Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Make sure good connectivity from other countries

    Scheduled Pinned Locked Moved pfBlockerNG
    14 Posts 2 Posters 830 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • chudakC
      chudak
      last edited by

      I will be traveling in Europe soon. Last time I did that I noticed that from countries I could not access my home network.

      My assumption was that it was pfBNG blocking my access (which maybe debatable)

      Anyhow, I am trying to test connectivity from the world.

      Here are the steps:

      • disable pfBNG GeoIP for Europe (for example, maybe done for one country)
      • test that connections allowed from that location

      And I am not sure how test this.

      Tried https://www.uptrends.com/tools/traceroute and https://www.cdnperf.com/tools/cdn-latency-benchmark

      Wonder what would be the right way to test that ?
      I am sure there is a better way and better tools.

      @BBcan177 and others pls

      1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad
        last edited by NogBadTheBad

        Accessing your local network how exactly ?

        It is just a matter of rule order.

        Screenshot 2019-06-16 at 19.01.01.png

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        chudakC 1 Reply Last reply Reply Quote 0
        • chudakC
          chudak @NogBadTheBad
          last edited by

          @NogBadTheBad via OpenVPN

          NogBadTheBadN 1 Reply Last reply Reply Quote 0
          • NogBadTheBadN
            NogBadTheBad @chudak
            last edited by

            @chudak

            Then just put your ovpn rule above your pfblocker rules.

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            chudakC 1 Reply Last reply Reply Quote 0
            • chudakC
              chudak @NogBadTheBad
              last edited by

              @NogBadTheBad
              My pfBNG rules are floating

              But one part of the question is how to make it, and not less important how to test it from the US and what tools to use?

              1 Reply Last reply Reply Quote 0
              • NogBadTheBadN
                NogBadTheBad
                last edited by NogBadTheBad

                Why floating rules, do you have loads of interfaces?

                Don't use floating rules and sort out the order of your inbound rules will fix it.

                Andy

                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                chudakC 1 Reply Last reply Reply Quote 0
                • chudakC
                  chudak @NogBadTheBad
                  last edited by chudak

                  @NogBadTheBad

                  What's wrong with using floating rules ?

                  Again regardless this, say you disabled pfBNG all together - what is a good way to test connectivity from other countries ?

                  1 Reply Last reply Reply Quote 0
                  • NogBadTheBadN
                    NogBadTheBad
                    last edited by NogBadTheBad

                    Floating rules are processed first, it’s easier to tweak your rules if you use normal rules.

                    There really no way to test without getting your traffic to appear that it originated from that country, a vpn would do this but it would be tricky to test a vpn over a vpn.

                    Andy

                    1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                    chudakC 1 Reply Last reply Reply Quote 0
                    • chudakC
                      chudak @NogBadTheBad
                      last edited by

                      @NogBadTheBad

                      Let's simply the use case, no VPN

                      Have you tried these tools: https://www.uptrends.com/tools/traceroute and https://www.cdnperf.com/tools/cdn-latency-benchmark

                      What did you get? You trust the results ?

                      1 Reply Last reply Reply Quote 0
                      • NogBadTheBadN
                        NogBadTheBad
                        last edited by

                        @chudak said in Make sure good connectivity from other countries:

                        https://www.uptrends.com/tools/traceroute

                        Well thats just testing ICMP not OpenVPN.

                        I block all IPv4 ICMP to my WAN interface.

                        Andy

                        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                        chudakC 1 Reply Last reply Reply Quote 0
                        • chudakC
                          chudak @NogBadTheBad
                          last edited by

                          @NogBadTheBad said in Make sure good connectivity from other countries:

                          @chudak said in Make sure good connectivity from other countries:

                          https://www.uptrends.com/tools/traceroute

                          Well thats just testing ICMP not OpenVPN.

                          I block all IPv4 ICMP to my WAN interface.

                          How do you test then access from other countries ?

                          1 Reply Last reply Reply Quote 0
                          • NogBadTheBadN
                            NogBadTheBad
                            last edited by

                            You cant without being there.

                            Don’t use floating rules and sort the order of the WAN rules like I suggested.

                            Andy

                            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                            chudakC 1 Reply Last reply Reply Quote 0
                            • chudakC
                              chudak @NogBadTheBad
                              last edited by

                              @NogBadTheBad said in Make sure good connectivity from other countries:

                              You cant without being there.

                              Don’t use floating rules and sort the order of the WAN rules like I suggested.

                              I remember now (after trying again) why I had floating rules option selected.

                              If I un-check "Floating Rules" and place my rules above pfBNG's rules then on update my order is not preserved, pfBNG rules placed on top again. IIRC @BBcan177 had some reasoning for it.

                              I guess question for you is - is your rule order is preserved after update? If yea, maybe I missing some setting somewhere.

                              Thx

                              1 Reply Last reply Reply Quote 0
                              • NogBadTheBadN
                                NogBadTheBad
                                last edited by NogBadTheBad

                                You can drag the rules to suit, they are only re ordered when you add new rules or modify.

                                Also you can define how they're added:-

                                Screenshot 2019-06-19 at 08.22.28.png

                                Or you could use pfBlockerNG to create aliases then roll your own firewall rules.

                                Andy

                                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.