• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

GeoIP not working? Where is rule?

Scheduled Pinned Locked Moved pfBlockerNG
4 Posts 3 Posters 990 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P
    patrick999
    last edited by Jul 16, 2022, 7:28 PM

    I have recently installed pfBlockerNG devel and am having a problem with GeoIP. I set it to deny inbound for every region except North America, where I am located, because I am running a small, limited-purpose web server for just two users and have a WAN port open. The problem is that I don't think GeoIP is actually blocking requests from outside North America. For one thing, there is no firewall rule created by pfBlockerNG for WAN, and the only floating rule is limited to LAN. So how could it possibly be blocking anything coming from outside North America or anywhere else since there are no associated firewall rules?

    Also, I looked in the web server log and could see that it received a request from the European region, so it appears that the WAN port is still open from all regions. (Incidentally, I do have a MaxMind license which I applied.)

    Does anyone have any thoughts about how to get this working? It seems something must be wrong with my setup.

    P S 2 Replies Last reply Jul 16, 2022, 9:08 PM Reply Quote 0
    • P
      patrick999 @patrick999
      last edited by Jul 16, 2022, 9:08 PM

      @patrick999 OK, I solved this on my own. I simply wasn't understanding the interface. I hadn't realized that selecting continents to block is insufficient. It's necessary to also choose specific countries within each continent. After I did that, the firewall rules were generated.

      1 Reply Last reply Reply Quote 0
      • ?
        A Former User
        last edited by Jul 16, 2022, 11:29 PM

        Perhaps nice to know for you too.
        pfBlockerNG MaxMind Registration required to continue to use the GeoIP functionality!

        1 Reply Last reply Reply Quote 0
        • S
          SteveITS Galactic Empire @patrick999
          last edited by Jul 17, 2022, 3:43 AM

          @patrick999 said in GeoIP not working? Where is rule?:

          I set it to deny inbound for every region except North America

          It should take less resources to do it the other way, allow North America. I usually use Alias Native and then can use it in my own rules, such as the Source on a NAT rule.

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote 👍 helpful posts!

          1 Reply Last reply Reply Quote 0
          1 out of 4
          • First post
            1/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received