Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
19.7 Legacy Series
»
GEOIP stopt working
« previous
next »
Print
Pages:
1
...
3
4
[
5
]
6
7
Author
Topic: GEOIP stopt working (Read 90413 times)
marjohn56
Hero Member
Posts: 1701
Karma: 179
Re: GEOIP stopt working
«
Reply #60 on:
January 10, 2020, 05:13:31 pm »
Definitely working here. Rules updated from Maxmind a couple of hours after I corrected my spelling mistake, yes it was me who did the doc, and the rules are working. Just turned on the logging of the inverted, same as dcol, and sure enough log entries started to appear. I normally have it turned off.
Just to confirm, the string should look like this, this is for the non-commercial users:
https://download.maxmind.com/app/geoip_download?edition_id=GeoLite2-Country-CSV&license_key=
YOUR_LICENCE_KEY
&suffix=zip
It took an hour or so after I changed it for it to update, not sure exactly how it works out the time to poll but its once a day,
You should see the last updated date, which is the file date and the number of entries, at least on mine is 433499 if it has successfully connected and downloaded the data.
«
Last Edit: January 10, 2020, 05:19:20 pm by marjohn56
»
Logged
OPNsense 24.7
-
Qotom Q355G4
- ISP -
Squirrel 1Gbps
.
Team Rebellion Member
- If we've helped you remember to applaud
agrumpyhermit
Newbie
Posts: 18
Karma: 2
Re: GEOIP stopt working
«
Reply #61 on:
January 10, 2020, 05:22:21 pm »
chemlud, creating a new alias did the trick. Thank you!
Logged
marjohn56
Hero Member
Posts: 1701
Karma: 179
Re: GEOIP stopt working
«
Reply #62 on:
January 10, 2020, 05:36:12 pm »
Here's a way of forcing a download and seeing what is happening.
Go into the shell. Bold chars are what you must enter
root@gateway:~ #
cd /usr/local/opnsense/scripts/filter/lib
root@gateway:/usr/local/opnsense/scripts/filter/lib #
python3
You will now be seeing the Python interpreter.
>>>
from geoip import download_geolite
>>>
download_geolite()
Wait a few seconds and if you have got the correct url and licence you should see something like this:
{'address_count': 433499, 'file_count': 499, 'timestamp': '2020-01-06T23:45:56', 'locations_filename': 'GeoLite2-Country-Locations-en.csv', 'address_sources': {'IPv4': 'GeoLite2-Country-Blocks-IPv4.csv', 'IPv6': 'GeoLite2-Country-Blocks-IPv6.csv'}}
Hit Ctrl-d to exit the Python interpreter.
This will download the data, and extract the lists to the /usr/local/share/GeoIP/alias folder and prove that your url is correct. If you run this at anytime it will update the files and you can prove this by looking at the changed date/time on the files in that folder. Note that the free Geolite files are only updated weekly, and according to the Maxmind website this happens on a Tuesday.
«
Last Edit: January 11, 2020, 02:44:50 pm by marjohn56
»
Logged
OPNsense 24.7
-
Qotom Q355G4
- ISP -
Squirrel 1Gbps
.
Team Rebellion Member
- If we've helped you remember to applaud
agrumpyhermit
Newbie
Posts: 18
Karma: 2
Re: GEOIP stopt working
«
Reply #63 on:
January 10, 2020, 05:55:24 pm »
When I try to delete the old alias it says cannot delete... in use by filter.rule.67/source. I've gone through all my rules in the gui thoroughly and can't find anywhere I missed changing to the new alias. I tried resetting states and reloading pf. It let me disable it but won't let me delete it. Can someone tell me how to figure out what filter.rule.67 is so I can fix this?
Logged
gpb
Full Member
Posts: 234
Karma: 13
Re: GEOIP stopt working
«
Reply #64 on:
January 10, 2020, 06:24:36 pm »
Quote from: marjohn56 on January 10, 2020, 05:36:12 pm
Here's a way of forcing a download and seeing what is happening.
Thanks very much! I never did get it working yesterday, applied the hotfix just now and manually verified it's correct. Cheers.
Logged
HP T730/AMD RX-427BB/8GB/500GB SSD
HP NC365T 4-PORT
Taomyn
Sr. Member
Posts: 444
Karma: 20
Re: GEOIP stopt working
«
Reply #65 on:
January 10, 2020, 07:14:38 pm »
Quote from: marjohn56 on January 10, 2020, 05:36:12 pm
Here's a way of forcing a download and seeing what is happening.
