Let's Encrypt and pfBlockerNG
-
Since Let's Encrypt (LE) does not advertise specific IP addresses and/or subnets or FQDNs which could be used to build exact allow rules for LE we regularly get into conflicts on sites where pfBlockerNG is running with GeoIP blocking enabled. Maybe the community has a solution here.
We basically want to achieve the following: Pass Let's Encrypt traffic when a certificate renewal takes place. Maybe this may be solved programmatically, we just don't have an idea how to realize it cleanly.
Thanks for your input!
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.