Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Specific allow rule GeoIP for specific country

    Scheduled Pinned Locked Moved pfBlockerNG
    3 Posts 2 Posters 524 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H Offline
      houseofdreams
      last edited by

      Hi. I have an IoT device in my house, connected to the outside so I can manage this device from anywhere on my phone.

      I now want to limit the access to this NAT rule, to only all IP's from my country, to be a bit safer.

      I have the PfBlocker package installed, which has GeoIP databases, but I can't seem to find a solution to make a firewall rule that does this, maybe it's not possible to do this to 1 specific firewall rule?

      In short: only allow access from country X to NAT rule Y

      Any help appreciated!

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ Offline
        johnpoz LAYER 8 Global Moderator @houseofdreams
        last edited by johnpoz

        Just whatever country IP alias you want in your nat rule as the source..

        Example..

        Here is alias I created that contains a couple of lists, and US as country. that allows access to my plex server

        rules.png

        I moved your thread to the pfblocker section - more appropriate for that area..

        Not sure what iot devices you have - but you really should not have to port forward anything for those. I control many lights and smart switches etc from anywhere.. And zero port forwards required because the iot devices phone home.. And you control them via that connection.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

        1 Reply Last reply Reply Quote 0
        • H Offline
          houseofdreams
          last edited by

          Thanks for the quick reply :)

          I don't know if IoT is the exact category, it's older home automation hardware from 10 years ago, that isn't that clever. It did cost a few pennies, so upgrading it won't be an option for a while.

          I will use your solution for now, and maybe contact the manufacturer (or by asking on their forum) if there is a better/safer option to be able to control it from the outside.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.