Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Disable action does not work ?

    Scheduled Pinned Locked Moved pfBlockerNG
    33 Posts 3 Posters 3.9k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • RonpfSR Offline
      RonpfS @chudak
      last edited by

      @chudak said in Disable action does not work ?:

      You know I need to play with a bit and produce a good log. Will update later.
      Thx for looking !

      Start by enable only on GeoIP group check if things change with a Force Update, then run a Force Reload IP or ALL.

      Disable that GeoIP group, Update, Reload IP.

      2.4.5-RELEASE-p1 (amd64)
      Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
      Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

      chudakC 1 Reply Last reply Reply Quote 0
      • chudakC Offline
        chudak @RonpfS
        last edited by

        @ronpfs

        It looks like it was my bad and disable in fact does work.

        My apologies !

        Can I ask you kinda related-unrelated question.

        When I look at my Whitelist I see:

        54b748ac-560a-4789-bede-dbe7cfcabb7b-image.png

        and corresponding FW rule:

        2418589b-a757-472d-a62d-59e88fac0b45-image.png

        Do White_List_hosts and White_List_ports have to be used? Can they be removed ?

        RonpfSR 1 Reply Last reply Reply Quote 0
        • RonpfSR Offline
          RonpfS @chudak
          last edited by

          @chudak said in Disable action does not work ?:

          Do White_List_hosts and White_List_ports have to be used? Can they be removed ?

          When was this settings configured ? Look at both aliases to see if they are still relevant.

          2.4.5-RELEASE-p1 (amd64)
          Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
          Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

          chudakC 1 Reply Last reply Reply Quote 0
          • chudakC Offline
            chudak @RonpfS
            last edited by

            @ronpfs said in Disable action does not work ?:

            When was this settings configured ? Look at both aliases to see if they are still relevant.

            The problem is I don;t actually remember when and how :)

            So I'd say no need for them. But when I try to disable "Custom DST Port" and "Custom Destination" and Save I get:

            56605d6b-1ffd-486d-b7d5-b7335ba7d06c-image.png

            ???

            What do you see there ?

            RonpfSR 1 Reply Last reply Reply Quote 0
            • RonpfSR Offline
              RonpfS @chudak
              last edited by

              @chudak Strange. You are sure you untick both boxes, save, etc ?

              2.4.5-RELEASE-p1 (amd64)
              Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
              Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

              chudakC 1 Reply Last reply Reply Quote 0
              • chudakC Offline
                chudak @RonpfS
                last edited by

                @ronpfs said in Disable action does not work ?:

                @chudak Strange. You are sure you untick both boxes, save, etc ?

                Yup, unchecked both and on save that error.

                Do you have aliases in tee WL?

                RonpfSR 1 Reply Last reply Reply Quote 0
                • RonpfSR Offline
                  RonpfS @chudak
                  last edited by RonpfS

                  @chudak And you did that in the Whitelist group ? not with the FW rules.
                  I do have a Whitelist rules with both boxes unticked, maybe empty the field also.

                  2.4.5-RELEASE-p1 (amd64)
                  Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                  Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                  chudakC 1 Reply Last reply Reply Quote 0
                  • chudakC Offline
                    chudak @RonpfS
                    last edited by

                    @ronpfs

                    Not sure what you call "the Whitelist group"
                    I have it in my IPv4 list

                    fe7b5fd6-dbfa-4bfc-81c0-de2a952b586f-image.png

                    Tried emptying as well with no love

                    RonpfSR 1 Reply Last reply Reply Quote 0
                    • RonpfSR Offline
                      RonpfS @chudak
                      last edited by

                      @chudak said in Disable action does not work ?:

                      Not sure what you call "the Whitelist group"

                      Permit group ....

                      2.4.5-RELEASE-p1 (amd64)
                      Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                      Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                      chudakC 1 Reply Last reply Reply Quote 0
                      • chudakC Offline
                        chudak @RonpfS
                        last edited by

                        @ronpfs said in Disable action does not work ?:

                        @chudak said in Disable action does not work ?:

                        Not sure what you call "the Whitelist group"

                        Permit group ....

