Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    GeoIP blockage not working

    Scheduled Pinned Locked Moved pfBlockerNG
    10 Posts 4 Posters 1.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      killmasta93
      last edited by

      Hi
      Currently im trying to get working the GeoIP blockage working, i created an account on maxmind and it downloaded correctly the IPs but on the dashboard i see this
      not sure what step i missed?
      8065173c-75af-4cb7-b03c-091b36239e8b-image.png

      82186f67-a80d-45f9-8aab-ca44aea1f417-image.png

      Tutorials:

      https://www.mediafire.com/folder/v329emaz1e9ih/Tutorials

      D 1 Reply Last reply Reply Quote 0
      • D
        darcey @killmasta93
        last edited by darcey

        @killmasta93 You have them set to 'Alias Deny'. In which case, in order to block traffic, you would need to define some firewall rules that target the generated aliases.
        You probably want one of the Deny options. Then pfblocker will also create the rules for you as well as the aliases.

        K 1 Reply Last reply Reply Quote 0
        • K
          killmasta93 @darcey
          last edited by

          @darcey Thanks for the reply, currently i have this
          ef236184-e891-4b7e-8fe0-b5a00598de6d-image.png

          Tutorials:

          https://www.mediafire.com/folder/v329emaz1e9ih/Tutorials

          johnpozJ D 2 Replies Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @killmasta93
            last edited by

            @killmasta93 not good practice to try and block the internet. Much easier to just allow the countries you want on the rules you want them to access, like your openvpn or port forward

            Just use the alias for the country you want to allow in those rules vs trying to block everything else on the planet other than what you want to allow.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            K 1 Reply Last reply Reply Quote 0
            • D
              darcey @killmasta93
              last edited by darcey

              @killmasta93 That looks like it should work. However something I just noticed in your pfblockerNG status screenshot: The 'Count' is empty for all but two of the aliases. I think that means those aliases are unpopulated.
              Check you actually have countries selected in those regions. Then run pfblocker update IP and check the log.
              Also, as @johnpoz says, you might want to take an allow (src address and dst port) rather than the deny approach with respect to exposing wan services.

              1 Reply Last reply Reply Quote 0
              • K
                killmasta93 @johnpoz
                last edited by

                @johnpoz
                thanks for the reply, currently testing it on a test environment, the idea is only to leave my country the rest to block the rest because its a website for only in our country.
                so whats your saying is something like creating inverse rule?
                ddd4e4ba-7517-455b-836f-da6ff07debd7-image.png

                Thank you

                Tutorials:

                https://www.mediafire.com/folder/v329emaz1e9ih/Tutorials

                johnpozJ P 2 Replies Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @killmasta93
                  last edited by

                  @killmasta93 no you would not use a inverse Bang as source. If all you want to allow is S America, then that would be the source.

                  By default all are deny, if you create a rule that says hey source SAmerica can access my port, and IP that is not in SAmerica list then that rule would not trigger and the traffic would just fall through your rule list to the default deny.

                  Here are my allowed traffic for example

                  allow.jpg

                  This is an alias that has a both US and since I have a friend in Morocco that as well, along some other IPs that I allow..

                  alias.jpg

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                  1 Reply Last reply Reply Quote 0
                  • P
                    Patch @killmasta93
                    last edited by Patch

                    @killmasta93
                    No, use two firewall rules

                    1. Allow your country
                    2. Then Block everything (else by rule order)
                    johnpozJ 1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator @Patch
                      last edited by

                      @patch yeah don't need a block, since it is default deny.. If traffic is not allowed it is denied, you only need a block and allow rule if you say want to allow IP to do something, but block all other to that whatever, but at the end say on your lan you have default allow any any rule.

                      On wan, since there is no default any any rule, all you need to do is limit what can access and by default anything that doesn't match that would be denied.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                      K 1 Reply Last reply Reply Quote 0
                      • K
                        killmasta93 @johnpoz
                        last edited by

                        @johnpoz
                        Thank you so much i think that did the trick

                        Tutorials:

                        https://www.mediafire.com/folder/v329emaz1e9ih/Tutorials

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.