OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • [SOLVED] Geo blocking
« previous next »
  • Print
Pages: [1]

Author Topic: [SOLVED] Geo blocking  (Read 7954 times)

marjohn56

  • Hero Member
  • *****
  • Posts: 1677
  • Karma: 171
    • View Profile
[SOLVED] Geo blocking
« on: December 24, 2017, 07:33:56 pm »
I like the new way of selecting countries to block, however I get an 'error cannot allocate memory'.

Now, this may be down to me being very anti social and blocking everywhere except the three IP addresses in the Faroe islands!  8)

It appears that I get the memory error until I reduce the number of countries I am blocking and that means the number of IP addresses or ranges.

I've not looked any deeper as this may mean something to the Devs, and may need just an increase in the allocation size.
« Last Edit: January 04, 2018, 09:52:15 pm by franco »
Logged
OPNsense 21.7 - Qotom Q355G4 - ISP - Community Fibre 1Gbps.

Team Rebellion Member - If we've helped you remember to applaud

guest16985

  • Guest
Re: Geo blocking
« Reply #1 on: December 24, 2017, 10:19:17 pm »
How are you doing the blocking? Aliases or the IPS settings? What hardware are you running? How much ram do you have? What version of OPNsense?
Logged

marjohn56

  • Hero Member
  • *****
  • Posts: 1677
  • Karma: 171
    • View Profile
Re: Geo blocking
« Reply #2 on: December 24, 2017, 10:27:07 pm »
:) 17.7.11

Using Aliases.

8 Gb RAM

Try adding all countries, leave one small one out for a test and see what happens.
« Last Edit: December 24, 2017, 10:28:50 pm by marjohn56 »
Logged
OPNsense 21.7 - Qotom Q355G4 - ISP - Community Fibre 1Gbps.

Team Rebellion Member - If we've helped you remember to applaud

mimugmail

  • Hero Member
  • *****
  • Posts: 6340
  • Karma: 435
    • View Profile
Re: Geo blocking
« Reply #3 on: December 24, 2017, 10:50:24 pm »
You could try to increase the table size via advanced settings but from a performance perspective you should really consider block ANY and only allow the small country in front of the block rule
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

marjohn56

  • Hero Member
  • *****
  • Posts: 1677
  • Karma: 171
    • View Profile
Re: Geo blocking
« Reply #4 on: December 24, 2017, 11:03:17 pm »
@mimugmail

Thank you.. ;)

Increased it to 300000 and solved my problem.

I was not really trying to block the world and just allow one small island, but I do run a very limited access to servers on my network.

Actually, it was easier just to select the allowed countries and then do an invert on the firewall rule, used tunnel bear to check it and it works like a charm.

Anyway, that solved it so thanks again!
« Last Edit: December 25, 2017, 12:47:51 am by marjohn56 »
Logged
OPNsense 21.7 - Qotom Q355G4 - ISP - Community Fibre 1Gbps.

Team Rebellion Member - If we've helped you remember to applaud

opnsense-user123

  • Newbie
  • *
  • Posts: 23
  • Karma: 1
    • View Profile
Re: [SOLVED] Geo blocking
« Reply #5 on: January 04, 2018, 10:05:01 pm »
...if I have found this setting correctly, to help others, it is:

Firewall -> Settings -> Advanced and look for "Firewall Maximum Table Entries".
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • [SOLVED] Geo blocking
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2