From b1ef3af0c8c141b75dc61ba9c68f80b961e9f03d Mon Sep 17 00:00:00 2001 From: BBcan177 Date: Sun, 15 Nov 2015 22:35:26 -0500 Subject: pfBlockerNG v2.0 --- config/pfblockerng/pfblockerng.xml | 217 +++++++++++++++++++++---------------- 1 file changed, 123 insertions(+), 94 deletions(-) (limited to 'config/pfblockerng/pfblockerng.xml') diff --git a/config/pfblockerng/pfblockerng.xml b/config/pfblockerng/pfblockerng.xml index d3b2cb16..c7f2c068 100644 --- a/config/pfblockerng/pfblockerng.xml +++ b/config/pfblockerng/pfblockerng.xml @@ -1,20 +1,19 @@ - - + + Describe your package requirements here Currently there are no FAQ items provided. pfblockerng - 1.09 + 2.0 pfBlockerNG: General Settings /usr/local/pkg/pfblockerng/pfblockerng.inc pfBlockerNG: Save General Settings @@ -60,84 +59,91 @@
Firewall
/pkg_edit.php?xml=pfblockerng.xml + + dnsbl + dnsbl.sh + lighttpd_pfb + pfBlockerNG DNSBL Web Server + https://packages.pfsense.org/packages/config/pfblockerng/pfblockerng.priv.inc /etc/inc/priv/ - 0644 https://packages.pfsense.org/packages/config/pfblockerng/pfblockerng.inc /usr/local/pkg/pfblockerng/ - 0644 https://packages.pfsense.org/packages/config/pfblockerng/pfblockerng_install.inc /usr/local/pkg/pfblockerng/ + + https://packages.pfsense.org/packages/config/pfblockerng/pfblockerng_extra.inc + /usr/local/pkg/pfblockerng/ + https://packages.pfsense.org/packages/config/pfblockerng/pfblockerng.php /usr/local/www/pfblockerng/ - 0644 https://packages.pfsense.org/packages/config/pfblockerng/pfblockerng_alerts.php /usr/local/www/pfblockerng/ - 0644 + + + https://packages.pfsense.org/packages/config/pfblockerng/pfblockerng_alerts_ar.php + /usr/local/www/pfblockerng/ https://packages.pfsense.org/packages/config/pfblockerng/pfblockerng_update.php /usr/local/www/pfblockerng/ - 0644 https://packages.pfsense.org/packages/config/pfblockerng/pfblockerng_log.php /usr/local/www/pfblockerng/ - 0644 - https://packages.pfsense.org/packages/config/pfblockerng/pfblockerng_diag_dns.php + https://packages.pfsense.org/packages/config/pfblockerng/pfblockerng_threats.php /usr/local/www/pfblockerng/ - 0644 https://packages.pfsense.org/packages/config/pfblockerng/pfblockerng.widget.php /usr/local/www/widgets/widgets/ - 0644 https://packages.pfsense.org/packages/config/pfblockerng/widget-pfblockerng.inc /usr/local/www/widgets/include/ - 0644 https://packages.pfsense.org/packages/config/pfblockerng/pfblockerng.js /usr/local/www/widgets/javascript/ - 0644 https://packages.pfsense.org/packages/config/pfblockerng/pfblockerng_top20.xml /usr/local/pkg/pfblockerng/ - 0644 + + + https://packages.pfsense.org/packages/config/pfblockerng/pfblockerng_dnsbl.xml + /usr/local/pkg/pfblockerng/ + + + https://packages.pfsense.org/packages/config/pfblockerng/pfblockerng_dnsbl_lists.xml + /usr/local/pkg/pfblockerng/ + + + https://packages.pfsense.org/packages/config/pfblockerng/pfblockerng_dnsbl_easylist.xml + /usr/local/pkg/pfblockerng/ https://packages.pfsense.org/packages/config/pfblockerng/pfblockerng_v4lists.xml /usr/local/pkg/pfblockerng/ - 0644 https://packages.pfsense.org/packages/config/pfblockerng/pfblockerng_v6lists.xml /usr/local/pkg/pfblockerng/ - 0644 https://packages.pfsense.org/packages/config/pfblockerng/pfblockerng_sync.xml /usr/local/pkg/pfblockerng/ - 0644 - - - https://packages.pfsense.org/packages/config/pfblockerng/countrycodes.tar.bz2 - /var/db/pfblockerng/ - 0444 https://packages.pfsense.org/packages/config/pfblockerng/pfblockerng.sh @@ -145,14 +151,14 @@ 0755 - https://packages.pfsense.org/packages/config/pfblockerng/geoipupdate.sh - /usr/local/pkg/pfblockerng/ + https://packages.pfsense.org/packages/config/pfblockerng/index.php + /usr/local/www/pfblockerng/www/ 0755 General - /pkg_edit.php?xml=pfblockerng.xml&id=0 + /pkg_edit.php?xml=pfblockerng.xml @@ -165,47 +171,23 @@ Reputation - /pkg_edit.php?xml=/pfblockerng/pfblockerng_reputation.xml&id=0 + /pkg_edit.php?xml=/pfblockerng/pfblockerng_reputation.xml IPv4 - /pkg.php?xml=/pfblockerng/pfblockerng_v4lists.xml&id=0 + /pkg.php?xml=/pfblockerng/pfblockerng_v4lists.xml IPv6 - /pkg.php?xml=/pfblockerng/pfblockerng_v6lists.xml&id=0 - - - Top20 - /pkg_edit.php?xml=/pfblockerng/pfblockerng_top20.xml&id=0 - - - Africa - /pkg_edit.php?xml=/pfblockerng/pfblockerng_Africa.xml&id=0 - - - Asia - /pkg_edit.php?xml=/pfblockerng/pfblockerng_Asia.xml&id=0 + /pkg.php?xml=/pfblockerng/pfblockerng_v6lists.xml - Europe - /pkg_edit.php?xml=/pfblockerng/pfblockerng_Europe.xml&id=0 + DNSBL + /pkg_edit.php?xml=/pfblockerng/pfblockerng_dnsbl.xml - N.A. - /pkg_edit.php?xml=/pfblockerng/pfblockerng_NorthAmerica.xml&id=0 - - - Oceania - /pkg_edit.php?xml=/pfblockerng/pfblockerng_Oceania.xml&id=0 - - - S.A. - /pkg_edit.php?xml=/pfblockerng/pfblockerng_SouthAmerica.xml&id=0 - - - P.S. - /pkg_edit.php?xml=/pfblockerng/pfblockerng_ProxyandSatellite.xml&id=0 + Country + /pkg_edit.php?xml=/pfblockerng/pfblockerng_top20.xml Logs @@ -213,7 +195,7 @@ Sync - /pkg_edit.php?xml=/pfblockerng/pfblockerng_sync.xml&id=0 + /pkg_edit.php?xml=/pfblockerng/pfblockerng_sync.xml @@ -224,8 +206,8 @@ LINKS - Firewall Alias     - Firewall Rules     Firewall Logs]]> + Firewall Alias  + Firewall RulesFirewall Logs]]> info @@ -241,7 +223,7 @@ pfb_keep checkbox Note: - with 'Keep settings' enabled, pfBlockerNG will maintain run state - on Installation/Upgrade
If 'Keep Settings' is not 'enabled' on pkg Install/De-Install, all Settings will be Wiped!

