Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
20.7 Legacy Series
»
GeoIP Rules Question
« previous
next »
Print
Pages: [
1
]
2
Author
Topic: GeoIP Rules Question (Read 7429 times)
guyp2k
Newbie
Posts: 41
Karma: 3
GeoIP Rules Question
«
on:
August 09, 2020, 03:26:54 pm »
Would the following rules be sufficient for GeoIP?
Logged
Mondmann
Jr. Member
Posts: 73
Karma: 7
Re: GeoIP Rules Question
«
Reply #1 on:
August 09, 2020, 05:50:04 pm »
Hello,
Although I'm a newcomer to OPNsense, I have this
via a floating rule for "all interfaces"
and therefore the rule should apply to incoming and outgoing traffic.
(Should my rule be faulty, I would be happy about further contributions...)
Greetings from Germany
Logged
OPNsense 22.7.9*WG-kmod*OpenSSL*OpenVPN* AdGuardHome*i7-7700*32GB*256SSD*ix0-1, igb0-4, em0*OpenVPN+Wireguard WG0, WG1*NetGear ProSafe XS508*AP Netgear WAX610*alles echtes Blech* Sorry, my English is translated via app*
lar.hed
Sr. Member
Posts: 323
Karma: 10
Re: GeoIP Rules Question
«
Reply #2 on:
August 09, 2020, 06:41:33 pm »
Okay, let's combine both your efforts then: Floating rule for sure, and both destination and source, in and out.
Logged
Mondmann
Jr. Member
Posts: 73
Karma: 7
Re: GeoIP Rules Question
«
Reply #3 on:
August 09, 2020, 07:54:49 pm »
@ lar.hed
Okay, understood, with the proposed rule
the source and/or destination (GeoIP) is blocked.
Got it corrected right in my floating.
Thanks!
Logged
OPNsense 22.7.9*WG-kmod*OpenSSL*OpenVPN* AdGuardHome*i7-7700*32GB*256SSD*ix0-1, igb0-4, em0*OpenVPN+Wireguard WG0, WG1*NetGear ProSafe XS508*AP Netgear WAX610*alles echtes Blech* Sorry, my English is translated via app*
guyp2k
Newbie
Posts: 41
Karma: 3
Re: GeoIP Rules Question
«
Reply #4 on:
August 09, 2020, 09:41:35 pm »
Thanks for the replies and here are my GeoIP floating rules:
Logged
Mondmann
Jr. Member
Posts: 73
Karma: 7
Re: GeoIP Rules Question
«
Reply #5 on:
August 09, 2020, 10:37:09 pm »
@guyp2k
I think more like this -> see attachment...
Direction in and out and do not forget the interfaces
...concerning the rule...
Logged
OPNsense 22.7.9*WG-kmod*OpenSSL*OpenVPN* AdGuardHome*i7-7700*32GB*256SSD*ix0-1, igb0-4, em0*OpenVPN+Wireguard WG0, WG1*NetGear ProSafe XS508*AP Netgear WAX610*alles echtes Blech* Sorry, my English is translated via app*
guyp2k
Newbie
Posts: 41
Karma: 3
Re: GeoIP Rules Question
«
Reply #6 on:
August 09, 2020, 11:33:50 pm »
Thanks again, scaled down to 2 floating rules and added the interfaces, see attached.
Logged
Mondmann
Jr. Member
Posts: 73
Karma: 7
Re: GeoIP Rules Question
«
Reply #7 on:
August 09, 2020, 11:54:08 pm »
@guyp2k
OK -> reduced to 2 floating rules and added the interfaces
Your rule is not OK yet -> please have a look at geoip_2.png again! (marked with RED) or from lar.hed BlockCountries.jpg...
you recognize your error
«
Last Edit: August 10, 2020, 11:17:23 am by Mondmann
»
Logged
OPNsense 22.7.9*WG-kmod*OpenSSL*OpenVPN* AdGuardHome*i7-7700*32GB*256SSD*ix0-1, igb0-4, em0*OpenVPN+Wireguard WG0, WG1*NetGear ProSafe XS508*AP Netgear WAX610*alles echtes Blech* Sorry, my English is translated via app*
guyp2k
Newbie
Posts: 41
Karma: 3
Re: GeoIP Rules Question
«
Reply #8 on:
August 10, 2020, 12:10:28 am »
Updated, see attached.
Thanks
Logged
Mondmann
Jr. Member
Posts: 73
Karma: 7
Re: GeoIP Rules Question
«
Reply #9 on:
August 10, 2020, 12:18:58 am »
yes, and now take the correct description - >
Your No. 1 = Block Countries Destination
Your No. 2 = Block Countries Source
Logged
OPNsense 22.7.9*WG-kmod*OpenSSL*OpenVPN* AdGuardHome*i7-7700*32GB*256SSD*ix0-1, igb0-4, em0*OpenVPN+Wireguard WG0, WG1*NetGear ProSafe XS508*AP Netgear WAX610*alles echtes Blech* Sorry, my English is translated via app*
guyp2k
Newbie
Posts: 41
Karma: 3
Re: GeoIP Rules Question
«
Reply #10 on:
August 10, 2020, 01:18:24 am »
Thanks for all the help, new to opnsnese and still learning....
Logged
lar.hed
Sr. Member
Posts: 323
Karma: 10
Re: GeoIP Rules Question
«
Reply #11 on:
August 10, 2020, 08:59:04 am »
May I ask why you only like to run the floating rules on a specific interface?
In my case I run GeoIP block on ALL interfaces, in all directions, both source and target - since I never expect it to be there so to speak.
I also block ALL TOR exit nodes, in the same manner - All interfaces, All directions and both source and target.
Logged
Mondmann
Jr. Member
Posts: 73
Karma: 7
Re: GeoIP Rules Question
«
Reply #12 on:
August 10, 2020, 11:26:52 am »
@ lar.hed
I agree with this and have generally selected all interfaces.
in my attachment: geoip_3.png i only made my private entries unrecognizable...
* and excuse me i write my texts via translation tool
Greetings from Germany
«
Last Edit: August 10, 2020, 01:38:49 pm by Mondmann
»
Logged
OPNsense 22.7.9*WG-kmod*OpenSSL*OpenVPN* AdGuardHome*i7-7700*32GB*256SSD*ix0-1, igb0-4, em0*OpenVPN+Wireguard WG0, WG1*NetGear ProSafe XS508*AP Netgear WAX610*alles echtes Blech* Sorry, my English is translated via app*
lar.hed
Sr. Member
Posts: 323
Karma: 10
Re: GeoIP Rules Question
«
Reply #13 on:
August 10, 2020, 11:50:14 am »
No worries mate! I can read german, but it is way to long ago I wrote, so sorry I will save is all from even trying :-)
Logged
Julien
Hero Member
Posts: 666
Karma: 33
Re: GeoIP Rules Question
«
Reply #14 on:
August 10, 2020, 08:41:16 pm »
What countries are you blocking for in and out ?
i am just curious.
Logged
OPNsense 23.1.7_3-amd64
FreeBSD 13.1-RELEASE-p7
OpenSSL 1.1.1t 7 Feb 2023
Print
Pages: [
1
]
2
« previous
next »
OPNsense Forum
»
Archive
»
20.7 Legacy Series
»
GeoIP Rules Question