Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfblocker IP list bypass

    General pfSense Questions
    4
    20
    1.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S
      stephenw10 Netgate Administrator
      last edited by

      If you set it as block in pfBlocker does the rule get created?

      I don't see that custom list in the update logs...

      M 1 Reply Last reply Reply Quote 0
      • M
        michmoor LAYER 8 Rebel Alliance @stephenw10
        last edited by

        @stephenw10 It does not.

        43cd3ed9-2a04-4d95-87e9-5ea9cd761805-image.png

        debc8d39-0ef4-44d2-b696-7b7723f8fe9b-image.png

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          Ok, so it's probably not populating the list. Or it's not enabled or similar.

          M 1 Reply Last reply Reply Quote 0
          • M
            michmoor LAYER 8 Rebel Alliance @stephenw10
            last edited by

            @stephenw10 Yeah for some reason it just doesnt see the custom group. I'll open a redmine

            Also i do have an Ports Alias that i use in an Inbound Firewall rule in conjunction wtih GeoIP thats processed without issue.

            1ec12502-0888-4b05-8e18-7f0e370ba1c4-image.png

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              This seems like it might just be the list isn't configured correctly. What is in that list apart from the custom firewall source?

              M 1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                Yes, in fact re-reading this it looks like you might have created an empty list and just added the alias the firewall rules section as a source to use?
                That won't create any rules since nothing is actually listed.

                You probably want to add the IPs directly in the 'IPv4 Custom_List' section.

                M 1 Reply Last reply Reply Quote 1
                • M
                  michmoor LAYER 8 Rebel Alliance @stephenw10
                  last edited by

                  This post is deleted!
                  1 Reply Last reply Reply Quote 0
                  • M
                    michmoor LAYER 8 Rebel Alliance @stephenw10
                    last edited by michmoor

                    @stephenw10 Ok I see what you mean now. My logic was faulty.
                    But when i add it to the custom IPv4 list those IPs show up as Destinations. I suppose setting it to Alias Native would work but anyway to have the IPs listed in my field set to source

                    EDIT: Figured it all out...
                    Going out for a drink. haha.
                    @stephenw10 @SteveITS Appreciate yall

                    EDIT2: For future me or anyone else who looks back at this.

                    1. Create the custom group with the IPv4 Custom_List IPs.
                    2. Set to Alias Permit
                    3. Under Floating Rules , create a Pass rule.
                    4. Set the Firewall Auto Rule Order to pfSense Pass...
                    5. Adjust accordingly.

                    My rule is at the top exactly where I needed it to be.

                    9a6ebcb0-2a76-4f91-8701-522ab73f25d5-image.png

                    1 Reply Last reply Reply Quote 1
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      Yup, that's probably how you'd have to do it.

                      My only concern there is that the pfBlocker auto-rules might get moved above that when they are reloaded. You should check that.

                      M 1 Reply Last reply Reply Quote 0
                      • M
                        michmoor LAYER 8 Rebel Alliance @stephenw10
                        last edited by

                        @stephenw10 Still at the top of the rule set.

                        I made sure to make the following change overnight.

                        fc6d16b2-98c7-4fa1-8dab-36fd1a8f4ea0-image.png

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.