+ on Installation/Upgrade
If 'Keep Settings' is not 'enabled' on pkg Install/De-Install, all settings will be Wiped!

Note: To clear all downloaded lists, uncheck these two checkboxes and 'Save'. re-check both boxes and run a 'Force Update']]>
@@ -258,8 +240,8 @@ Hour Interval pfb_interval Every hour
- Select the cron Hour Interval. The interval selected will be used with the Start min/hour below.
- Ensure that all List 'Update Settings' are within the selected Interval/Start Hour Settings.]]> + Select the cron hour interval. The interval selected will be used with the start min/hour below.
+ Ensure that all list 'Update settings' are within the selected interval/start hour settings.]]>
select @@ -295,7 +277,7 @@ Start Hour pfb_hour 0
- Select the Start Hour]]> + Select the start hour]]>
select @@ -330,7 +312,7 @@ Start Hour]]> pfb_dailystart - 0
This is used for the 'Daily/Weekly' Scheduler Only.]]>
+ 0
This is used by the 'Daily/Weekly' scheduler only.]]>
select @@ -367,14 +349,20 @@ checkbox Only for IPv4 Lists
+ + Enable Aggregation of CIDRs + enable_agg + checkbox + Optimise CIDRs (not recommended for slow systems with large lists) + Enable Suppression suppression checkbox - - Country Blocking Lists cannot be Suppressed.
This will also remove any RFC1918 addresses from all Lists.

- Alerts can be Suppressed using the '+' icon in the Alerts Tab and IPs added to the 'pfBlockerNGSuppress' Alias
- A Blocked IP in a CIDR other than /32 or /24 will need a 'Whitelist Alias' w/ List Action: 'Permit Outbound' Firewall Rule + + Country blocking lists cannot be suppressed.
This will also remove any RFC1918 addresses from all lists.

