Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Firewall alias using multiple pfBlocker aliases

    Scheduled Pinned Locked Moved pfBlockerNG
    6 Posts 3 Posters 691 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      McMurphy
      last edited by

      Until now I have permitted firewall access to a single country using a pfBlocker alias in a FW rule.

      I now wish to permit access from multiple countries and have two pfBlocker aliases.
      pfB-Asia_v4
      pfB_Oceana_v4

      Rather than duplicate each FW rule, one for each alias I wanted to create a single FW alias that includes both bfBlocker aliases then I just need a single FW rule.

      Is this possible?

      When I tried to create a FW alias and include a pfBlocker alias I receive the following error:

      The following input errors were detected:
      The alias(es): pfB_Oceania_v4 cannot be nested because they are not of the same type.

      NogBadTheBadN S 2 Replies Last reply Reply Quote 0
      • NogBadTheBadN Offline
        NogBadTheBad @McMurphy
        last edited by NogBadTheBad

        @mcmurphy Do it via Firewall -> pfBlockerNG -> IP -> IPv4 and create a new entry and add all your GeoIP countries.

        You'd still need two aliases & rules if you use IPv4 & IPv6.

        Screenshot 2022-12-19 at 13.56.06.png

        Screenshot 2022-12-19 at 13.59.17.png

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        M 1 Reply Last reply Reply Quote 0
        • S Offline
          SteveITS Galactic Empire @McMurphy
          last edited by

          @mcmurphy You might try creating the country lists as Alias Native and see if that works. With Alias Native pfB just creates the aliases and you can add your own rules.

          I would think "of the same type" means a URL alias vs a host alias (?) but I would have thought they were the same in this usage since pfB is creating both.
          https://docs.netgate.com/pfsense/en/latest/firewall/aliases.html#nesting-aliases

          Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
          Upvote 👍 helpful posts!

          1 Reply Last reply Reply Quote 0
          • M Offline
            McMurphy @NogBadTheBad
            last edited by

            @nogbadthebad

            Thanks. My UI looks different and I do not have the GeoIP option in the dropdown?
            pfbWhiteliost.png

            S 1 Reply Last reply Reply Quote 0
            • S Offline
              SteveITS Galactic Empire @McMurphy
              last edited by

              @mcmurphy You likely have the older pfBlocker not pfBlocker-devel. The former doesn’t seem to be updated anymore and the package maintainer has posted to use the devel version. Despite the name.

              Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
              Upvote 👍 helpful posts!

              M 1 Reply Last reply Reply Quote 0
              • M Offline
                McMurphy @SteveITS
                last edited by

                @steveits
                That'll be it. I was not using the devel version.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.