• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Using pfBlockerNG Alias as source for NAT rule

Scheduled Pinned Locked Moved NAT
6 Posts 3 Posters 1.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B
    bradyrf
    last edited by Mar 18, 2019, 6:12 PM

    I am trying to use pfblockerng to create an alias of the US IP space so I can use that as a source in my NAT rule.
    I have created an alias match under GEOIP North America as well as created an alias under IPV4 pointing at the source /usr/local/share/GeoIP/cc/US_v4.txt. When I go into the NAT rule the aliases I have created do not show up.

    Am I missing something, maybe misunderstanding the pfblockerng / nat connection or is there a better way to accomplish this?

    Thanks in advance.

    1 Reply Last reply Reply Quote 1
    • N
      NogBadTheBad
      last edited by Mar 18, 2019, 7:00 PM

      Here is how I allow the access to my SFTP server using GEOIP:-

      NB I use any on the NAT rule so I can quickly change the firewall rule if needed.

      Screenshot 2019-03-18 at 18.54.41.png

      Screenshot 2019-03-18 at 18.55.13.png

      Screenshot 2019-03-18 at 18.55.42.png

      Andy

      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

      1 Reply Last reply Reply Quote 2
      • B
        bradyrf
        last edited by Mar 18, 2019, 7:23 PM

        Thanks much for the help my friend. I got it working.
        Its weird about an hour after i was working on it the alias's popped up as an available alias in the NAT source alias.

        Always appreciate your time. Im sure this will help many folks.
        Have a great day.
        B

        G N 2 Replies Last reply Mar 18, 2019, 7:50 PM Reply Quote 0
        • G
          Grimson Banned @bradyrf
          last edited by Mar 18, 2019, 7:50 PM

          @bradyrf said in Using pfBlockerNG Alias as source for NAT rule:

          Its weird about an hour after i was working on it the alias's popped up as an available alias in the NAT source alias.

          RTFM:
          pfB-rtfm.jpg

          1 Reply Last reply Reply Quote 0
          • N
            NogBadTheBad @bradyrf
            last edited by NogBadTheBad Mar 18, 2019, 8:05 PM Mar 18, 2019, 8:01 PM

            @bradyrf

            Don't create the alias using Firewall -> pfBlockerNG -> IP -> GeoIP as it will tie up the North America rule.

            Better to use Firewall -> pfBlockerNG -> IP -> IPv4 & IPv6 as you can name the alias whatever you want.

            You can force an update of the aliases via Firewall -> pfBlockerNG -> Update

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            1 Reply Last reply Reply Quote 0
            • B
              bradyrf
              last edited by Mar 18, 2019, 10:28 PM

              Thank you kind sir.
              I appreciate the advice.
              B

              1 Reply Last reply Reply Quote 0
              6 out of 6
              • First post
                6/6
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received