        Grimson Banned @NogBadTheBad
        last edited by

        @nogbadthebad
        Report it to Maxmind https://www.maxmind.com/en/geoip2-databases that's the source for the database in pfBlockerNG.

        1 Reply Last reply Reply Quote 0
        • NogBadTheBadN
          NogBadTheBad
          last edited by NogBadTheBad

          it’s not a maxmind issue, the IP address is in the Russia txt file, pfBlockerNG Dev reports the source is in the GB.

          See my last screenshot.

          Andy

          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by johnpoz

            Sorry but the whois shows that IP as RU
            https://www.ultratools.com/tools/ipv6InfoResult?ipAddress=2001%3A6d0%3Affd9%3A301%3A195%3A209%3A146%3A222&as_sfid=AAAAAAXJdN8y4VwMH_qPRG_IcyFdkPd3_ZN0h9t9D15a_vHkdQJ8YFwobWJbcq4LRKKBjEqFL6b5YZxVtYEgtINFLR4zjSfuBv2mXAo25oTOlmd2zVc8qUymoip6aF95o4-qiac%3D&as_fid=4cf20d4e5d982453717d1efee86a730cba0705ee
            0_1542020317688_ruwhois.png

            And so does maxmind
            0_1542020148249_ru.png

            Where are you getting that its GB?

            In the Big Picture guess you could say that RU is Europe ;)

            Where an IP is for sure not an exact science and all kinds of problems can be seen with their database... I was fighting with maxmind for like ever that a /24 out of our /16 was not in freaking Vietnam!! ;) I don't think they ever fixed it.. Have to go back and look.. But it was stopping people from accessing their banks and websites because the IP was coming out not in the US.. Which clearly it was.. It was IP of our DC in Florida for gosh sake ;) But we shut down the proxy at that location so stop getting complaints about not able to access this or that because of geoip info not being correct..

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • NogBadTheBadN
              NogBadTheBad
              last edited by NogBadTheBad

              Also I'd have thought the Alert would have been Inbound not outbound like all the other IPv4 alerts, as it's 2001:6d0:ffd9:301:195:209:146:222 trying to poke my WAN interface on port 53.

              0_1542021175559_Screenshot 2018-11-12 at 11.11.50.png

              0_1542021366659_Screenshot 2018-11-12 at 11.09.58.png

              0_1542021199410_Screenshot 2018-11-12 at 11.08.20.png

              0_1542021885420_Screenshot 2018-11-12 at 11.23.05.png

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                Those blocks in the firewall your showing are inbound to the wan. If they were outbound block you would have the little > symbol..

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                NogBadTheBadN 1 Reply Last reply Reply Quote 0
                • NogBadTheBadN
                  NogBadTheBad @johnpoz
                  last edited by

                  @johnpoz

                  Yup

                  Andy

                  1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.