Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to create a PTR Record rule?

    Firewalling
    2
    4
    484
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      somerino
      last edited by

      I know you can create an ALIAS for one specific URL. But for example Teamviewer is using multiple subdomains: *.teamviewer.com
      How do I create a rule for something like that?

      Thanks for your help!

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @somerino
        last edited by johnpoz

        @wellcomefit your trying to block all access to anything.teamviewer.com ? That would not really be possible with an alias.. How could you possible resolve any and all possible combinations of anything.domain.tld

        You could prevent anything.domain.tld resolving for the client if using pfsense as their dns, so they wouldn't know what IP to go to - if that your goal. But there would be no way to populate a alias with IPs for anything.domain.tld - the combinations are almost infinite, etc.

        Are you trying to whitelist so clients could only go to something.teamviewer.com ? Possible solution there would be to find out what ASN, ie the network they are using to host.. And then using pfblocker you could easy find all the ips/networks used by that ASN.. And then use that alias in an allow list, etc.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        S 1 Reply Last reply Reply Quote 0
        • S
          somerino @johnpoz
          last edited by

          @johnpoz Thanks for your reply.

          I'm trying to whitelist anything.teamviewer.com for Port 5389 TCP/UDP.
          What is an ASN? I never used pfblocker. So this extension is capable of creating an allow list of all IP addresses which are owned by teamviewer?

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @somerino
            last edited by johnpoz

            @wellcomefit ASN is Autonomous System Number, this is what defines a group of IP prefixes..

            But teamviewer could be honestly pretty much anywhere on the planet from here.

            https://www.teamviewer.com/en-us/trust-center/faq/ with pretty much all the major CDNs

            So that pretty much wouldn't do you much good.. whitelisting *.teamviewer.com would be what you do when you use a proxy, not a firewall. For that just open up port 5389.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.