Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfBlockerNG

    Scheduled Pinned Locked Moved pfBlockerNG
    1.2k Posts 210 Posters 1.8m Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      marcus556
      last edited by

      So I just tried to use TeamViewer and Pfblockerng is blocking it.  Not sure what list but don’t want to disable the whole list just for TeamViewer, so I went in and added www.teamviewer.com into the alias list and it still isn’t working.  I figured I added the wrong thing so I thought I would come here and ask if anyone knows how to add TeamViewer to the alias list and keep it from being blocked?

      1 Reply Last reply Reply Quote 0
      • D
        doktornotor Banned
        last edited by

        Generic hint: Only use such blocklists that fit your needs and that you are able to manage…

        1 Reply Last reply Reply Quote 0
        • S
          Supermule Banned
          last edited by

          Why not push the pass of teamviewer to the top of the list so it doesnt hit the block list before the passlist?? ;)

          1 Reply Last reply Reply Quote 0
          • M
            marcus556
            last edited by

            @Supermule:

            Why not push the pass of teamviewer to the top of the list so it doesnt hit the block list before the passlist?? ;)

            Where exactly do I go to do that?  I still very new with pfsense so please bare with me…

            1 Reply Last reply Reply Quote 0
            • BBcan177B
              BBcan177 Moderator
              last edited by

              @marcus556:

              So I just tried to use TeamViewer and Pfblockerng is blocking it.

              You need to look at the Alerts Tab and see which List is blocking it.
              I came across this issue before with TeamViewer and for that case, it was being blocked by a Country Block.. (One of the Top20)

              You also can't use an alias in the Custom Input settings. They have to be IP addresses.

              Try to ping www.teamviewer.com from your desktop and take a look for what is blocking it in the Alerts Tab.

              "Experience is something you don't get until just after you need it."

              Website: http://pfBlockerNG.com
              Twitter: @BBcan177  #pfBlockerNG
              Reddit: https://www.reddit.com/r/pfBlockerNG/new/

              1 Reply Last reply Reply Quote 0
              • M
                marcus556
                last edited by

                @doktornotor:

                Generic hint: Only use such blocklists that fit your needs and that you are able to manage…

                Its actually one of the Top 20 sites that is blocking it not one of the list I imported..

                1 Reply Last reply Reply Quote 0
                • BBcan177B
                  BBcan177 Moderator
                  last edited by

                  Add that Blocked IP to a Whitelist Alias. I described how to do that in a post this morning.

                  "Experience is something you don't get until just after you need it."

                  Website: http://pfBlockerNG.com
                  Twitter: @BBcan177  #pfBlockerNG
                  Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                  1 Reply Last reply Reply Quote 0
                  • D
                    DickB
                    last edited by

                    Something I found out the hard way  :), if you comment an IP address/range in IPv4 Custom Address(es) with a #, then it is still active.
                    For some tests I added the Google address range to an alias list.

                    74.125.0.0/16    # 1e100.net - (Google)

                    Then I commented it after the testing for later use.
                    This worked fine in pfBlocker but when I moved the alias list to pfBlockerNG my Nexus 7 could not connect to Google Play anymore.
                    Kept me confused for a while until I remembered this commented out entry.
                    I mention it because it may confuse others.

                    1 Reply Last reply Reply Quote 0
                    • M
                      marcus556
                      last edited by

                      @BBcan177:

                      Add that Blocked IP to a Whitelist Alias. I described how to do that in a post this morning.

                      That worked thanks!

                      1 Reply Last reply Reply Quote 0
                      • S
                        stuck
                        last edited by

                        @BBcan177:

                        It's strange that there are no aliases. (url tables) listed? Are you sure you checked it properly?

                        Try to run this command from the shell :

                        pfctl -sa      (and at the end of the output, do you see any pfblocker tables?)

                        Also try to delete all files in

                        /var/db/aliastables  (then reboot)

                        Thank BBcan117,
                        Your post made it clear to me… I kept thinking I was to delete aliases from WebGUI "Firewall" > "Aliases".  I now realize I need to delete aliases from /var/db/aliastables/
                        I've done as you suggested, and I think it is working... So far, no error messages.  I'll wait a day to recheck.
                        Thanks again.

                        1 Reply Last reply Reply Quote 0
                        • B
                          Bummer
                          last edited by

                          What am I doing wrong????

                          Just when I think I'm doing great, I see I'm messing up.

                          I had China blocked in Country block. I've added 6 lists for and all seemed good. Now I'm getting nailed from China. I see that in County Block China is no longer listed. China by it's self does more than everyone else put together!

                          Help!

                          1 Reply Last reply Reply Quote 0
                          • BBcan177B
                            BBcan177 Moderator
                            last edited by

                            Hi Bummer, I need some more details to help.

                            You added "China", is it "Deny Both" or "Deny Inbound" or "Deny Outbound"?
                            The 6 Lists are also which Action setting?

                            What do you mean by "I see that in County Block China is no longer listed."?

                            "Experience is something you don't get until just after you need it."

                            Website: http://pfBlockerNG.com
                            Twitter: @BBcan177  #pfBlockerNG
                            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                            1 Reply Last reply Reply Quote 0
                            • BBcan177B
                              BBcan177 Moderator
                              last edited by

                              @doktornotor:

                              Lazy man's feature request: can you make the widget's aliases clickable? Like, show what's in the alias on hover (like when you hover in Firewall - Rules) and edit the alias when the row is double-clicked. :D

                              And I can, if you reply back on the testing of the Nano/Ramdisk Aliastables issue/Fix  ;D >:(

                              "Experience is something you don't get until just after you need it."

