• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

PFBlockerNG Bypass for specific IP address

Scheduled Pinned Locked Moved Firewalling
6 Posts 3 Posters 4.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    slbailey617
    last edited by Aug 18, 2021, 5:57 PM

    I have enabled pfblocker with ad blocking, etc. on my network. Works great...

    Except for one thing... The wife plays a game on her iPad that gives her benefits by watching ads.

    Is there a way I can bypass her ad blocking on the specific IP address of her iPad?

    I see where I can whitelist certain domains but short of sniffing the wire while she's playing I can't find all the domains they route you to.

    Plus I really don't want to enable those domains on every device. I'd rather lock her workstation down to a specific IP address and allow her to bypass pfblocker.

    Ideas?

    A 1 Reply Last reply Aug 18, 2021, 7:27 PM Reply Quote 0
    • A
      awebster @slbailey617
      last edited by Aug 18, 2021, 7:27 PM

      @slbailey617 After you've locked the device to a specific IP (DHCP reservation or static IP), you will need to change the default pfBlocker rule Order so that you can have your own rules before any pfBlocker rules, and then put a LAN firewall rule to allow her device's IP access to the Internet before any pfBlocker rules

      –A.

      S 1 Reply Last reply Aug 18, 2021, 7:32 PM Reply Quote 0
      • S
        slbailey617 @awebster
        last edited by Aug 18, 2021, 7:32 PM

        @awebster I'm not seeing the PFBlocker rules for the DNSBL groups... That's the only rule I want to override for her IP... Don't DNSBL any requests from her IP.

        A 1 Reply Last reply Aug 18, 2021, 7:52 PM Reply Quote 0
        • A
          awebster @slbailey617
          last edited by Aug 18, 2021, 7:52 PM

          @slbailey617 Sorry I missed the DNSBL part. DNSBL will return the virtual blacklisted IP to the clients who request a blocked domain, so rules won't help here.
          An easier mechanism might be to provide alternate DNS servers for that one client, ie: use 8.8.8.8 instead of the pfSense DNS service.

          –A.

          1 Reply Last reply Reply Quote 1
          • U
            Uglybrian
            last edited by Aug 21, 2021, 12:38 PM

            Hi, you can also add the static ip to the DNSBL Python Group Policy.Screenshot from
2021-08-21 05-36-12.png

            S 1 Reply Last reply Aug 21, 2021, 12:43 PM Reply Quote 0
            • S
              slbailey617 @Uglybrian
              last edited by Aug 21, 2021, 12:43 PM

              @uglybrian I like this solution better. I will try this and see if it works.

              1 Reply Last reply Reply Quote 0
              6 out of 6
              • First post
                6/6
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received