Country Block
-
Country Block sounds great and I really want to use it. I'm running pfSense 2.0 RC-1 and it is working great. But I've read that some people have had problems when they try to upgrade to another snapshot of 2.0. I do realize it's hard to code with consistency for somersetting else that is always changing.
Is there any new one way or the other that you can add about this as of today (May 10th)? I really want to try it.
Thanks!
There is no reason why you can't install it and try it. If it doesn't work, it doesn't work. It doesn't break anything or mess with your install at all.
My money says that it will work just fine, in fact I guarantee that it works! -
Confidence! I like that.
My concern is when I update to a newer snapshot. That's when I'm afraid that I'll have problems. I've read a few things here and there in different places in the forum. I just can't afford to be down while trying to fix stuff after having Country Block installed and then upgrading to a newer snapshot. That's my concern.
I'm not as smart as the rest of the guys in this forum!
-
Confidence! I like that.
My concern is when I update to a newer snapshot. That's when I'm afraid that I'll have problems. I've read a few things here and there in different places in the forum. I just can't afford to be down while trying to fix stuff after having Country Block installed and then upgrading to a newer snapshot. That's my concern.
I'm not as smart as the rest of the guys in this forum!
I could see that for one of my other packages (ip-blocklist since it requires perl and perl doesn't install properly some times) but countryblock only uses php which mean there is no difference in the countryblock that runs on 1.2.3 and the latest BETA.
So based on that it will work on any version including future version.The only down side from upgrades will be loosing your configuration settings or your country selection. So what forum posts are giving you concern?
-
I don't recall what other forum posts I saw this in. They are all over the place. You need your own division or top. Maybe it's the config that I recall people losing. That's no problem and would be easy to redo.
It sounds great! Do you know if it requires a reboot when it's installed?
Thank you for your time!
-
Another dumb question…
After I install Country Block, I'm blocking all of the countries you have listed as top spammers. You made it easy, because those are the countries I do want to block.
I do have a few clients that correspond with people in the countries I want to block because these people do programming for them. How do I go about blocking the country yet allowing a few specific IPs access to our network?
Again, thanks for your time.
-
There is no reason why you can't install it and try it. If it doesn't work, it doesn't work. It doesn't break anything or mess with your install at all.
My money says that it will work just fine, in fact I guarantee that it works!Or your money back!
:)
-
@Bai:
There is no reason why you can't install it and try it. If it doesn't work, it doesn't work. It doesn't break anything or mess with your install at all.
My money says that it will work just fine, in fact I guarantee that it works!Or your money back!
:)
Not like someone can't easily backup their current configuration, and at worse, reinstall pfsense…easy as all get out with minimal time. This isn't a Windows Server rebuild...
-
You're correct about reinstalling pfSense. It's fast and easy. The problem is that the data center is a 45 minute drive (one way) from where I'm located.
I'm hoping to have the ability to install County Block yet allow specific IPs from banned countries access. I have a few clients that have people in those countries that do programming and they need to have access to their sites.
-
You're correct about reinstalling pfSense. It's fast and easy. The problem is that the data center is a 45 minute drive (one way) from where I'm located.
I'm hoping to have the ability to install County Block yet allow specific IPs from banned countries access. I have a few clients that have people in those countries that do programming and they need to have access to their sites.
Just bustin' your chops…I understand. Being an IT one has to be sure before making willy-nilly decisions. I've been using Country Block since its inception and it is awesome, in fact it is the reason I started pfsense. I prefer the 1.2.3 version as it is solid. As far as your questions about specific IPs...that would be a cool feature but I haven't seen it implemented yet. I'm still trying to figure out why the email doesn't work effectively. Hmm. Good luck mate!
-
Another dumb question…
After I install Country Block, I'm blocking all of the countries you have listed as top spammers. You made it easy, because those are the countries I do want to block.
I do have a few clients that correspond with people in the countries I want to block because these people do programming for them. How do I go about blocking the country yet allowing a few specific IPs access to our network?
Again, thanks for your time.
Take a look at the whitelist tab.
-
Take a look at the whitelist tab.
Damn…even comes with an example... I'll just go back to that email tab...
-
Damn, I do feel like an idiot!
I guess I should have installed it and asked questions later!
Duh!
Thanks!
-
Hi,
few more questions.
Is the IP address list updated automatically?
If not where are the files located for me to edit?
If I were to try to edit I noticed that countryipblocks.net format is x.x.x.x/sn.
I ask because I had someone spam one of my forums I host. Their IP was in the Ukraine, but was not on the list from that website. I have the person's IP address but I dont think theres any way for me to tell the subnet.
Any insight?
-
Hi,
few more questions.
Is the IP address list updated automatically?
If not where are the files located for me to edit?
If I were to try to edit I noticed that countryipblocks.net format is x.x.x.x/sn.
I ask because I had someone spam one of my forums I host. Their IP was in the Ukraine, but was not on the list from that website. I have the person's IP address but I dont think theres any way for me to tell the subnet.
Any insight?
What's the IP?
-
At this point I dont recall. :(
-
Hey Tommyboy180
Don't you love it when we can't remember? I know you have to just shake your head.
-
I banned the previous user from my forum which deleted any information pertaining to the IP address. However a new spammer registered and i ran an ARIN lookup on his IP address. It comes from this CIDR block in Denmark: 91.0.0.0/8
Obviously its not in the list, how do I add this block to my list manually? Where are the files for the lists located?
Thanks in advance!
-
I banned the previous user from my forum which deleted any information pertaining to the IP address. However a new spammer registered and i ran an ARIN lookup on his IP address. It comes from this CIDR block in Denmark: 91.0.0.0/8
Obviously its not in the list, how do I add this block to my list manually? Where are the files for the lists located?
Thanks in advance!
Take a look at the denmark country at http://www.countryipblocks.net/country-blocks/select-formats/. This list is the one I have in the package. From what I can tell most of 91 is in there.
The entire 91.0.0.0/8 block does not belong to Denmark. Denmark only has a few networks out of that range. The EU also uses 91 as well as Russia. Therefore you need to find exactly what country that IP belongs to and block that country.
-
Just a quick "Thank You, Tommy!" Package seems to run smoothly on RC1 embedded now (tested for a couple of days now, survived test reboot, rule changes, and pppoe dialups). Just did a plain install, no manual cron jobs or anything.
Best
Georg -
@ghm:
Just a quick "Thank You, Tommy!" Package seems to run smoothly on RC1 embedded now (tested for a couple of days now, survived test reboot, rule changes, and pppoe dialups). Just did a plain install, no manual cron jobs or anything.
Best
GeorgGlad to hear it! I am constantly working on this package and other packages (even some future releases to come).
If you like it that much consider donating at http://tomschaefer.org/pfsense/