Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Country IP Block

    Scheduled Pinned Locked Moved Firewalling
    10 Posts 6 Posters 3.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F Offline
      fajer67
      last edited by

      Hello,

      I'm using the VK-T40E and on 2.1.5-RELEASE and would like to know how I can configure Country IP blocks to block China, Korea and various other countries attempting to connect, I would want to do this in the GUI interface a step by step guide would be highly appreciated.

      1 Reply Last reply Reply Quote 0
      • jimpJ Offline
        jimp Rebel Alliance Developer Netgate
        last edited by

        The "country ip blocks" package is old/outdated and should be removed. It has been replaced by pfBlocker.

        The data in both of them is quite old, however, and not very accurate. pfBlocker would be better to try, there are other threads around with how-tos for setting that up.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • U Offline
          ukhost4u
          last edited by

          We actually had to remove pfBlocker from our 2.1.5 install as for some reason it started blocking all outbound traffic from our Lan. I'm not sure if pfBlocker has a bug with the latest version of pfsense.

          Paul.

          1 Reply Last reply Reply Quote 0
          • F Offline
            fajer67
            last edited by

            Hello jimp, first of all thanks for your response, would you happen to know if there actually is a bug in this version of pfBlocker as ukhost4u has stated ?

            Thanks very much

            1 Reply Last reply Reply Quote 0
            • jimpJ Offline
              jimp Rebel Alliance Developer Netgate
              last edited by

              I'm not aware of any bug like that. It may be possible to accidentally set pfBlocker to have more list items than your firewall is configured to allow, which would result in a failed ruleset load, but that can be fixed by increasing the allowed number of table entries under System > Advanced on the Firewall tab.

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • S Offline
                silliwk53
                last edited by

                It might also be possible that all of the countries were selected in each of the continent tabs and deny both or deny outbound was selected as the action to enforce.

                1 Reply Last reply Reply Quote 0
                • BBcan177B Offline
                  BBcan177 Moderator
                  last edited by

                  By any chance are you guys using pfBlocker with Squid as a proxy?

                  Some of the Block Lists can contain 127.0.0.1 which can cause issues.

                  "Experience is something you don't get until just after you need it."

                  Website: http://pfBlockerNG.com
                  Twitter: @BBcan177  #pfBlockerNG
                  Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                  1 Reply Last reply Reply Quote 0
                  • S Offline
                    silliwk53
                    last edited by

                    I am not utilizing Squid.  I am utilizing pfBlocker with action alias only and creating firewall rules on interfaces as needed.  I have not had any issues outside of the maximum table entries issue mentioned earlier in the thread which I was able to adjust and then all loaded appropriately.

                    1 Reply Last reply Reply Quote 0
                    • F Offline
                      fajer67
                      last edited by

                      Thank you all I found this an easy tutorial to initially setup and served my purpose for the "top spammers"

                      http://www.youtube.com/watch?v=XM9D7U2KCYU&feature=youtu.be&src_vid=mWaOasM6OR0&feature=iv&annotation_id=annotation_2437889699

                      1 Reply Last reply Reply Quote 0
                      • J Offline
                        Jamerson
                        last edited by

                        pfblock is working fine, on the new release,
                        this how to configure it
                        https://doc.pfsense.org/index.php/Pfblocker

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.