• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Custom aliases using domain name

Scheduled Pinned Locked Moved Off-Topic & Non-Support Discussion
32 Posts 5 Posters 4.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    Su30MKI @NogBadTheBad
    last edited by Su30MKI Nov 22, 2018, 7:20 PM Nov 22, 2018, 7:19 PM

    @nogbadthebad I understand that part. How to create an alias for blocking pfsense by pfblockerng? I am very new to pf blockerng. I also have paid blacklist service. Can I load that to pfblockerng?

    1 Reply Last reply Reply Quote 0
    • N
      NogBadTheBad
      last edited by NogBadTheBad Nov 22, 2018, 7:41 PM Nov 22, 2018, 7:29 PM

      • Instal lpfBlockerNG-devel

      • Run the setup wizard , define your inbound and outbound interface.

      • Create a rule Firewall -> pfBlockerNG -> IP -> IPv4 as per my screenshot but set it as deny outbound

      • Run update via Firewall -> pfBlockerNG -> Update, the firewall rules will automatically be created

      The rules will automatically be created on the inbound and outbound interfaces, give it a go, its quite easy.

      0_1542914881999_Screenshot 2018-11-22 at 19.25.49.png

      Re the paid block list you can, depending on the format, it basically creates tables that are used in firewall rules, check the tables out via Diagnostics -> Tables

      0_1542915086235_Screenshot 2018-11-22 at 19.31.13.png

      Andy

      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

      S 1 Reply Last reply Nov 28, 2018, 6:08 AM Reply Quote 1
      • S
        Su30MKI @NogBadTheBad
        last edited by Nov 28, 2018, 6:08 AM

        @nogbadthebad Hello.. Thank you for your support. I am sorry for the delay in the reply. I was doing a whole new set up. I have multi wan failover setup done. So in PfblockerNG, The Inbound interface --> WAN1 & WAN2 and The outbound interface --> LAN. Is it the right method?

        N 1 Reply Last reply Nov 28, 2018, 8:47 AM Reply Quote 0
        • N
          NogBadTheBad @Su30MKI
          last edited by Nov 28, 2018, 8:47 AM

          @su30mki

          Yup sounds right.

          Andy

          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

          S 1 Reply Last reply Nov 28, 2018, 8:56 AM Reply Quote 1
          • S
            Su30MKI @NogBadTheBad
            last edited by Nov 28, 2018, 8:56 AM

            @nogbadthebad I am having multiple vlans created in pfsense. Then I think the outbound interface should be all the vlans.

            N 1 Reply Last reply Nov 28, 2018, 10:48 AM Reply Quote 0
            • N
              NogBadTheBad @Su30MKI
              last edited by Nov 28, 2018, 10:48 AM

              @su30mki

              Yes.

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              S 1 Reply Last reply Nov 28, 2018, 2:19 PM Reply Quote 1
              • S
                Su30MKI @NogBadTheBad
                last edited by Su30MKI Nov 28, 2018, 2:19 PM Nov 28, 2018, 2:19 PM

                @nogbadthebad Hi, I tried doing it, But it is not blocking facebook. Please find the screenshots.1_1543414765834_IPv4-list-2.PNG 0_1543414765815_IPv4-list1.PNG

                1 Reply Last reply Reply Quote 0
                • N
                  NogBadTheBad
                  last edited by NogBadTheBad Nov 28, 2018, 2:24 PM Nov 28, 2018, 2:21 PM

                  It's deny outbound.

                  Get it working with ASN numbers they play with the social networking source after.

                  Andy

                  1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                  1 Reply Last reply Reply Quote 0
                  • N
                    NogBadTheBad
                    last edited by NogBadTheBad Nov 28, 2018, 2:51 PM Nov 28, 2018, 2:40 PM

                    I've just tried it and its an issue with your block list as it doesn't contain valid IP addresses just 0.0.0.0 FQDN.

                    PfB_Test_v4 Table
                    IP Address
                    123.41.54.45
                    130.211.230.53
                    160.41.54.45
                    163.41.54.45
                    194.41.54.45

                    Rather than using IP try using the DBNS

                    0_1543416681468_Screenshot 2018-11-28 at 14.50.13.png

                    Andy

                    1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                    1 Reply Last reply Reply Quote 1
                    • S
                      Su30MKI
                      last edited by Nov 28, 2018, 3:00 PM

                      Can you please suggest any list?

