OPNsense Forum

Archive => 23.1 Legacy Series => Topic started by: gonzo on April 19, 2023, 09:12:48 PM

Title: Firewall: Diagnostics: Aliases / add address / remove address works for 30 secon
Post by: gonzo on April 19, 2023, 09:12:48 PM
Hi

When I add an IP in Firewall: Diagnostics: Aliases it appears in the list for 30 seconds and disappears.
What should I do so that the added IP address remains on the list permanently ?

gonzo

Title: Re: Firewall: Diagnostics: Aliases / add address / remove address works for 30 secon
Post by: arnog on April 19, 2023, 09:55:38 PM
I am not sure, if I understand your question correctly, but you can create aliases in "Firewall" > "Aliases". When you do it there, they should stick.

The IP address disappears, because the aliases tables are recreated periodically from what has been configured for an alias.
Title: Re: Firewall: Diagnostics: Aliases / add address / remove address works for 30 secon
Post by: gonzo on April 19, 2023, 10:03:13 PM
Yes, I have an alias created, but it fetches data every 6 hours. And I want to add or remove one address quickly.
Title: Re: Firewall: Diagnostics: Aliases / add address / remove address works for 30 secon
Post by: Seimus on April 20, 2023, 10:40:44 AM
I don't think Firewall > Diagnostics > Aliases is made for this purpose. As I see it its mainly functionality is to see stats of the defined Alias groups made in Firewall > Aliases.

Also adding an object in Firewall > Aliases is already a quick thing. Thats why it was created in first place so you dont need to constantly redo your rules.

Regards,
Seimus
Title: Re: Firewall: Diagnostics: Aliases / add address / remove address works for 30 secon
Post by: gonzo on April 20, 2023, 11:46:13 AM

Ok, so tell me how to quickly remove an IP address that was mistakenly included in the list of blocked IP addresses when the list is refreshed every 12 hours ?
I have to wait 12 hours ?
Title: Re: Firewall: Diagnostics: Aliases / add address / remove address works for 30 secon
Post by: abulafia on April 20, 2023, 01:12:29 PM
1. Create an IP alias with a NOT ("!") setting, e.g. "!1.2.3.4".
2. Create an alias that combines your IP list and the not-IP-alias
3. Use the new combined alias.
4. Done.