                        is Permit group different from my ?
                        where is the Permit group ?

                        RonpfSR 1 Reply Last reply Reply Quote 0
                        • RonpfSR Offline
                          RonpfS @chudak
                          last edited by

                          @chudak Well you have a Group Whitelist for IP permit both. Mine is permit Outbound.

                          2.4.5-RELEASE-p1 (amd64)
                          Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                          Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                          chudakC 2 Replies Last reply Reply Quote 0
                          • chudakC Offline
                            chudak @RonpfS
                            last edited by

                            @ronpfs said in Disable action does not work ?:

                            @chudak Well you have a Group Whitelist for IP permit both. Mine is permit Outbound.

                            ok i see, seems like the same then

                            RonpfSR 1 Reply Last reply Reply Quote 0
                            • chudakC Offline
                              chudak @RonpfS
                              last edited by

                              @ronpfs

                              are you on pfBlockerNG-devel 3.0.0_16 ?

                              1 Reply Last reply Reply Quote 0
                              • RonpfSR Offline
                                RonpfS @chudak
                                last edited by RonpfS

                                @chudak With permit both, the FW rules requires Custom port/dest settings, this is a requirement from pfSense, nothing to do with pfBlockerNG.

                                With permit Outbound that requirements isn't needed. Check the forum for similar issues.

                                2.4.5-RELEASE-p1 (amd64)
                                Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                chudakC 1 Reply Last reply Reply Quote 0
                                • chudakC Offline
                                  chudak @RonpfS
                                  last edited by

                                  @ronpfs said in Disable action does not work ?:

                                  @chudak With permit both, the FW rules requires Custom port/dest settings, this is a requirement from pfSense, nothing to do with pfBlockerNG.

                                  With permit Outbound that requirements isn't needed. Check the forum for similar issues.

                                  copy that

                                  what do you have ?

                                  RonpfSR 1 Reply Last reply Reply Quote 0
                                  • RonpfSR Offline
                                    RonpfS @chudak
                                    last edited by

                                    @chudak Permit outbound, any protocol ,nothing in Advanced FW Rules

                                    2.4.5-RELEASE-p1 (amd64)
                                    Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                    Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                    chudakC 1 Reply Last reply Reply Quote 1
                                    • chudakC Offline
                                      chudak @RonpfS
                                      last edited by

                                      @ronpfs said in Disable action does not work ?:

                                      @chudak Permit outbound, any protocol ,nothing in Advanced FW Rules

                                      I’ve changed my to Permit outbound and my Issues including https://forum.netgate.com/topic/162857/problem-after-pfblockerng-devel-3-0-0_16-update/13 are gone !

                                      I’m very puzzled. How it used to work all this time and how it was setup like this. Need to do explaining to myself :)

                                      Thanks a million for being patient!

                                      How does permit outbound actually works ? (Need to think about it)

                                      RonpfSR 1 Reply Last reply Reply Quote 0
                                      • RonpfSR Offline
                                        RonpfS @chudak
                                        last edited by

                                        @chudak said in Disable action does not work ?:

                                        How does permit outbound actually works ? (Need to think about it)

                                        That may contain some answers : https://docs.netgate.com/

                                        2.4.5-RELEASE-p1 (amd64)
                                        Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                        Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                        chudakC 1 Reply Last reply Reply Quote 1
                                        • chudakC Offline
                                          chudak @RonpfS
                                          last edited by

                                          @ronpfs said in Disable action does not work ?:

                                          @chudak said in Disable action does not work ?:

                                          How does permit outbound actually works ? (Need to think about it)

                                          That may contain some answers : https://docs.netgate.com/

                                          I am sure it does ! 😃

                                          Is Permit Outbound default setting for white lists ?

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.