• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Issue with pfBlocker GEOIP

pfBlockerNG
4
11
1.0k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • A
    Abramelin
    last edited by Feb 9, 2024, 11:20 PM

    Hello, guys!
    Can someone help me with this issue?
    The problem is that I'm trying to add countries in GEOIP block and enable it, but when I click on the IP tab and IPV4, this tab doesn't show the rules to be enabled.
    🔒 Log in to view
    🔒 Log in to view
    🔒 Log in to view

    I have checked the list of the GEOIPs using /usr/local/share/GeoIP/cc/, and I can see that some lists have no IP inside. So, I think that my issue is at this step, but I don't know how to force this update properly or if something in my firewall is blocking any MaxMind repository.

    I'm thinking of excluding all files from /usr/local/share/GeoIP/cc/ and trying to recreate it again with cron.

    Have you guys already faced this issue? If the answer is yes, what was the solution that you applied to it?

    J 1 Reply Last reply Feb 10, 2024, 12:04 AM Reply Quote 0
    • J
      johnpoz LAYER 8 Global Moderator @Abramelin
      last edited by johnpoz Feb 10, 2024, 12:07 AM Feb 10, 2024, 12:04 AM

      @Abramelin Not exactly sure what your hoping to accomplish.. But little advice, its much easier to allow than to try and block everything else..

      I use geoip aliases to allow inbound into my services I have open to the public, but I limit it to US ips.. and some others that I have created.

      This is much smaller list than trying to block the planet.

      🔒 Log in to view

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

      A 1 Reply Last reply Feb 10, 2024, 1:30 AM Reply Quote 0
      • A
        Abramelin @johnpoz
        last edited by Feb 10, 2024, 1:30 AM

        @johnpoz Thanks sir i will do that!

        S 1 Reply Last reply Feb 10, 2024, 2:08 AM Reply Quote 0
        • S
          SteveITS Galactic Empire @Abramelin
          last edited by Feb 10, 2024, 2:08 AM

          @Abramelin I’d think this problem would apply to pfBlocker as well:
          https://forum.netgate.com/topic/186065/heads-up-new-suricata-7-0-3-package-is-coming-soon
          …might need an update to it.

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote 👍 helpful posts!

          T 1 Reply Last reply Feb 28, 2024, 8:53 AM Reply Quote 0
          • T
            tieskekiggen @SteveITS
            last edited by Feb 28, 2024, 8:53 AM

            @SteveITS
            I have the same issue as the TS with GeoIP.
            The link to the post you sent gives me access denied even though I am logged into the forum.
            🔒 Log in to view
            What was the problem/fix given therein?
            Thanks in advance!

            J 1 Reply Last reply Feb 28, 2024, 10:36 AM Reply Quote 0
            • J
              johnpoz LAYER 8 Global Moderator @tieskekiggen
              last edited by Feb 28, 2024, 10:36 AM

              @tieskekiggen that post was deleted because it was release, here is the release notes

              https://forum.netgate.com/topic/186071/suricata-package-v7-0-3-available-here-are-the-release-notes

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              T 1 Reply Last reply Feb 28, 2024, 11:03 AM Reply Quote 0
              • T
                tieskekiggen @johnpoz
                last edited by Feb 28, 2024, 11:03 AM

                @johnpoz
                Thanks for the reply.
                But I don't think that is the issue because the lists are downloading to the system and contain IP information.
                🔒 Log in to view
                It seems to be an issue in pfBlocker.
                This is a fresh installation of pfBlocker on the machine.
                I've put all continents on deny inbound except Europe.
                🔒 Log in to view
                After an update/reload the aliases for the continents are not created, but the default block list is working.
                🔒 Log in to view
                Any idea what it could be?

                J 1 Reply Last reply Feb 28, 2024, 11:30 AM Reply Quote 0
                • J
                  johnpoz LAYER 8 Global Moderator @tieskekiggen
                  last edited by Feb 28, 2024, 11:30 AM

                  @tieskekiggen I already went over my suggestion.. You shouldn't be trying to block the world.. If all you want to allow is EU, then just allow that..

                  There is little point to blocking the whole planet, when there is a default deny.. If you do not allow it, its blocked anyway. Create your rules with the allow in them. See my screenshot above.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                  T 1 Reply Last reply Feb 28, 2024, 11:42 AM Reply Quote 0
                  • T
                    tieskekiggen @johnpoz
                    last edited by Feb 28, 2024, 11:42 AM

                    @johnpoz
                    Yes I understand that, when I get it working, I will implement it differently too. This was purely for testing.
                    But the problem I am running into now is that the aliases it is supposed to create are not creating.
                    Hence my question as to how it could be that it doesn't work.
                    It seems to be nothing with the MaxMind license because I see the downloaded files in the /usr/local/share/GeoIP folder. Only pfBlocker is not creating the needed aliases.

                    J 1 Reply Last reply Feb 28, 2024, 11:54 AM Reply Quote 0
                    • J
                      johnpoz LAYER 8 Global Moderator @tieskekiggen
                      last edited by Feb 28, 2024, 11:54 AM

                      @tieskekiggen look in your table to validate the alias is populated.

                      🔒 Log in to view

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                      T 1 Reply Last reply Feb 28, 2024, 12:18 PM Reply Quote 0
                      • T
                        tieskekiggen @johnpoz
                        last edited by Feb 28, 2024, 12:18 PM

                        @johnpoz
                        Found the issue, I didn't choose the countries within the continent.
                        Therefore, it was not creating the alias.
                        Thanks for your quick responses anyway!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.