Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
pfSense Forum
pfSense English Support
»
Packages
»
pfBlocker
Username:
Password:
1 Hour
1 Day
1 Week
1 Month
Forever
Home
Help
Search
Login
Register
Pages:
1
...
24
25
26
27
[
28
]
29
30
31
32
...
45
Go Down
« previous
next »
Print
Author
Topic: pfBlocker (Read 103628 times)
0 Members and 2 Guests are viewing this topic.
LinuxTracker
Full Member
Offline
Posts: 117
Re: pfBlocker
«
Reply #405 on:
February 22, 2012, 12:33:01 am »
I know Rules ReOrdering after a pfBlocker change has been covered in this thread.
I'd like to bring it back up because it's making me crazy.
Here's my situation.
I use the pfBlocker widget. I also have my rules customized and ordered a certain way.
In the last pfBlocker ver., I'd set every Action to Deny Inbound.
Next I'd customize and reorder the auto-created rules. I'd be finished in 10 min or so.
I'm pretty sure pfBlocker automatically changed Action to Alias when I had adjusted the rules.
The end result was the rules wouldn't change after an update.
In this latest pfBlocker ver., my last method doesn't work. I have to set action to Alias myself.
If I don't, my rule changes are wiped out after every update.
So, I make any changes at all to pfBlocker, I'm re-writing my blocking rules totally from scratch.
It's the only way I can have Widget+CustomizedRules+CustomRulesOrder.
It's doubled my time to restore settings after each pfBlocker config change.
Selecting a single country becomes a 20+min process, per machine.
I'm to weary to come up with any helpful suggestions/workarounds right now.
I'll revisit the thread when my brain is working again.
Thanks.
edit: I had another look at the Backup feature and discovered the option for FirewallRules.
I've make my copy and will try to restore from it after my next pfBlocker change.
«
Last Edit: February 22, 2012, 12:48:06 am by LinuxTracker
»
Logged
marcelloc
Hero Member
Offline
Posts: 8111
Re: pfBlocker
«
Reply #406 on:
February 22, 2012, 05:22:41 am »
Linuxtracker,
After a update, as well as I know, you need just to enable pfBlocker to get all your settings working again.
Maybe I misundertood you but I did not coded an automatic action switch from deny to alias only.
The steps I do for rule reordering are:
Apply pfBlocker conf with action I want on rules.
Change alias description on created firewall rules and then customize it's order.
Back on pfBlocker and change action to alias only.
Logged
Have I helped you?
Donations are always welcome!
Te ajudei?
Doações são sempre bem vindas!
LinuxTracker
Full Member
Offline
Posts: 117
Re: pfBlocker
«
Reply #407 on:
February 23, 2012, 01:16:24 am »
Quote from: marcelloc on February 22, 2012, 05:22:41 am
1) Apply pfBlocker conf with action I want on rules.
2) Change alias description on created firewall rules and then customize it's order.
3) Back on pfBlocker and change action to alias only.
I did #1 and #2 and had just started on #3.
The moment I set the first country-group to alias (S.America) it tosses that country group off the list.
The remaining rules - order and customizations - were all reset.
As near as I can tell, any change at all in pfBlocker now mandates that I rewrite my rules from scratch.
It may be that every list update does the same.
I offer that because the rules table completely reset about 11:30pm today - I have to rewrite them again.
«
Last Edit: February 23, 2012, 01:38:16 am by LinuxTracker
»
Logged
marcelloc
Hero Member
Offline
Posts: 8111
Re: pfBlocker
«
Reply #408 on:
February 23, 2012, 08:59:09 am »
Linuxtracker,
How are you renaming rule description before changing action to alias only?
I did a clean install and then:
Installed pfblocker
denied inbound access to argentina and some countries on Oceania
Renamed the rule description from South America to block Argentina
saved firewall rules and applied changes
back to pfblocker, set action to alias only on South America tab
saved config
After this, both rules(South america and Oceania) are still there.
I'll do some tests with lists applied too.
«
Last Edit: February 23, 2012, 09:01:43 am by marcelloc
»
Logged
Have I helped you?
Donations are always welcome!
Te ajudei?
Doações são sempre bem vindas!
LinuxTracker
Full Member
Offline
Posts: 117
Re: pfBlocker
«
Reply #409 on:
February 23, 2012, 12:41:59 pm »
Quote from: marcelloc on February 23, 2012, 08:59:09 am
Linuxtracker,
How are you renaming rule description before changing action to alias only?
I don't change the rule descriptions that are generated by pfBlocker.
I figured they were necessary for the widget to work.
