Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Rules keep moving

    Scheduled Pinned Locked Moved Firewalling
    8 Posts 2 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      skeating
      last edited by

      Hello

      I have created some rules, which I moved ahead of the pfBlock rules. Never the less, in the morning the rules are once again below the pfBlock rules. I click the Apply Changes button every time, but in the AM their back below. What do I need to do tofix this?

      Thanks
      Stephen Keating

      1 Reply Last reply Reply Quote 0
      • BBcan177B Offline
        BBcan177 Moderator
        last edited by

        In the pfBlockerNG, General tab, you need to select the "Rule Order" Setting that meets your network needs…

        "Experience is something you don't get until just after you need it."

        Website: http://pfBlockerNG.com
        Twitter: @BBcan177  #pfBlockerNG
        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

        1 Reply Last reply Reply Quote 0
        • S Offline
          skeating
          last edited by

          So, if the pfBlocker rule is blocking a country, and I put in a rule to let an IP through, but it is lower on the list after the pfBlocker, will the IP be blocked?

          1 Reply Last reply Reply Quote 0
          • BBcan177B Offline
            BBcan177 Moderator
            last edited by

            Its best to create a new pfBNG Alias,  ie - Whitelist, and set it to "Permit Outbound". Then enter the IPs you want to allow outbound in the "Custom Box entry"… Then make sure that the Rule Order is configured with Permit rules above the Block rules ...See the link below...

            https://forum.pfsense.org/index.php?topic=86212.msg513676#msg513676

            "Experience is something you don't get until just after you need it."

            Website: http://pfBlockerNG.com
            Twitter: @BBcan177  #pfBlockerNG
            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

            1 Reply Last reply Reply Quote 0
            • S Offline
              skeating
              last edited by

              Thanks for the info.

              1 Reply Last reply Reply Quote 0
              • S Offline
                skeating
                last edited by

                One point though, the IPs are trying to send mail to me, not receive from me. Is the rule setup the same. And where do I find documentation for all this. I just got this dumped on me.

                1 Reply Last reply Reply Quote 0
                • BBcan177B Offline
                  BBcan177 Moderator
                  last edited by

                  You can use the new feature in v1.09 to Fine-Tune the "Inbound Settings"
                  https://forum.pfsense.org/index.php?topic=86212.msg524957#msg524957

                  or you can manually create a Rule with the IPs that you want to allow Inbound to the Mail Server Ports that are open on the WAN only. But with the new feature, you can create a single Alias of allowed IPs, and then configure the pfBNG Country Alias to use these custom Inbound settings when creating the Inbound Firewall rules…

                  "Experience is something you don't get until just after you need it."

                  Website: http://pfBlockerNG.com
                  Twitter: @BBcan177  #pfBlockerNG
                  Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                  1 Reply Last reply Reply Quote 0
                  • S Offline
                    skeating
                    last edited by

                    After I manually create the Alias, how do I get it to show up in the Rules list, and so I can edit the settings for the alias.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.