Netgate Store

Author Topic: im new to pfBlockerNG  (Read 296 times)

0 Members and 1 Guest are viewing this topic.

Offline Sharaz

  • Jr. Member
  • **
  • Posts: 82
  • Karma: +0/-0
    • View Profile
im new to pfBlockerNG
« on: January 26, 2018, 11:07:26 am »
just did my first config on pfblocker.  initially, i had an alias which contained firehol_level1 and its behavior was block both, but i immediately started getting all my internal 10.x traffic blocked.  (haha, so bad i had to console and roll back the config, as i couldnt even get to the web gui anymore).  i also removed the pfblockerNG config from all VLAN interfaces, and its just currently on WAN, LAN (oh yeah, i did leave it on 1 DEV VLAN, but not hte vlan shown below)

so i split firehol_level1 into a new alias that is inbound only block.  however, i seem to have a residual block somewhere, but im not sure what to make of this.  in the firewall rules logs, i see this:

Jan 26 11:02:19    VLAN_2541    Default deny rule IPv4 (1000000103)    10.125.41.41:445      10.125.59.69:59170      TCP:R

... but when i look at hte firewall rules for VLAN 2541 there is only the default any:any rule that i created, so i am not sure what is causing the above to be logged. 

anyone have some direction for me?
Jonathan

Offline RonpfS

  • Hero Member
  • *****
  • Posts: 753
  • Karma: +99/-2
    • View Profile
Re: im new to pfBlockerNG
« Reply #1 on: January 26, 2018, 11:21:20 am »
2.3.5-RELEASE-p2 (amd64)
Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
pfBlockerNG 2.1.2_3/Dev, suricata 4.0.4_1

Offline V3lcr0

  • Full Member
  • ***
  • Posts: 242
  • Karma: +12/-0
    • View Profile
Re: im new to pfBlockerNG
« Reply #2 on: January 29, 2018, 07:52:03 pm »
I never had luck with that list...try doing a "Force reload" with the list removed. Maybe a reinstall of package(making sure you "checked" the box that says "don't keep block or settings".