+ Alerts can be suppressed using the '+' icon in the Alerts tab and IPs added to the 'pfBlockerNGSuppress' alias
+ A blocked IP in a CIDR other than /32 or /24 will need a 'Whitelist alias' w/ list action: 'Permit Outbound' Firewall rule
Do not use the pfBlockerNGSuppress Alias in a Firewall Rule. This alias is used during the cron download process only.]]>
@@ -383,17 +371,44 @@ Global Enable Logging enable_log checkbox - - This overrides any Log Settings in the Alias Tabs.]]> + + This overrides any log settings in the Alias tabs.]]>
- Disable MaxMind Country Database CRON Updates + Disable MaxMind Country database CRON updates database_cc checkbox - - This does not affect the MaxMind Binary Cron Task]]> + + This does not affect the MaxMind binary cron task]]> + + + + Max daily download failure threshold + skipfeed + 0 (Disabled)
+ Select max daily download failure threshold via CRON. Clear widget 'failed downloads' to reset.]]>
+ select + + + + + + + + + + 0 +
+ + Restore previous download on failure + restore_feed + checkbox + Enabled
+ When 'selected', on a download failure, the previously downloaded list is restored.]]> +
+ on
Logfile Size @@ -423,25 +438,26 @@ inbound_interface Interface(s) - Select the Inbound interface(s) you want to Apply Auto Rules to + Select the Inbound interface(s) you want to apply auto rules to: interfaces_selection loopback + wan Rule Action inbound_deny_action - Block
Select 'Rule Action' for Inbound Rules]]>
+ Block
Select 'Rule action' for Inbound rules:]]>
select - block end + block
Outbound Firewall Rules @@ -450,38 +466,39 @@ Interface(s) outbound_interface - Select the Outbound interface(s) you want to Apply Auto Rules to + Select the Outbound interface(s) you want to apply auto rules to: interfaces_selection loopback + lan Rule Action outbound_deny_action - Reject
Select 'Rule Action' for Outbound rules]]>
+ Reject
Select 'Rule action' for Outbound rules:]]>
select - reject + reject end
OpenVPN Interface openvpn_action checkbox - Select to add Auto-Rules for OpenVPN. These will be added to 'Floating Rules' or OpenVPN Rules Tab. + Select to add auto-rules for OpenVPN. These will be added to 'Floating Rules' or OpenVPN rules tab. Floating Rules enable_float checkbox - Enabled: Auto-Rules will be generated in the 'Floating Rules' Tab

- Disabled: Auto-Rules will be generated in the Selected Inbound/Outbound Interfaces

+ Enabled: Auto-rules will be generated in the 'Floating Rules' tab

+ Disabled: Auto-rules will be generated in the selected Inbound/Outbound interfaces

Rules will be ordered by the selection below.]]>
@@ -490,8 +507,8 @@ pass_order Default Order: | pfB_Block/Reject | All other Rules | (original format)

Select The 'Order' of the Rules
-   Selecting 'original format', sets pfBlockerNG rules at the top of the Firewall TAB.
-   Selecting any other 'Order' will re-order all the Rules to the format indicated!]]> +  Selecting 'original format', sets pfBlockerNG rules at the top of the Firewall TAB.
+  Selecting any other 'Order' will re-order all the rules to the format indicated!]]>
select @@ -506,7 +523,7 @@ Auto Rule Suffix autorule_suffix auto rule
- Select 'Auto Rule' Description Suffix for Auto Defined rules. pfBlockerNG Must be Disabled to Modify Suffix]]> + Select 'Auto Rule' description suffix for auto defined rules. pfBlockerNG must be disabled to modify suffix]]>
select @@ -516,6 +533,14 @@ autorule
+ + Kill States + killstates + checkbox + + Firewall states will be cleared.]]> + + listtopic @@ -525,11 +550,11 @@ credits info pfBlockerNG - Created in 2015 by BBcan177.

+ Created in 2015 by BBcan177.

Based upon pfBlocker by Marcello Coutinho and Tom Schaefer.
- Country Database GeoLite distributed under the Creative Commons Attribution-ShareAlike 3.0 Unported License by: - MaxMind Inc. @ MaxMind.com. - The Database is Automatically Updated the First Tuesday of Each Month]]> + Country database GeoLite distributed under the Creative Commons Attribution-ShareAlike 3.0 Unported License by: + MaxMind Inc. @ MaxMind.com. + The database is automatically updated the first Tuesday of each month]]>
@@ -540,7 +565,7 @@ - Click to SAVE Settings and/or Rule Edits.       Changes are Applied via CRON or + Click to SAVE Settings and/or Rule edits.   Changes are applied via CRON or 'Force Update']]> listtopic @@ -556,11 +581,15 @@ ]]> + +
\ No newline at end of file -- cgit v1.2.3