                              Website: http://pfBlockerNG.com
                              Twitter: @BBcan177  #pfBlockerNG
                              Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                              1 Reply Last reply Reply Quote 0
                              • D
                                doktornotor Banned
                                last edited by

                                @BBcan177:

                                And I can, if you reply back on the testing of the Nano/Ramdisk Aliastables issue/Fix  ;D >:(

                                Hmmm… I tried to apply the pull request and failed, even after editing out those erroneous .bak files and whatnot.

                                1 Reply Last reply Reply Quote 0
                                • B
                                  Bummer
                                  last edited by

                                  Yeah, I need to make things clearer. You know what they say, "A picture is worth a 1,000 words.". Well attached is a screen cap of what I have.

                                  I had China blocked in the Country Block. But something in my lists must have unblocked it as well as other countries I had blocked under Country Block.

                                  I really appreicate you help and in repeating stuff. I read things and then can't find it later when looking for it. It gets frustrating and I hate bothering the community. Everyone is so good.

                                  bbcan_1.png
                                  bbcan_1.png_thumb

                                  1 Reply Last reply Reply Quote 0
                                  • BBcan177B
                                    BBcan177 Moderator
                                    last edited by

                                    I'm doing this again in hopes that people read it the fifth time  ;D .. and for those that are afraid to ask …  ;D

                                    1. What is the "White Listed IPs" (Generally speaking). Are these IPs that might be blocked by a Country Block? You normally do not want to allow inbound like that.

                                    2. You can make a Single Alias "Malicious" and put multiple Lists into one… Makes it easier to organize.

                                    3. Spamhaus only needs to be "Deny Outbound" as the Firewall is already Blocking Inbound. Unless you have open ports that you want to protect?

                                    4. Why are the last two aliases set to "Deny Inbound" when you should block the "Outbound"? Unless you have Open Ports on the Wan (Inbound).

                                    5. Country Blocking is set in the Continent Tabs. They will not show in the IPv4 tab. Where do you see it missing in your setup?

                                    "Experience is something you don't get until just after you need it."

                                    Website: http://pfBlockerNG.com
                                    Twitter: @BBcan177  #pfBlockerNG
                                    Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                                    1 Reply Last reply Reply Quote 0
                                    • B
                                      Bummer
                                      last edited by

                                      Yes, I'm a dummy.  :-\

                                      1. The Ips are to insure they are not blocked. These client are my bread and butter. One is from the UAE and the other is from IT.

                                      2. I'll look in to the Alias. To me this seemed easier to manage.

                                      3. Dumb question - where is the Spamhaus being denied access inbound? Via other lists? Sorry, I'm confused on this one. It shows it is blocking.

                                      4. The ports I have opened are only the ones used. The last 2 are showing that they are blocking inbound.

                                      5. As for the Continent tabs, it was set to block China. It was highlighted or whatever you want to call it. China is still showing up, but not as being blocked.

                                      My concern it to protect the network by blocking all incoming traffic that could do harm.

                                      1 Reply Last reply Reply Quote 0
                                      • BBcan177B
                                        BBcan177 Moderator
                                        last edited by

                                        No problem… Lets get it working for you...

                                        1. Just be careful with a "Permit Inbound Rule". Make it very specific to a small IP range. You don't want to open up a large CIDR range if you don't need to... If the IPs are not in a Country that you are blocking, then a Country Block will not block it... Do you expect a list to Block any of those Whitelisted IPs... Its up to you. Just giving you information.

                                        2. Spamhaus is "Deny Both" so if you do not have any Open ports, it could be "Deny Outbound".

                                        3. Opened ports are opened if you created a NAT Rule or something similar.
                                          Just remember that pfSense is a "Stateful Firewall" It blocks all Inbound by default. If a device on the Lan (Inside) wants to go out thru the Firewall, it will open an Outbound State which inturn allows that IP Inbound access.  So generally, you can set these lists to "Deny Outbound"… Its only needed if you have defined open ports.

                                        Read up on what a "Stateful Firewall means" ...

                                        In the Asia Tab, Select "China", Set the "List Action" as "Deny Outbound" and Run a "Force Update"... If you defined any Open Ports, than use "Deny Both".

                                        "Experience is something you don't get until just after you need it."

                                        Website: http://pfBlockerNG.com
                                        Twitter: @BBcan177  #pfBlockerNG
                                        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                                        1 Reply Last reply Reply Quote 0
                                        • B
                                          Bummer
                                          last edited by

                                          I really appreciate your help.

                                          As for the inbound Ips, there is no range. They are 3 Ips and nothing else.

                                          As for Spamhouse, e do have a mail server. My concern is more with spam coming in than leaving. Although, I don't want a hacked client spamming someone else.

                                          Yes, the NAT rule only open the ports that we use. All other ports are closed.

                                          Okay, I'm curious, for China why do I deny outbound? Isn't inbound that I should be concerned about?

                                          Thanks!

                                          1 Reply Last reply Reply Quote 0
                                          • C
                                            capitangiaco
                                            last edited by

                                            I am using List Action: Deny Both. How can I use custom addresses to insert some whitelisted IPs ?

                                            Giacomo

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.