Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Disable action does not work ?

    Scheduled Pinned Locked Moved pfBlockerNG
    33 Posts 3 Posters 3.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • chudakC
      chudak
      last edited by

      I use pfBlockerNG-devel 3.0.0_16 and troubleshooting an issue and needed to disable one of the GeoIP feeds.

      I went to GeoIP
      Disabled the feed
      Saved
      Ran force reload

      Checked and the rule was not actually working (ping an IP that is blocked by the feed).

      Checked the FW (floating) and the corresponding rule was still enabled (does pfBlockerNG-devel disable FW rule in this scenario??)

      Then
      Disabled FW rule and confirmed that it was successful.

      Why before I disabled the FW it did not work?
      Anything else I missed doing ?

      Thx

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @chudak
        last edited by

        My turn :

        I went to GeoIP
        I enabled a feed

        Like this :

        9fc101f6-6d8e-440a-b9f3-3910390f6f9d-image.png

        Saved
        Ran force reload

        I had these 4 new firewall rules on my Floating page :

        0433eb32-743d-4821-866a-2addce489531-image.png

        I removed the GEOP feed, saved, ran force reload.

        The four firewall rules (see above) on the floating page were gone.

        Btw : Normally, I do not use the GEOIP feeds, as I'm not hosting any web or mail server / I'm not letting anything in (well, I do, but these are limited using known source IP addresses).

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        chudakC 1 Reply Last reply Reply Quote 0
        • chudakC
          chudak @Gertjan
          last edited by

          @gertjan

          I removed the GEOP feed, saved, ran force reload.

          Ho did you "remove" it? I see only option to "disable" for GeoIP (unlike for IPv4 they can be deleted)

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan @chudak
            last edited by

            ff4cd3e0-b291-4b87-933e-bc88c102f464-image.png

            Disabled is like removed (for me).

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            chudakC 1 Reply Last reply Reply Quote 0
            • chudakC
              chudak @Gertjan
              last edited by

              @gertjan said in Disable action does not work ?:

              Disabled is like removed (for me).

              Got it! That's helpful.
              Just to confirm - after you disabled GeoIP feed the corresponding FW rules were removed as well ?

              This is what I expect, but don't see happening!

              GertjanG 1 Reply Last reply Reply Quote 0
              • GertjanG
                Gertjan @chudak
                last edited by Gertjan

                @chudak said in Disable action does not work ?:

                Just to confirm - after you disabled GeoIP feed the corresponding FW rules were removed as well ?

                I confirm.

                Did you hit the save button(see image above) ?

                edit : this button :

                20d6e91d-c70e-4320-b028-8a77ca0d5aab-image.png

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                chudakC 2 Replies Last reply Reply Quote 0
                • chudakC
                  chudak @Gertjan
                  last edited by chudak

                  @gertjan

                  That reminds me

                  My Cousin Vinny

                  on 0:17

                  "I am positive"

                  :)
                  @BBcan177 FYI

                  1 Reply Last reply Reply Quote 0
                  • chudakC
                    chudak @Gertjan
                    last edited by

                    @gertjan

                    Confirmed the same problem on 2.5.1-RELEASE/pfBlockerNG-devel 3.0.0_16

                    Disable GeoIP Europe + update/reload -> does not remove pfB_NAmerica_v4 FW rule !

                    RonpfSR 1 Reply Last reply Reply Quote 0
                    • RonpfSR
                      RonpfS @chudak
                      last edited by RonpfS

                      @chudak Maybe post pfblockerng.log, we can't see much without that.

                      2.4.5-RELEASE-p1 (amd64)
                      Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                      Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                      chudakC 1 Reply Last reply Reply Quote 0
                      • chudakC
                        chudak @RonpfS
                        last edited by

                        @ronpfs said in Disable action does not work ?:

                        @chudak Maybe post pfblockerng.log, we can see much without that.

                        https://pastebin.ubuntu.com/p/SHnvfgm2xN/

                        Please take a look !
                        Thx!

