OPNsense Forum

English Forums => General Discussion => Topic started by: andrei.butcu@gmail.com on October 23, 2024, 07:54:01 AM

Title: Firewall rule & add to alias
Post by: andrei.butcu@gmail.com on October 23, 2024, 07:54:01 AM
Dear all,
I want to creat the following rule:
If any IP try to hit 3389 port of my public IP firewall address, then:
- block &
- add the source IP to a Alias list "Block list"

I already configured the manual "Block list" and the rule to block any traffic from "Block list". I need to populate the "Block list" with anyone who is tryinng to hit the 3389 port of the WAN.

I don't see in the interface a option like "...and add the source IP Ip to alias list". Can someone help?
Title: Re: Firewall rule & add to alias
Post by: Patrick M. Hausen on October 23, 2024, 09:01:27 AM
There is to my knowledge no function in OPNsense that does that. You might want to look into Crowdsec.
Title: Re: Firewall rule & add to alias
Post by: andrei.butcu@gmail.com on October 23, 2024, 12:41:28 PM
Quote from: Patrick M. Hausen on October 23, 2024, 09:01:27 AM
There is to my knowledge no function in OPNsense that does that. You might want to look into Crowdsec.

Thank you. I'll stop the research then... :). :D