OPNsense Forum

English Forums => General Discussion => Topic started by: Noob3 on October 14, 2017, 04:50:08 pm

Title: IP and URL Block Lists
Post by: Noob3 on October 14, 2017, 04:50:08 pm
I am a PfSense user at the moment and the one thing I am obsessed with is IP and URL Block Lists.

Is there going to be a package like PFblocker for Opnsense??
Also country blocker?

Or is that on the to do list ;)

Many thanks this looks like a great firewall project ;)
Title: Re: IP and URL Block Lists
Post by: phoenix on October 14, 2017, 04:59:45 pm
How about Suricata (the inline IPS), you can find more details here: https://wiki.opnsense.org/manual/ips.html
Title: Re: IP and URL Block Lists
Post by: fabian on October 14, 2017, 05:07:36 pm
URL Blocking: https://docs.opnsense.org/manual/how-tos/proxywebfilter.html
Title: Re: IP and URL Block Lists
Post by: Noob3 on October 18, 2017, 12:39:40 pm
O thats fantastic I like that ;) looks great!
Title: Re: IP and URL Block Lists
Post by: mimugmail on October 18, 2017, 02:17:10 pm
Geoblocking via Aliases will receive a really nice update within the next releases:

https://github.com/opnsense/core/issues/1860#issuecomment-336718443
Title: Re: IP and URL Block Lists
Post by: franco on October 18, 2017, 11:07:59 pm
Sorry for the ugly dev capture there (mea culpa), the end result is:

https://user-images.githubusercontent.com/1915288/31587781-d9435510-b1e7-11e7-9a23-7a88c0a663b1.png

It'll be in 17.7.7.


Cheers,
Franco
Title: Re: IP and URL Block Lists
Post by: cyberzeus on December 31, 2017, 08:53:01 am
Hello OPNsense folks,

Aside from the proxy method described here, I have read that this functionality can be accomplished using aliases.  However, even with that, there is a lot of pfBlocker functionality not present in OPNsesne that, if added, would be of great benefit to the platform.

With that in mind, are there any plans to provide a fully functional pfB port or similar to OPNsense? 

It is a very useful and powerful package as it offloads a lot of load and resource drain from the IPS and adds in other functionality as well.

Thanks.
Title: Re: IP and URL Block Lists
Post by: franco on January 04, 2018, 10:03:39 pm
The plan has been repeated a lot in this forum, not just lately. Let me reiterate.

Make a suggestion on GitHub about what part of pfBlockerNG you are interested in and we will work on a seamless integration. The goal cannot be to port the package. It's very powerful indeed, but it could be even more so if part of the core functionality with streamlined UX.

That being said, others have committed privately to working on particular parts of the integration, namely feeds, whitelists, IP and Host/ASN. The more the merrier. Usually all it takes is for one person to kickstart the work. :)


Cheers,
Franco
Title: Re: IP and URL Block Lists
Post by: l0rdraiden on August 24, 2018, 07:55:07 pm
Any news about how this is evolving?
Title: Re: IP and URL Block Lists
Post by: mimugmail on August 24, 2018, 08:50:56 pm
With 18.7.1 there is a Bind plugin where you can use DNSBLs like PiHole or pfBlockerNG.
Just install, enable, and do a portforward from some test IPs ..
Title: Re: IP and URL Block Lists
Post by: l0rdraiden on August 25, 2018, 11:40:16 am
Yeah but that would imply to run pfsense with pfblockerng  and opnsense at the same time, which make no sense if you can simply run pfsense.

Someone mention that there was people working in private to bring some pfblockerng capabilities to opnsense, any news about this?
Title: Re: IP and URL Block Lists
Post by: mimugmail on August 25, 2018, 12:51:23 pm
Why would you need pfsense when OPN has a Bind Plugin supporting DNSBL?
Title: Re: IP and URL Block Lists
Post by: l0rdraiden on August 25, 2018, 02:05:39 pm
Sorry I understood you wrong.

And then for IPBlock lists is there any option?
Title: Re: IP and URL Block Lists
Post by: mimugmail on August 25, 2018, 02:07:49 pm
It's already possible via URL Table alias:

https://docs.opnsense.org/manual/aliases.html#url-tables
https://www.routerperformance.net/opnsense/using-pfblocker-features-in-opnsense/
Title: Re: IP and URL Block Lists
Post by: l0rdraiden on August 26, 2018, 11:11:22 am
It's possible to whitelist DNSBL and IP false block easily?
It's possible apply the block lists only to specific ports?
Does opnsense merge the lists to avoid duplicated entries?
Title: Re: IP and URL Block Lists
Post by: mimugmail on August 26, 2018, 02:16:46 pm
Yes
No
Yes