OPNsense Forum

Archive => 17.1 Legacy Series => Topic started by: Julien on February 12, 2017, 09:01:30 pm

Title: Pfblocker on opnsense
Post by: Julien on February 12, 2017, 09:01:30 pm
Hi Guys,
Are we seeing Pfblocker somewhere soon on the opnsense 17.x ?
I would like to block countries we don't log from. like China, Russia...
thank you
Title: Re: Pfblocker on opnsense
Post by: fabian on February 12, 2017, 10:44:27 pm
Use IPS instead or a country alias. It will not come.
Title: Re: Pfblocker on opnsense
Post by: Julien on February 13, 2017, 02:35:13 pm
Use IPS instead or a country alias. It will not come.
thank you Fabian for your answer.
do you mean with country alias https://docs.opnsense.org/manual/aliases.html?highlight=country%20alias ? or something else ?

thank you
Title: Re: Pfblocker on opnsense
Post by: Wayne Train on February 13, 2017, 10:00:32 pm
Nope,
I think he means this one: https://docs.opnsense.org/manual/how-tos/ips-geoip.html
Regards,
CS
Title: Re: Pfblocker on opnsense
Post by: Julien on February 13, 2017, 10:59:24 pm
Nope,
I think he means this one: https://docs.opnsense.org/manual/how-tos/ips-geoip.html
Regards,
CS
thank you,
not country means that country would not access the firewall or the other way around ?
Title: Re: Pfblocker on opnsense
Post by: Wayne Train on February 14, 2017, 01:37:46 pm
Hi,
"COUTRYNAME not" does the reverse. For example if ou choose "china not" your IPS will block everything except traffic going to and coming from china. I just selected the countries that most attacks originate from. According to symantec and other snakeoil-companies, this is russia, china and the greater trump-reich ;-) and some more... For testing purpose I selected russia and tried to surf to vkontakte which was succesfully blocked. Don't forget to click update & download rules after setting up your configuration. Otherwise your Geo-Block won't work.
Hope this helps.
Best regards,
CS
Title: Re: Pfblocker on opnsense
Post by: Julien on February 15, 2017, 12:03:00 am
Hi,
"COUTRYNAME not" does the reverse. For example if ou choose "china not" your IPS will block everything except traffic going to and coming from china. I just selected the countries that most attacks originate from. According to symantec and other snakeoil-companies, this is russia, china and the greater trump-reich ;-) and some more... For testing purpose I selected russia and tried to surf to vkontakte which was succesfully blocked. Don't forget to click update & download rules after setting up your configuration. Otherwise your Geo-Block won't work.
Hope this helps.
Best regards,
CS
thank you for your explanation, can show a picture of the IPS rules ?
which countries are those according to Symantec ?

is the below screenshots the correct one to block traffic from in and to china ?
one issue after I enable the IPS my internet connections just drops fully, my internet goes down.
I've followed this link.https://docs.opnsense.org/manual/how-tos/ips-feodo.html
I noticed when I disable the rule for the USA on the Intrusion Detection and user diffened .
am I forced to not block the USA ?
thank you
Title: Re: Pfblocker on opnsense
Post by: Julien on February 17, 2017, 01:27:08 am
is this even possible ?
to block all countries at once ?
and allow only the one I need to open ?
Title: Re: Pfblocker on opnsense
Post by: franco on February 17, 2017, 10:11:23 am
Hmm, just to make sure: we have two GeoIP databases, one for the IPS another for the Aliases. I recommend the latter. Create an alias, chose the respective type and compile your country list. You can use these aliases freely in the firewall rules (and even invert your selection).


Cheers,
Franco
Title: Re: Pfblocker on opnsense
Post by: pgras on February 17, 2017, 11:26:28 am
Hmm, just to make sure: we have two GeoIP databases, one for the IPS another for the Aliases. I recommend the latter. Create an alias, chose the respective type and compile your country list. You can use these aliases freely in the firewall rules (and even invert your selection).


Cheers,
Franco

Hello Franco,

How would your rule(s) look like?
Thnx!
Title: Re: Pfblocker on opnsense
Post by: Julien on February 20, 2017, 09:22:27 pm
Hmm, just to make sure: we have two GeoIP databases, one for the IPS another for the Aliases. I recommend the latter. Create an alias, chose the respective type and compile your country list. You can use these aliases freely in the firewall rules (and even invert your selection).


Cheers,
Franco
thank you Franco for your answer.
do you guys have a tutorial or some document to follow ?
I really did not understand the GEOIP yet,
enabling it to block top 10 spammers countries causes us not receiving emails from our customer.

do we have to use ( our country not ) when activating this ?