                        RonpfSR 1 Reply Last reply Reply Quote 0
                        • RonpfSR
                          RonpfS @chudak
                          last edited by

                          @chudak Did you ran a Force Update or a Force Reload All after disabling the GeoIP group?

                          2.4.5-RELEASE-p1 (amd64)
                          Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                          Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                          chudakC 1 Reply Last reply Reply Quote 0
                          • chudakC
                            chudak @RonpfS
                            last edited by

                            @ronpfs said in Disable action does not work ?:

                            @chudak Did you ran a Force Update or a Force Reload All after disabling the GeoIP group?

                            Yes

                            RonpfSR 1 Reply Last reply Reply Quote 0
                            • RonpfSR
                              RonpfS @chudak
                              last edited by RonpfS

                              @chudak So you ran both ? timestamp of the Force Update ?

                              2.4.5-RELEASE-p1 (amd64)
                              Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                              Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                              chudakC 1 Reply Last reply Reply Quote 0
                              • chudakC
                                chudak @RonpfS
                                last edited by

                                @ronpfs

                                You know I need to play with a bit and produce a good log. Will update later.

                                Thx for looking !

                                RonpfSR 1 Reply Last reply Reply Quote 0
                                • RonpfSR
                                  RonpfS @chudak
                                  last edited by

                                  @chudak said in Disable action does not work ?:

                                  You know I need to play with a bit and produce a good log. Will update later.
                                  Thx for looking !

                                  Start by enable only on GeoIP group check if things change with a Force Update, then run a Force Reload IP or ALL.

                                  Disable that GeoIP group, Update, Reload IP.

                                  2.4.5-RELEASE-p1 (amd64)
                                  Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                  Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                  chudakC 1 Reply Last reply Reply Quote 0
                                  • chudakC
                                    chudak @RonpfS
                                    last edited by

                                    @ronpfs

                                    It looks like it was my bad and disable in fact does work.

                                    My apologies !

                                    Can I ask you kinda related-unrelated question.

                                    When I look at my Whitelist I see:

                                    54b748ac-560a-4789-bede-dbe7cfcabb7b-image.png

                                    and corresponding FW rule:

                                    2418589b-a757-472d-a62d-59e88fac0b45-image.png

                                    Do White_List_hosts and White_List_ports have to be used? Can they be removed ?

                                    RonpfSR 1 Reply Last reply Reply Quote 0
                                    • RonpfSR
                                      RonpfS @chudak
                                      last edited by

                                      @chudak said in Disable action does not work ?:

                                      Do White_List_hosts and White_List_ports have to be used? Can they be removed ?

                                      When was this settings configured ? Look at both aliases to see if they are still relevant.

                                      2.4.5-RELEASE-p1 (amd64)
                                      Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                      Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                      chudakC 1 Reply Last reply Reply Quote 0
                                      • chudakC
                                        chudak @RonpfS
                                        last edited by

                                        @ronpfs said in Disable action does not work ?:

                                        When was this settings configured ? Look at both aliases to see if they are still relevant.

                                        The problem is I don;t actually remember when and how :)

                                        So I'd say no need for them. But when I try to disable "Custom DST Port" and "Custom Destination" and Save I get:

                                        56605d6b-1ffd-486d-b7d5-b7335ba7d06c-image.png

                                        ???

                                        What do you see there ?

                                        RonpfSR 1 Reply Last reply Reply Quote 0
                                        • RonpfSR
                                          RonpfS @chudak
                                          last edited by

                                          @chudak Strange. You are sure you untick both boxes, save, etc ?

                                          2.4.5-RELEASE-p1 (amd64)
                                          Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                          Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                          chudakC 1 Reply Last reply Reply Quote 0
                                          • chudakC
                                            chudak @RonpfS
                                            last edited by

                                            @ronpfs said in Disable action does not work ?:

                                            @chudak Strange. You are sure you untick both boxes, save, etc ?

                                            Yup, unchecked both and on save that error.

                                            Do you have aliases in tee WL?

                                            RonpfSR 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.