Thank-you very much for this, works a treat. Checked before and after applying the hotfix and looks fine.
Logged
dcol
Hero Member
Posts: 635
Karma: 51
Re: GEOIP stopt working
«
Reply #66 on:
January 11, 2020, 05:07:49 pm »
Tried recreating rule and alias, still no log entries for GeoIP.
Tried the shell command above and everything is correct. Just not seeing any blocks in the logs. Not sure if it is working or not.
Is there any other way to test this?
«
Last Edit: January 11, 2020, 05:40:30 pm by dcol
»
Logged
chemlud
Hero Member
Posts: 2481
Karma: 112
Re: GEOIP stopt working
«
Reply #67 on:
January 11, 2020, 05:43:53 pm »
Enter into your browser
yandex.ru
or
opnsense.org
What happenz?
«
Last Edit: January 11, 2020, 05:45:25 pm by chemlud
»
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare
felix eichhorns premium katzenfutter mit der extraportion energie
A router is not a switch - A router is not a switch - A router is not a switch - A rou....
dcol
Hero Member
Posts: 635
Karma: 51
Re: GEOIP stopt working
«
Reply #68 on:
January 11, 2020, 05:53:36 pm »
@chemlud It works. Also tried China sites using WebSitePulse and they all work.
So that means the GeoIP is not functioning for me.
Logged
chemlud
Hero Member
Posts: 2481
Karma: 112
Re: GEOIP stopt working
«
Reply #69 on:
January 11, 2020, 05:59:42 pm »
I would delete the Alias, reboot and establish a fresh Alias. Still not blocking? Did you upgrade to 19.7.9_1? (dunno what got fixed by the latest update though...)
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare
felix eichhorns premium katzenfutter mit der extraportion energie
A router is not a switch - A router is not a switch - A router is not a switch - A rou....
dcol
Hero Member
Posts: 635
Karma: 51
Re: GEOIP stopt working
«
Reply #70 on:
January 11, 2020, 06:26:08 pm »
Started working after I changed the floating rule to block both directions. Seems most of the blocking was done by IDS already
Logged
chemlud
Hero Member
Posts: 2481
Karma: 112
Re: GEOIP stopt working
«
Reply #71 on:
January 11, 2020, 08:06:42 pm »
I have two floating rules on all interfaces, one with GeoIP as SOURCE, one with DESTINATION. But I checked now, only the one with SOURCE does fire, if I try to access yandex.ru in the browser. My expectation was that even the traffic from the LAN client (GeoIP as DESTINATION) would be blocked...
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare
felix eichhorns premium katzenfutter mit der extraportion energie
A router is not a switch - A router is not a switch - A router is not a switch - A rou....
dcol
Hero Member
Posts: 635
Karma: 51
Re: GEOIP stopt working
«
Reply #72 on:
January 11, 2020, 08:17:51 pm »
I found a real disadvantage in using the invert GeoIP floating rule.
For example. I have a GeoIP rule which blocks every country except US and Canada for my Email ports (except 25). Doing this, any local IP's will not be in the Maxmind list so it will be blocked as well.
I am using a floating rule because I have multiple email servers and wanted the same GeoIP blocking for all of them.
So I either have to make a rule which allows all the local ports to pass before the GeoIP rule, or not use invert and have an enormous list in GeoIP.
Floating rules can be tricky to use due to the multiple interfaces and dual direction capabilities.
Any recommendations for the best approach here?
«
Last Edit: January 11, 2020, 09:36:10 pm by dcol
»
Logged
mayo
Jr. Member
Posts: 72
Karma: 4
Re: GEOIP stopt working
«
Reply #73 on:
January 12, 2020, 10:44:09 am »
One question about Geoip: do I have to subscribe also if I don’t use aliases? Thank you!
Logged
marjohn56
Hero Member
Posts: 1701
Karma: 179
Re: GEOIP stopt working
«
Reply #74 on:
January 12, 2020, 11:14:43 am »
If you are not using GeoIP rules in the firewall then the answer is no.
Logged
OPNsense 24.7
-
Qotom Q355G4
- ISP -
Squirrel 1Gbps
.
Team Rebellion Member
- If we've helped you remember to applaud
Print
Pages:
1
...
3
4
[
5
]
6
7
« previous
next »
OPNsense Forum
»
Archive
»
19.7 Legacy Series
»
GEOIP stopt working