Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlocker Options

    Scheduled Pinned Locked Moved pfBlockerNG
    2 Posts 2 Posters 486 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      comprev
      last edited by

      The Netgate help file shows the following options:
      Options are:

      Deny Both - Will deny access on Both directions.
      Deny Inbound - Will deny access from selected lists to the local network.
      Deny Outbound - Will deny access from local users to IP address lists selected to block.
      Permit Inbound - Will allow access from selected lists to the local network.
      Permit Outbound - Will allow access from local users to IP address lists selected to block.
      Disabled - Will just keep selection and do nothing to selected Lists.
      Alias Only - Will create an alias with selected Lists to help custom rule assignments.

      However, in my pfBlocker page in pfSense, I'm also presented with the options:
      Match Inbound/Outbound/Both

      The instructions recommend not "blocking the world" since default behavior is to block unless permitted, but I also don't want to just allow any inbound traffic from certain countries. Would "Match Inbound" only allow from the specified countries to my open ports but drop all other traffic from those countries? I'm guessing the Match statement would force it to still be processed through other firewall rules.

      1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad
        last edited by NogBadTheBad

        Create an alias using pfBlocker and craft your own firewall rules.

        Screenshot 2020-07-01 at 16.06.10.png

        Screenshot 2020-07-01 at 16.06.33.png

        With the aliases the deny, permit & match only defines where the info in the report tab goes.

        Screenshot 2020-07-01 at 16.08.44.png

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        1 Reply Last reply Reply Quote 1
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.