Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Firewall rules get moved arround after updates on PfBlockerNG?

    Scheduled Pinned Locked Moved pfSense Packages
    6 Posts 3 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      killmasta93
      last edited by

      Hi,

      Not sure since I updated to version 1.08 my rules would get moved around which then meant that I would get blocked out. So I have whatsapp blocked but for me it should be allow. I enabled suppression and added it to rules. I put it on top of all the rules but once I click on force update it changes and puts it on the bottom making whatsapp blocked for me. I also tried leaving it alone but after one day it updates itself and shifts my rules. I was wondering what am i doing wrong? See picture below.

      Thank you
      Clipboarder.2015.05.01-006.png
      Clipboarder.2015.05.01-006.png_thumb
      Clipboarder.2015.05.01-003.png
      Clipboarder.2015.05.01-003.png_thumb
      Clipboarder.2015.05.01-004.png
      Clipboarder.2015.05.01-004.png_thumb
      Clipboarder.2015.05.01-005.png
      Clipboarder.2015.05.01-005.png_thumb

      Tutorials:

      https://www.mediafire.com/folder/v329emaz1e9ih/Tutorials

      1 Reply Last reply Reply Quote 0
      • BBcan177B
        BBcan177 Moderator
        last edited by

        In the pfBNG 'General' tab, define the 'Rule Order' option.

        "Experience is something you don't get until just after you need it."

        Website: http://pfBlockerNG.com
        Twitter: @BBcan177  #pfBlockerNG
        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

        1 Reply Last reply Reply Quote 0
        • K
          killmasta93
          last edited by

          Hi BBcan177,

          The rule order is pfb pass/match –-pfb block/reject----pfSense pass/match

          I have tried pfb pass/match ---pfSense pass/match ---pfb block/reject
          it works but it ignores the block when accessing block facebook because IPv4 accepts everything

          If i put a pass/match lets say facebook it will now pass facebook and ignore the block

          I tried putting source the ip of my device so it ignores the block which works perfect but then pfblocker updates and deletes the source. Am i missing on a way to only allow certain ip to ignore the block?

          Thank you

          Tutorials:

          https://www.mediafire.com/folder/v329emaz1e9ih/Tutorials

          1 Reply Last reply Reply Quote 0
          • D
            doktornotor Banned
            last edited by

            Yeah, a generic match all rule does match everything; not really surprising. So why are you using the autorules instead of using alias and designing ordering your own rules as needed?

            1 Reply Last reply Reply Quote 0
            • K
              killmasta93
              last edited by

              yeah i just ended up using my alias to block sites and allow myself to access it only  and pfBlockerNG to block all ads

              Thanks  :)

              Tutorials:

              https://www.mediafire.com/folder/v329emaz1e9ih/Tutorials

              1 Reply Last reply Reply Quote 0
              • BBcan177B
                BBcan177 Moderator
                last edited by

                Hi  killmasta93,

                I took a look at your Firwall Rules screenshot… Please do not use the "pfBlockerNGSuppress" Alias as a Firewall Rule Reference… That Alias is used for suppressing those IPs when Lists are downloaded so that they don't end up blocking those IPs. Take a look at the following thread:

                https://forum.pfsense.org/index.php?topic=86212.msg513676#msg513676

                "Experience is something you don't get until just after you need it."

                Website: http://pfBlockerNG.com
                Twitter: @BBcan177  #pfBlockerNG
                Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.