OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • ( Solved )Block USA
« previous next »
  • Print
Pages: [1]

Author Topic: ( Solved )Block USA  (Read 7878 times)

Julien

  • Hero Member
  • *****
  • Posts: 666
  • Karma: 33
    • View Profile
( Solved )Block USA
« on: April 21, 2018, 10:04:34 pm »
Hi Guys,
We are willing to block USA on the IDS.
Wenever we Block USA on the IDS the emails are originally from Office 365 and Outlook/Gmail stops arriving.
is there is a way to get those working with blocking USA ?
« Last Edit: April 26, 2018, 03:29:21 pm by Julien »
Logged
OPNsense 23.1.7_3-amd64
FreeBSD 13.1-RELEASE-p7
OpenSSL 1.1.1t 7 Feb 2023

bartjsmit

  • Hero Member
  • *****
  • Posts: 2023
  • Karma: 194
    • View Profile
Re: Block USA
« Reply #1 on: April 22, 2018, 09:36:18 am »
Hi Julien,

Point your MX record to a mail filter in the DMZ and don't IDS that traffic. Something like https://efa-project.org/

Bart...
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: Block USA
« Reply #2 on: April 22, 2018, 11:03:48 am »
Block via GeoIP Alias. You can allow SMTP globally and then deny USA
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

Julien

  • Hero Member
  • *****
  • Posts: 666
  • Karma: 33
    • View Profile
Re: Block USA
« Reply #3 on: April 22, 2018, 10:30:47 pm »
Quote from: mimugmail on April 22, 2018, 11:03:48 am
Block via GeoIP Alias. You can allow SMTP globally and then deny USA
the IP of the spam filter is a virtual IP which is pointing to the spam filter internally. so when the IDS is active it does apply on the both interfaces.
i would love to know how to configure this mimugmail.
do you have somewhere a tutorial or something ?

Logged
OPNsense 23.1.7_3-amd64
FreeBSD 13.1-RELEASE-p7
OpenSSL 1.1.1t 7 Feb 2023

Julien

  • Hero Member
  • *****
  • Posts: 666
  • Karma: 33
    • View Profile
Re: Block USA
« Reply #4 on: April 24, 2018, 01:25:08 am »
Quote from: bartjsmit on April 22, 2018, 09:36:18 am
Hi Julien,

Point your MX record to a mail filter in the DMZ and don't IDS that traffic. Something like https://efa-project.org/

Bart...
Hi Bart,
We do have two WANS.
WAN1 . using for internet / VPN / OWA
WAN2. using for the mx records and pointing to the spam filter

WAN1 is a physical NIC and WAN2 is Virtual IP configured.
whenever we enable the IDS we include both WAN1 and LAN but somehow WAN2 is reacting on the block.

is this the right way of doing things ?
Logged
OPNsense 23.1.7_3-amd64
FreeBSD 13.1-RELEASE-p7
OpenSSL 1.1.1t 7 Feb 2023

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: Block USA
« Reply #5 on: April 24, 2018, 06:19:30 am »
WAN2 is a Virtual IP and sitting on which physical interface?

Geoblocking with IPS is not the right way doing things (since 17.7.x).

Use GeoIP Alias, it's easier and more powerful, just try it.
« Last Edit: April 24, 2018, 06:21:14 am by mimugmail »
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

Julien

  • Hero Member
  • *****
  • Posts: 666
  • Karma: 33
    • View Profile
Re: Block USA
« Reply #6 on: April 24, 2018, 06:15:06 pm »
Quote from: mimugmail on April 24, 2018, 06:19:30 am
WAN2 is a Virtual IP and sitting on which physical interface?

Geoblocking with IPS is not the right way doing things (since 17.7.x).

Use GeoIP Alias, it's easier and more powerful, just try it.
Hi Mimugmail
thank you for your continue support
the virtual IP is on the WAN interfaces nested see attached screenshot.

When we block UK the websites that are hosted in the UK won't open ?

Can you explain how to get the GeoIP Alias configured ?

« Last Edit: April 24, 2018, 06:32:26 pm by Julien »
Logged
OPNsense 23.1.7_3-amd64
FreeBSD 13.1-RELEASE-p7
OpenSSL 1.1.1t 7 Feb 2023

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: Block USA
« Reply #7 on: April 24, 2018, 08:14:32 pm »
https://docs.opnsense.org/manual/aliases.html


Then set up a firewall rule with this alias.
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

Julien

  • Hero Member
  • *****
  • Posts: 666
  • Karma: 33
    • View Profile
Re: Block USA
« Reply #8 on: April 24, 2018, 09:07:54 pm »
Quote from: mimugmail on April 24, 2018, 08:14:32 pm
https://docs.opnsense.org/manual/aliases.html


Then set up a firewall rule with this alias.
Thank you for your answer,
are you suggesting to turn off the Intrusion Detection (GeoIP/Country  ) and use GeoIP ( firewall Rules ) to block countries ?
Logged
OPNsense 23.1.7_3-amd64
FreeBSD 13.1-RELEASE-p7
OpenSSL 1.1.1t 7 Feb 2023

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: Block USA
« Reply #9 on: April 24, 2018, 09:42:29 pm »
Yes, it's way more flexible and delivers better performance.
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

Julien

  • Hero Member
  • *****
  • Posts: 666
  • Karma: 33
    • View Profile
Re: Block USA
« Reply #10 on: April 24, 2018, 09:53:58 pm »
Quote from: mimugmail on April 24, 2018, 09:42:29 pm
Yes, it's way more flexible and delivers better performance.
Thank you for the answer,
the GeoIP does the job. however i cannot seem to see the countries that are blocked on the firewall >> Diagnostic >>>PFtables...
« Last Edit: April 28, 2018, 12:03:07 am by Julien »
Logged
OPNsense 23.1.7_3-amd64
FreeBSD 13.1-RELEASE-p7
OpenSSL 1.1.1t 7 Feb 2023

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • ( Solved )Block USA
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2