When I write the rules from scratch, the descriptions are identical to the pfBlocker generated ones.
ie:
Code:
pfBlockerSouthAmerica auto rule
Thanks
Logged
LinuxTracker
Full Member
Offline
Posts: 117
Re: pfBlocker
«
Reply #410 on:
February 23, 2012, 12:46:01 pm »
Quote from: marcelloc on February 23, 2012, 08:59:09 am
I did a clean install and then:
Installed pfblocker
denied inbound access to Argentina and some countries on Oceania
Renamed the rule description from South America to block Argentina
saved firewall rules and applied changes
back to pfblocker, set action to alias only on South America tab
saved config
After this, both rules(South America and Oceania) are still there.
I'll do some tests with lists applied too.
I need to clarify something.
Renamed the rule description from South America to block Argentina
You mean you changed the rule description from "South America", so that it read "block Argentina" - correct?
The last time I changed my rule descriptions, my pfBlocker widget quit working.
So, I've kept my rules descriptions identical to whatever pfBlocker created.
But:
It seems we can rename the pfBlocker-generated alias name
as long as the new alias name is at the beginning of the rules description.
That won't break the widget. Do I understand correctly?
Logged
marcelloc
Hero Member
Offline
Posts: 8111
Re: pfBlocker
«
Reply #411 on:
February 23, 2012, 12:55:10 pm »
Linuxtracker,
I've changed rule description to "pfBlockerSouthAmerica deny inbound" to do not break widget and also included a list with every hour update and rules are still there.
Logged
Have I helped you?
Donations are always welcome!
Te ajudei?
Doações são sempre bem vindas!
LinuxTracker
Full Member
Offline
Posts: 117
Re: pfBlocker
«
Reply #412 on:
February 23, 2012, 01:58:46 pm »
Quote from: marcelloc on February 23, 2012, 12:55:10 pm
Linuxtracker,
I've changed rule description to "pfBlockerSouthAmerica deny inbound" to do not break widget and also included a list with every hour update and rules are still there.
OK Thanks for your time on this.
I'll uninstall the package tonight and see what a fresh start yields.
Question: How do I force a manual list update?
Logged
marcelloc
Hero Member
Offline
Posts: 8111
Re: pfBlocker
«
Reply #413 on:
February 23, 2012, 02:30:47 pm »
Quote from: LinuxTracker on February 23, 2012, 01:58:46 pm
Question: How do I force a manual list update?
As I forgot to include this option, you can change update frequency to every hour and then run
/usr/local/bin/php -q /usr/local/www/pfblocker.php cron
on console.
Logged
Have I helped you?
Donations are always welcome!
Te ajudei?
Doações são sempre bem vindas!
LinuxTracker
Full Member
Offline
Posts: 117
Re: pfBlocker
«
Reply #414 on:
February 24, 2012, 03:49:06 am »
Quote from: marcelloc on February 23, 2012, 12:55:10 pm
Linuxtracker,
I've changed rule description to "pfBlockerSouthAmerica deny inbound" to do not break widget and also included a list with every hour update and rules are still there.
My custom lists weren't pulling new updates. I don't think the countries were updating either.
So I uninstalled the package and deleted the pgblocker*.xml files in /usr/local/pkg.
After reinstalling pfBlocker, both lists and countries updated correctly.
After that, I followed your guide as before.
Once my rules were setup, I went back into pfBlocker and changed Oceana from Deny All to Alias
and all my rule changes and ordering were thrown out.
That made me sad.
Update
:
So with a heavy heart I set out to rewrite my rules from scratch.
I set the rest of the pfBlocker options to Alias and applied the settings.
I next went to rules - and discovered that my rule settings and ordering - were restored back to where I wanted them.
I am no longer sad. Now I am confused.
«
Last Edit: February 24, 2012, 04:48:27 am by LinuxTracker
»
Logged
marcelloc
Hero Member
Offline
Posts: 8111
Re: pfBlocker
«
Reply #415 on:
February 24, 2012, 08:57:18 am »
Quote from: LinuxTracker on February 24, 2012, 03:49:06 am
My custom lists weren't pulling new updates. I don't think the countries were updating either.
Did you tried to run it on console the way I described to you?
Quote from: LinuxTracker on February 24, 2012, 03:49:06 am
I don't think the countries were updating either.
Country lists are updated on pfblocker releases, not via cron job.
Quote from: LinuxTracker on February 24, 2012, 03:49:06 am
So I uninstalled the package and deleted the pgblocker*.xml files in /usr/local/pkg.
After reinstalling pfBlocker, both lists and countries updated correctly.
After that, I followed your guide as before.
Once my rules were setup, I went back into pfBlocker and changed Oceana from Deny All to Alias
and all my rule changes and ordering were thrown out.
That made me sad.
Update
:
So with a heavy heart I set out to rewrite my rules from scratch.
I set the rest of the pfBlocker options to Alias and applied the settings.
I next went to rules - and discovered that my rule settings and ordering - were restored back to where I wanted them.
