Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    GeoIP Rules Missing

    pfBlockerNG
    3
    21
    2.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      Spyderturbo007
      last edited by

      I setup pfBlocker for a friend of mine and I appear to be missing the GeoIP rules. I have the Maxmind key setup, but the rules named pfB_Asia, pfB_Europe, etc are all missing.

      Is there a way for me to get pfBlocker to recreate the firewall rules?

      S 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @Spyderturbo007
        last edited by

        @spyderturbo007 After you set up the feeds you need to run an update in pfB, to generate the aliases.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote 👍 helpful posts!

        S 1 Reply Last reply Reply Quote 0
        • S
          Spyderturbo007 @SteveITS
          last edited by

          @steveits I went to pfBlockerNG -> Update and hit the Run button. It went through the update and said finished, but there still aren't any GeoIP rules.

          I'm not sure what I'm doing wrong?

          Thank you!

          Here is what his shows:

          Firewall Rules.PNG GeoIP Summary.PNG

          And this is what mine shows.

          My pfSense.PNG

          S 1 Reply Last reply Reply Quote 0
          • S
            SteveITS Galactic Empire @Spyderturbo007
            last edited by

            @spyderturbo007 Since this is WAN2, do you have WAN2 selected on:
            54c3a8e2-091a-434d-8a19-b8d09b76fb09-image.png

            Are the aliases created if you look in Diagnostics/Tables?

            Alternately, I usually set up pfBlocker to use Alias Native, and then create my own rules in the order I want.

            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
            Upvote 👍 helpful posts!

            S 1 Reply Last reply Reply Quote 0
            • S
              Spyderturbo007 @SteveITS
              last edited by

              @steveits The tables do not appear in Diagnostics -> Tables. I do have WAN2 selected. Thank you for the help.

              Netgate Tables.PNG

              Netgate Configuration.PNG

              S 1 Reply Last reply Reply Quote 0
              • S
                SteveITS Galactic Empire @Spyderturbo007
                last edited by

                @spyderturbo007 What does your pfBlocker log say for an update?

                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                Upvote 👍 helpful posts!

                S 1 Reply Last reply Reply Quote 0
                • S
                  Spyderturbo007 @SteveITS
                  last edited by

                  @steveits Is this what you need? This was from yesterday, when you said that I should run the update.

                  Thank youpfBlocker Update Log.txt

                  S 1 Reply Last reply Reply Quote 0
                  • S
                    SteveITS Galactic Empire @Spyderturbo007
                    last edited by

                    @spyderturbo007 Well the GeoIP section is empty. Do you have the MaxMind key set up?

                    Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                    When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                    Upvote 👍 helpful posts!

                    S 1 Reply Last reply Reply Quote 0
                    • S
                      Spyderturbo007 @SteveITS
                      last edited by Spyderturbo007

                      @steveits said in GeoIP Rules Missing:

                      @spyderturbo007 Well the GeoIP section is empty. Do you have the MaxMind key set up?

                      @SteveITS I do. I generated a key and entered it just as I did with mine.

                      MaxMind.PNG

                      S 1 Reply Last reply Reply Quote 0
                      • S
                        SteveITS Galactic Empire @Spyderturbo007
                        last edited by

                        @spyderturbo007 Did you (have to) put in the patch for the new key format?

                        https://forum.netgate.com/topic/179107/maxmind-licence-key-problem

                        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                        Upvote 👍 helpful posts!

                        P S 2 Replies Last reply Reply Quote 0
                        • P
                          pfsjap @SteveITS
                          last edited by

                          @steveits I think the patch you mentioned is included in pfBlockerNG 3.2.0_4.

                          S 1 Reply Last reply Reply Quote 0
                          • S
                            Spyderturbo007 @SteveITS
                            last edited by Spyderturbo007

                            @steveits @pfsjap Thank you for the help.

                            I am running 3.2.0_4 with a key that was generated in the old format. I generated a new key in the new format and then ran the Reload (All) and am attaching the new log file. I also did an Update which didn't appear to do anything either.

                            Update.txt

                            Reload.txt

                            1 Reply Last reply Reply Quote 0
                            • S
                              SteveITS Galactic Empire @pfsjap
                              last edited by

                              @pfsjap said in GeoIP Rules Missing:

                              @steveits I think the patch you mentioned is included in pfBlockerNG 3.2.0_4.

                              Oh! Did not realize a new version was out sorry.

                              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                              Upvote 👍 helpful posts!

                              S 1 Reply Last reply Reply Quote 0
                              • S
                                Spyderturbo007 @SteveITS
                                last edited by

                                @steveits @pfsjap Any other ideas on how to get this working?

                                S P 2 Replies Last reply Reply Quote 0
                                • S
                                  SteveITS Galactic Empire @Spyderturbo007
                                  last edited by

                                  @spyderturbo007 If you edit one of the continents, are any countries selected?

                                  One can also create a list manually like so:
                                  c2dbe7cf-bd2a-4314-91e8-2fd42ad7158d-image.png

                                  I just updated our office router (on 2.6) to the _4 version and it updates fine.

                                  Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                  When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                                  Upvote 👍 helpful posts!

                                  1 Reply Last reply Reply Quote 0
                                  • P
                                    pfsjap @Spyderturbo007
                                    last edited by

                                    @spyderturbo007 My set up is similar to what @steveits showed above.

                                    S 1 Reply Last reply Reply Quote 0
                                    • S
                                      Spyderturbo007 @pfsjap
                                      last edited by

                                      @pfsjap @SteveITS Unfortunately that screen is different on the one I'm trying to fix.

                                      Here are some screenshots showing that screen, the Maxmind account and the screen in pfsense. I even tried generating a key in my account and adding it to his netgate. That didn't work either.

                                      Thank you for the continued help. I really want to get this working.

                                      pfSense.PNG

                                      License.PNG

                                      pfSense License Key.PNG

                                      S 1 Reply Last reply Reply Quote 0
                                      • S
                                        SteveITS Galactic Empire @Spyderturbo007
                                        last edited by

                                        @spyderturbo007 If you click the pencil to the right of the PRI1 line, to edit it, you'll see the page I showed.
                                        c9bd69c1-61e4-4a5b-8d73-5d709d0da264-image.png

                                        Ensure they are On:
                                        c9f8cd18-df13-45c1-9cde-4c1f607bc072-image.png

                                        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                                        Upvote 👍 helpful posts!

                                        S 1 Reply Last reply Reply Quote 0
                                        • S
                                          Spyderturbo007 @SteveITS
                                          last edited by

                                          @steveits They are all showing as "ON".

                                          pfSense - 1.PNG

                                          S 1 Reply Last reply Reply Quote 0
                                          • S
                                            Spyderturbo007 @Spyderturbo007
                                            last edited by

                                            @SteveITS Any other thoughts? I'm still stuck on this issue.

                                            S 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.