OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • IP and URL Block Lists
« previous next »
  • Print
Pages: [1] 2

Author Topic: IP and URL Block Lists  (Read 23699 times)

Noob3

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
IP and URL Block Lists
« on: October 14, 2017, 04:50:08 pm »
I am a PfSense user at the moment and the one thing I am obsessed with is IP and URL Block Lists.

Is there going to be a package like PFblocker for Opnsense??
Also country blocker?

Or is that on the to do list ;)

Many thanks this looks like a great firewall project ;)
Logged

phoenix

  • Hero Member
  • *****
  • Posts: 545
  • Karma: 58
    • View Profile
Re: IP and URL Block Lists
« Reply #1 on: October 14, 2017, 04:59:45 pm »
How about Suricata (the inline IPS), you can find more details here: https://wiki.opnsense.org/manual/ips.html
Logged
Regards


Bill

fabian

  • Hero Member
  • *****
  • Posts: 2769
  • Karma: 200
  • OPNsense Contributor (Language, VPN, Proxy, etc.)
    • View Profile
    • Personal Homepage
Re: IP and URL Block Lists
« Reply #2 on: October 14, 2017, 05:07:36 pm »
URL Blocking: https://docs.opnsense.org/manual/how-tos/proxywebfilter.html
Logged

Noob3

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
Re: IP and URL Block Lists
« Reply #3 on: October 18, 2017, 12:39:40 pm »
O thats fantastic I like that ;) looks great!
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: IP and URL Block Lists
« Reply #4 on: October 18, 2017, 02:17:10 pm »
Geoblocking via Aliases will receive a really nice update within the next releases:

https://github.com/opnsense/core/issues/1860#issuecomment-336718443
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17706
  • Karma: 1618
    • View Profile
Re: IP and URL Block Lists
« Reply #5 on: October 18, 2017, 11:07:59 pm »
Sorry for the ugly dev capture there (mea culpa), the end result is:

https://user-images.githubusercontent.com/1915288/31587781-d9435510-b1e7-11e7-9a23-7a88c0a663b1.png

It'll be in 17.7.7.


Cheers,
Franco
Logged

cyberzeus

  • Newbie
  • *
  • Posts: 11
  • Karma: 0
    • View Profile
Re: IP and URL Block Lists
« Reply #6 on: December 31, 2017, 08:53:01 am »
Hello OPNsense folks,

Aside from the proxy method described here, I have read that this functionality can be accomplished using aliases.  However, even with that, there is a lot of pfBlocker functionality not present in OPNsesne that, if added, would be of great benefit to the platform.

With that in mind, are there any plans to provide a fully functional pfB port or similar to OPNsense? 

It is a very useful and powerful package as it offloads a lot of load and resource drain from the IPS and adds in other functionality as well.

Thanks.
« Last Edit: December 31, 2017, 10:03:08 am by cyberzeus »
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17706
  • Karma: 1618
    • View Profile
Re: IP and URL Block Lists
« Reply #7 on: January 04, 2018, 10:03:39 pm »
The plan has been repeated a lot in this forum, not just lately. Let me reiterate.

Make a suggestion on GitHub about what part of pfBlockerNG you are interested in and we will work on a seamless integration. The goal cannot be to port the package. It's very powerful indeed, but it could be even more so if part of the core functionality with streamlined UX.

That being said, others have committed privately to working on particular parts of the integration, namely feeds, whitelists, IP and Host/ASN. The more the merrier. Usually all it takes is for one person to kickstart the work. :)


Cheers,
Franco
Logged

l0rdraiden

  • Jr. Member
  • **
  • Posts: 59
  • Karma: 4
    • View Profile
Re: IP and URL Block Lists
« Reply #8 on: August 24, 2018, 07:55:07 pm »
Any news about how this is evolving?
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: IP and URL Block Lists
« Reply #9 on: August 24, 2018, 08:50:56 pm »
With 18.7.1 there is a Bind plugin where you can use DNSBLs like PiHole or pfBlockerNG.
Just install, enable, and do a portforward from some test IPs ..
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

l0rdraiden

  • Jr. Member
  • **
  • Posts: 59
  • Karma: 4
    • View Profile
Re: IP and URL Block Lists
« Reply #10 on: August 25, 2018, 11:40:16 am »
Yeah but that would imply to run pfsense with pfblockerng  and opnsense at the same time, which make no sense if you can simply run pfsense.

Someone mention that there was people working in private to bring some pfblockerng capabilities to opnsense, any news about this?
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: IP and URL Block Lists
« Reply #11 on: August 25, 2018, 12:51:23 pm »
Why would you need pfsense when OPN has a Bind Plugin supporting DNSBL?
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

l0rdraiden

  • Jr. Member
  • **
  • Posts: 59
  • Karma: 4
    • View Profile
Re: IP and URL Block Lists
« Reply #12 on: August 25, 2018, 02:05:39 pm »
Sorry I understood you wrong.

And then for IPBlock lists is there any option?
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: IP and URL Block Lists
« Reply #13 on: August 25, 2018, 02:07:49 pm »
It's already possible via URL Table alias:

https://docs.opnsense.org/manual/aliases.html#url-tables
https://www.routerperformance.net/opnsense/using-pfblocker-features-in-opnsense/
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

l0rdraiden

  • Jr. Member
  • **
  • Posts: 59
  • Karma: 4
    • View Profile
Re: IP and URL Block Lists
« Reply #14 on: August 26, 2018, 11:11:22 am »
It's possible to whitelist DNSBL and IP false block easily?
It's possible apply the block lists only to specific ports?
Does opnsense merge the lists to avoid duplicated entries?
Logged

  • Print
Pages: [1] 2
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • IP and URL Block Lists
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2