I am no longer sad. Now I am confused.
I'll keep trying to simulate this issue.
All tests I did, preserving the aliasname on firewall rule description were fine.
Logged
Have I helped you?
Donations are always welcome!
Te ajudei?
Doações são sempre bem vindas!
LinuxTracker
Full Member
Offline
Posts: 117
Re: pfBlocker
«
Reply #416 on:
February 24, 2012, 03:18:18 pm »
Quote from: marcelloc on February 24, 2012, 08:57:18 am
Did you tried to run it on console the way I described to you?
Yes. That did work and helped me to find a misspelled list name.
It'll also come in handy in the future.
Quote from: LinuxTracker on February 24, 2012, 03:49:06 am
Country lists are updated on pfblocker releases, not via cron job.
After I uninstalled the package -> deleted the pfblocker*.xml files -> reinstalled it - the country lists updated normally.
I think the package handler was wonky and didn't update pfblocker properly the last time.
Quote from: LinuxTracker on February 24, 2012, 03:49:06 am
I'll keep trying to simulate this issue.
All tests I did, preserving the aliasname on firewall rule description were fine.
That my rules would suddenly show correctly - after they were reset - seems really strange.
I have other pfSense boxes out there. I'll update one or two of them and see if any issues pop up.
I certainly appreciate your efforts.
For now I'll keep looking into things on my end.
Logged
archy
Newbie
Offline
Posts: 6
Re: pfBlocker
«
Reply #417 on:
February 29, 2012, 01:06:31 pm »
My exp for using pfBlocker ,
if I set max table size = 100000 ,
there still have error logged ,
php: : New alert found: There were error(s) loading the rules: /tmp/rules.debug:23: cannot define table pfBlockerNorthAmerica: Cannot allocate memory pfctl: Syntax error in config file: pf rules not loaded The line in question reads [23]: table <pfBlockerNorthAmerica> persist file "/var/db/aliastables/pfBlockerNorthAmerica.txt"
if I set max table size = 1000000
problem solve , just like to share .
Logged
dhatz
Hero Member
Offline
Posts: 921
Re: pfBlocker
«
Reply #418 on:
February 29, 2012, 01:22:02 pm »
I wonder if the pfBlocker developers have considered using pf anchors (
http://openbsd.org/faq/pf/anchors.html
) ?
IMHO it'd be a nice design practice for pfsense packages to use anchors.
Check article
http://forum.pfsense.org/index.php/topic,45277.0.html
which among others notes the recent pf extensions by Apple to make sure Mac OS X applications that interact with the packet filter configuration do not clobber each others' rules.
«
Last Edit: February 29, 2012, 01:24:12 pm by dhatz
»
Logged
marcelloc
Hero Member
Offline
Posts: 8111
Re: pfBlocker
«
Reply #419 on:
February 29, 2012, 01:31:13 pm »
dhatz,
Pfblocker use pfsense firewall rules and url table.
No pf rule is created by this package, only xml info to pfsense alias and rules.
anyway, thanks for this suggestion
Logged
Have I helped you?
Donations are always welcome!
Te ajudei?
Doações são sempre bem vindas!
Pages:
1
...
24
25
26
27
[
28
]
29
30
31
32
...
45
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Administrative
-----------------------------
=> Forum rules
=> Messages from the pfSense Team
=> Feedback
-----------------------------
pfSense English Support
-----------------------------
=> Installation and Upgrades
=> General Questions
=> 2.1 Snapshot Feedback and Problems
=> Post a bounty
===> Completed Bounties
===> Expired/Withdrawn Bounties
=> Hardware
=> Firewalling
=> NAT
=> CARP/VIPs
=> Routing and Multi WAN
=> Traffic Shaping
=> DHCP and DNS
=> IPv6
=> IPsec
=> PPTP
=> PPPoE Server
=> Captive Portal
=> webGUI
=> Wireless
=> SNMP
=> Packages
=> Virtualization installations and techniques
=> OpenVPN
=> Gaming
-----------------------------
Development/Documentation
-----------------------------
=> Documentation
=> Development
-----------------------------
General Category
-----------------------------
=> General Discussion
-----------------------------
International Support
-----------------------------
=> Indonesian
=> Deutsch
=> Español
=> Français
=> Italiano
=> Russian
=> Nederlands
=> Norwegian
=> Portuguese
=> Polish
=> Romanian
=> Swedish
=> Turkish
-----------------------------
Retired
-----------------------------
=> 1.2.3-PRERELEASE-TESTING snapshots - RETIRED
=> 1.2.1-RC Snapshot Feedback and Problems-RETIRED
=> 2.0-RC Snapshot Feedback and Problems - RETIRED
=> DNS Server testing area - RETIRED
Loading...