• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Firewall rule only for google recaptcha

Firewalling
2
4
3.7k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    SipriusPT
    last edited by Aug 2, 2021, 1:52 PM

    Hello everyone,

    I am trying to allow only google recaptcha without having to allow all or most google services (through google.com or www.google.com), to be used on a subnet that all internet is blocked, except certain websites.

    Anyone here, have a rule recipe for google recaptcha?

    Thanks in advance!

    1xSG-4860-1U
    1xSG-3100
    2xpfSense Virtual Machines

    G 1 Reply Last reply Aug 3, 2021, 10:28 AM Reply Quote 0
    • G
      Gertjan @SipriusPT
      last edited by Aug 3, 2021, 10:28 AM

      @sipriuspt said in Firewall rule only for google recaptcha:

      google recaptcha

      The "google recaptcha" is a script that runs on your web server. It uses a FQDN to access the Google's "google recaptcha" services.

      Using this FQDN as an alias, and use that alias as a with a pass rule probably won't work well, as this FQDN can point to many IP addresses.

      So, you mission is, if you accept it, is to find out what all these IP addresses are, put them in an aliases, and use that alias in your firewall rule.

      edit : Oops : https://www.google.com/recaptcha/api/ ..... "google.com" has thousands (more) IP's ...

      Btw : as you might have guessed / already know : firewall rules work only with IP addresses, not host names.

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      S 1 Reply Last reply Aug 3, 2021, 11:25 AM Reply Quote 1
      • S
        SipriusPT @Gertjan
        last edited by SipriusPT Aug 3, 2021, 11:26 AM Aug 3, 2021, 11:25 AM

        @gertjan The fact that they didnt dedicate a hand of IPs or even a sub DN or a DN dedicated to recaptchas, it turns filtering google recaptchas a real pain in the a**, through firewall rules.

        1xSG-4860-1U
        1xSG-3100
        2xpfSense Virtual Machines

        G 1 Reply Last reply Aug 3, 2021, 1:46 PM Reply Quote 0
        • G
          Gertjan @SipriusPT
          last edited by Gertjan Aug 3, 2021, 1:50 PM Aug 3, 2021, 1:46 PM

          @sipriuspt

          Google captchas functionality is put in place by an web server admin.
          Using other words : if you install a captcha on a web server, it needs an access to Google's API.
          It will not visit other web sites.
          So, why (firewall) filter connections initiated by a web server itself ??
          You - the admin - control the web server. It's not some device with controlled by a a person.

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          1 Reply Last reply Reply Quote 0
          1 out of 4
          • First post
            1/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.