OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • firewall allow via GEO isn't working
« previous next »
  • Print
Pages: [1]

Author Topic: firewall allow via GEO isn't working  (Read 2784 times)

osn1803

  • Newbie
  • *
  • Posts: 15
  • Karma: 1
    • View Profile
firewall allow via GEO isn't working
« on: March 30, 2019, 02:05:24 am »
Salutations --

I have a feeling I'm missing something super-obvious, but I can't find it. 

I defined a firewall alias named GEO_US_v4, Type GeoIP / IPv4,  where Content selects only my country of residence (US).   I used this alias as a Source in a port forward rule to allow connections to one port.   I created a similar alias for IPv6, and applied it to a rule on the tunnel V6 interface.   Unfortunately, in both cases, it does not match traffic which I know is US-based. 

If I change only the Source in those rules to be 'Any' instead of my alias GEO_US_v[46], then traffic is allowed -- so I know that the traffic is reaching this rule, and I've not blocked it some other way.   The alias must be wrong somehow.

Is there something else I should consider here, or other information I can provide to help illuminate what I'm sure is my mistake?

Thank you...
Logged

hbc

  • Hero Member
  • *****
  • Posts: 501
  • Karma: 47
    • View Profile
Re: firewall allow via GEO isn't working
« Reply #1 on: March 30, 2019, 06:38:55 pm »
I think there was a problem with aliases in port forwarding. Maybe you have the same problem.

https://forum.opnsense.org/index.php?topic=12002.0

should be fixed in 19.1.5
Logged
Intel(R) Xeon(R) Silver 4116 CPU @ 2.10GHz (24 cores)
256 GB RAM, 300GB RAID1, 3x4 10G Chelsio T540-CO-SR

osn1803

  • Newbie
  • *
  • Posts: 15
  • Karma: 1
    • View Profile
Re: firewall allow via GEO isn't working
« Reply #2 on: March 30, 2019, 08:39:16 pm »
Hmm ... I don't think that's it, because the same behavior is seen with IPv6, which is a simple firewall rule where port forwarding is not involved.  As with the v4 rule, if I change 'GEO_US_IPv6' to 'All', then traffic is passed.
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • firewall allow via GEO isn't working
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2