Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
General Discussion
»
GeoIP Problem!
« previous
next »
Print
Pages: [
1
]
Author
Topic: GeoIP Problem! (Read 4642 times)
opnsenseuser
Sr. Member
Posts: 437
Karma: 70
GeoIP Problem!
«
on:
November 09, 2018, 12:09:34 pm »
First, I created the alias. then I have selected the countries or continents that I want to block.
In the last step, I selected the alias as the source in the firewall rule of the wan interface. this then confirmed, 10 minutes waiting and tried.
how can it be that I still can load for example the angola homepage?
I then additionally entered as destination the alias in the wan firewall rules too. but it does not work either.
does this work only with IDS / IPS or am I doing something wrong?
Screenshots of the settings see appendix!
best regards
rené
«
Last Edit: November 09, 2018, 12:16:11 pm by noname12123
»
Logged
Supermicro A2SDi-4C-HLN4F
Team Rebellion Member
(sidebar / themes: tukan, cicada & vicuna
)
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: GeoIP Problem!
«
Reply #1 on:
November 09, 2018, 12:44:54 pm »
You have to increase max table size in Firewall : Settings : Advanced
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
opnsenseuser
Sr. Member
Posts: 437
Karma: 70
Re: GeoIP Problem!
«
Reply #2 on:
November 09, 2018, 01:33:17 pm »
thx for you reply.
i increased the Firewall Maximum Table Entries to "500000" and applied the changes.
i still use the alias on source and destionation wan rules.
no difference
http://www.governo.gov.ao/
still works!
Logged
Supermicro A2SDi-4C-HLN4F
Team Rebellion Member
(sidebar / themes: tukan, cicada & vicuna
)
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: GeoIP Problem!
«
Reply #3 on:
November 09, 2018, 01:42:30 pm »
Make ist 1,5 Mio .. if it's still not working it's Layer 8
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
opnsenseuser
Sr. Member
Posts: 437
Karma: 70
Re: GeoIP Problem!
«
Reply #4 on:
November 09, 2018, 01:58:47 pm »
Quote from: mimugmail on November 09, 2018, 01:42:30 pm
Make ist 1,5 Mio .. if it's still not working it's Layer 8
https://en.wikipedia.org/wiki/Layer_8
;-)
http://www.angolatelecom.ao/
-> still works
http://www.governo.gov.ao/
-> still works
http://www.angop.ao/
-> still works
if I understand the firewall rules correctly, is under "source" to understand the traffic that comes in the firewall and under "destination" everything that goes out of the firewall? right?
So if I want to block pages from Angola I would have to enter the alias under Destination. right ?
after having amused myself about layer 8, I can not really say what I'm doing wrong now.
perhaps choose the lan interface for the blocking rule and not the wan interface?
how can i check whether the GEOip blocking works?
by the way .. i´m using transparent squid proxy with certificate if this is important to know!
«
Last Edit: November 09, 2018, 02:06:50 pm by noname12123
»
Logged
Supermicro A2SDi-4C-HLN4F
Team Rebellion Member
(sidebar / themes: tukan, cicada & vicuna
)
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: GeoIP Problem!
«
Reply #5 on:
November 09, 2018, 03:13:38 pm »
If you want to block traffic TO Angola, you have to add the rule in LAN tag and it's destination.
When using Squid as transparent it SHOULD be on WAN tab and destination, but I'm unsure, never did that in transparent mode
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
opnsenseuser
Sr. Member
Posts: 437
Karma: 70
Re: GeoIP Problem!
«
Reply #6 on:
November 09, 2018, 04:19:15 pm »
Unfortunately, I have to tell you that I've tried everything you said, but unfortunately without success. no matter which countries are blocked, they are blocked via dest / source on the lan interface or via dest / source on the wan interface. it has to be somehow related to the transparent proxy. but I do not know yet.
Who knows how to configure it?
Logged
Supermicro A2SDi-4C-HLN4F
Team Rebellion Member
(sidebar / themes: tukan, cicada & vicuna
)
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: GeoIP Problem!
«
Reply #7 on:
November 09, 2018, 04:27:14 pm »
I'm afraid it won't work with transparent proxy.
Only solution is to make a no rdr rule in NAT for your country so it's not routed via proxy and then you have to put the rule in LAN tab.
Touching NAT rules on transparent proxy needs nat state clearing!
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
gex
Newbie
Posts: 11
Karma: 0
Re: GeoIP Problem!
«
Reply #8 on:
December 01, 2018, 06:48:43 pm »
try what I post in
https://forum.opnsense.org/index.php?topic=10458.new;topicseen#new
as a workaround
«
Last Edit: December 02, 2018, 12:53:51 am by gex
»
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
General Discussion
»
GeoIP Problem!