GeoIP Rules Question

Started by guyp2k, August 09, 2020, 03:26:54 PM

Previous topic - Next topic
Would the following rules be sufficient for GeoIP?


Hello,
Although I'm a newcomer to OPNsense, I have this
via a floating rule for "all interfaces"
and therefore the rule should apply to incoming and outgoing traffic.
(Should my rule be faulty, I would be happy about further contributions...)
Greetings from Germany

OPNsense 22.7.9*WG-kmod*OpenSSL*OpenVPN* AdGuardHome*i7-7700*32GB*256SSD*ix0-1, igb0-4, em0*OpenVPN+Wireguard WG0, WG1*NetGear ProSafe XS508*AP Netgear WAX610*alles echtes Blech* Sorry, my English is translated via app*

Okay, let's combine both your efforts then: Floating rule for sure, and both destination and source, in and out.

@ lar.hed
Okay, understood, with the proposed rule
the source and/or destination (GeoIP) is blocked.

Got it corrected right in my floating.

Thanks!  :)
OPNsense 22.7.9*WG-kmod*OpenSSL*OpenVPN* AdGuardHome*i7-7700*32GB*256SSD*ix0-1, igb0-4, em0*OpenVPN+Wireguard WG0, WG1*NetGear ProSafe XS508*AP Netgear WAX610*alles echtes Blech* Sorry, my English is translated via app*

Thanks for the replies and here are my GeoIP floating rules:


@guyp2k
I think more like this -> see attachment...
Direction in and out and do not forget the interfaces
...concerning the rule...
OPNsense 22.7.9*WG-kmod*OpenSSL*OpenVPN* AdGuardHome*i7-7700*32GB*256SSD*ix0-1, igb0-4, em0*OpenVPN+Wireguard WG0, WG1*NetGear ProSafe XS508*AP Netgear WAX610*alles echtes Blech* Sorry, my English is translated via app*

Thanks again, scaled down to 2 floating rules and added the interfaces, see attached.

August 09, 2020, 11:54:08 PM #7 Last Edit: August 10, 2020, 11:17:23 AM by Mondmann
@guyp2k
OK -> reduced to 2 floating rules and added the interfaces

Your rule is not OK yet -> please have a look at geoip_2.png again! (marked with RED) or from lar.hed BlockCountries.jpg...

you recognize your error :o
OPNsense 22.7.9*WG-kmod*OpenSSL*OpenVPN* AdGuardHome*i7-7700*32GB*256SSD*ix0-1, igb0-4, em0*OpenVPN+Wireguard WG0, WG1*NetGear ProSafe XS508*AP Netgear WAX610*alles echtes Blech* Sorry, my English is translated via app*

Updated, see attached.

Thanks

yes, and now take the correct description - >
Your No. 1 = Block Countries Destination
Your No. 2 = Block Countries Source 
OPNsense 22.7.9*WG-kmod*OpenSSL*OpenVPN* AdGuardHome*i7-7700*32GB*256SSD*ix0-1, igb0-4, em0*OpenVPN+Wireguard WG0, WG1*NetGear ProSafe XS508*AP Netgear WAX610*alles echtes Blech* Sorry, my English is translated via app*

Thanks for all the help, new to opnsnese and still learning....

May I ask why you only like to run the floating rules on a specific interface?

In my case I run GeoIP block on ALL interfaces, in all directions, both source and target - since I never expect it to be there so to speak.

I also block ALL TOR exit nodes, in the same manner - All interfaces, All directions and both source and target.

August 10, 2020, 11:26:52 AM #12 Last Edit: August 10, 2020, 01:38:49 PM by Mondmann
@ lar.hed

I agree with this and have generally selected all interfaces.
in my attachment: geoip_3.png i only made my private entries unrecognizable...

* and excuse me i write my texts via translation tool

Greetings from Germany
OPNsense 22.7.9*WG-kmod*OpenSSL*OpenVPN* AdGuardHome*i7-7700*32GB*256SSD*ix0-1, igb0-4, em0*OpenVPN+Wireguard WG0, WG1*NetGear ProSafe XS508*AP Netgear WAX610*alles echtes Blech* Sorry, my English is translated via app*

No worries mate! I can read german, but it is way to long ago I wrote, so sorry I will save is all from even trying :-)

What countries are you blocking for in and out ?
i am just curious.
DEC4240 – OPNsense Owner