                      N 1 Reply Last reply Nov 28, 2018, 3:06 PM Reply Quote 0
                      • N
                        NogBadTheBad @Su30MKI
                        last edited by Nov 28, 2018, 3:06 PM

                        @su30mki

                        Have you tried blocking facebook by ASN numbers or like I suggested try the using the list your using in the DBNSL section as per my screenshot.

                        Andy

                        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                        S 1 Reply Last reply Nov 28, 2018, 3:13 PM Reply Quote 0
                        • S
                          Su30MKI @NogBadTheBad
                          last edited by Nov 28, 2018, 3:13 PM

                          @nogbadthebad Thank you very much.. It is working. Saved my reputation.

                          N 1 Reply Last reply Nov 28, 2018, 3:14 PM Reply Quote 0
                          • N
                            NogBadTheBad @Su30MKI
                            last edited by Nov 28, 2018, 3:14 PM

                            @su30mki said in Custom aliases using domain name:

                            @nogbadthebad Thank you very much.. It is working. Saved my reputation.

                            via IP and ASN number or DNSBL ?

                            Andy

                            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                            S 1 Reply Last reply Nov 28, 2018, 3:21 PM Reply Quote 1
                            • S
                              Su30MKI @NogBadTheBad
                              last edited by Nov 28, 2018, 3:21 PM

                              @nogbadthebad Now how do I segregate different rules for different vlans?

                              N 1 Reply Last reply Nov 28, 2018, 3:29 PM Reply Quote 0
                              • N
                                NogBadTheBad @Su30MKI
                                last edited by Nov 28, 2018, 3:29 PM

                                @su30mki

                                Use alias permit, alias deny, alias match & alias native.

                                That will just create an alias you can use in firewall rules.

                                Andy

                                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                S 1 Reply Last reply Nov 28, 2018, 3:30 PM Reply Quote 1
                                • S
                                  Su30MKI @NogBadTheBad
                                  last edited by Nov 28, 2018, 3:30 PM

                                  @nogbadthebad Can you please help me with a screenshot?

                                  1 Reply Last reply Reply Quote 0
                                  • N
                                    NogBadTheBad
                                    last edited by NogBadTheBad Nov 28, 2018, 3:36 PM Nov 28, 2018, 3:35 PM

                                    0_1543419206004_Screenshot 2018-11-28 at 15.32.37.png

                                    Only allow GB access to my SFTP server:-

                                    0_1543419347807_Screenshot 2018-11-28 at 15.33.03.png

                                    Andy

                                    1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                    S 1 Reply Last reply Nov 28, 2018, 3:41 PM Reply Quote 1
                                    • S
                                      Su30MKI @NogBadTheBad
                                      last edited by Nov 28, 2018, 3:41 PM

                                      @nogbadthebad Thank you for your effort. But that is Geoip. Imagine I want to block facebook to one vlan and another vlan requires facebook access.. How do I do it? How can I do different rules for different vlan via DNSBL?

                                      A 1 Reply Last reply Dec 20, 2018, 5:28 AM Reply Quote 0
                                      • N
                                        NogBadTheBad
                                        last edited by Nov 28, 2018, 3:47 PM

                                        Use ASN if you want to block a specific company.

                                        DBNSL alters DNS so x.y.z.abc.com resolves to an internal ip address on your router.

                                        IP creates tables that can be used in firewall rules.

                                        The example I gave you was a GeoIP one I use but ASN based ones are no different, rather than containing a countries IP range it contains a companies IP range.

                                        Andy

                                        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                        1 Reply Last reply Reply Quote 0
                                        • A
                                          Alexismurphy @Su30MKI
                                          last edited by Dec 20, 2018, 5:28 AM

                                          @su30mki said in Custom aliases using domain name:

                                          I want to block facebook to one vlan and another vlan requires facebook access.. How do I do it?

                                          First at all, you have to configure your vlan.
                                          After that, you have to create an ACL in order to provide internet access to one vlan and block it in the other vlans.
                                          Remember set your device as a “Layer 3” device.

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            [[user:consent.lead]]
                                            [[user:consent.not_received]]