Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Firewall alias using multiple pfBlocker aliases

    Scheduled Pinned Locked Moved pfBlockerNG
    6 Posts 3 Posters 558 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      McMurphy
      last edited by

      Until now I have permitted firewall access to a single country using a pfBlocker alias in a FW rule.

      I now wish to permit access from multiple countries and have two pfBlocker aliases.
      pfB-Asia_v4
      pfB_Oceana_v4

      Rather than duplicate each FW rule, one for each alias I wanted to create a single FW alias that includes both bfBlocker aliases then I just need a single FW rule.

      Is this possible?

      When I tried to create a FW alias and include a pfBlocker alias I receive the following error:

      The following input errors were detected:
      The alias(es): pfB_Oceania_v4 cannot be nested because they are not of the same type.

      NogBadTheBadN S 2 Replies Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad @McMurphy
        last edited by NogBadTheBad

        @mcmurphy Do it via Firewall -> pfBlockerNG -> IP -> IPv4 and create a new entry and add all your GeoIP countries.

        You'd still need two aliases & rules if you use IPv4 & IPv6.

        Screenshot 2022-12-19 at 13.56.06.png

        Screenshot 2022-12-19 at 13.59.17.png

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        M 1 Reply Last reply Reply Quote 0
        • S
          SteveITS Galactic Empire @McMurphy
          last edited by

          @mcmurphy You might try creating the country lists as Alias Native and see if that works. With Alias Native pfB just creates the aliases and you can add your own rules.

          I would think "of the same type" means a URL alias vs a host alias (?) but I would have thought they were the same in this usage since pfB is creating both.
          https://docs.netgate.com/pfsense/en/latest/firewall/aliases.html#nesting-aliases

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote ๐Ÿ‘ helpful posts!

          1 Reply Last reply Reply Quote 0
          • M
            McMurphy @NogBadTheBad
            last edited by

            @nogbadthebad

            Thanks. My UI looks different and I do not have the GeoIP option in the dropdown?
            pfbWhiteliost.png

            S 1 Reply Last reply Reply Quote 0
            • S
              SteveITS Galactic Empire @McMurphy
              last edited by

              @mcmurphy You likely have the older pfBlocker not pfBlocker-devel. The former doesnโ€™t seem to be updated anymore and the package maintainer has posted to use the devel version. Despite the name.

              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
              Upvote ๐Ÿ‘ helpful posts!

              M 1 Reply Last reply Reply Quote 0
              • M
                McMurphy @SteveITS
                last edited by

                @steveits
                That'll be it. I was not using the devel version.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.