Project

General

Profile

Actions

Feature #14911

closed

Feature request - System Aliases

Added by Wolfgang Thegreat 7 months ago. Updated 7 months ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Category:
Aliases / Tables
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Default

Description

Hello,

I wish to ask for something I call "System Aliases".

At times there is a need to have a list of IPs and/or IP ranges, of different prominent services provider, but these IPs change from time to time and they are not under any unifying FQDN.

But, having them as one named object in pfSense, as a System Alias to use in the fw rulebase, will be awesome.

For example, Cloudflare, which is a large cloud CDN/Proxy/WAF, and many need to allow it access to their web server, but it has many ranges, as you can see at https://www.cloudflare.com/ips/.

It is not practical for any person or firm to manually track changes in this list and update it manually in pfSense, in a timely fashion.

But, CF also share this data in per-line, plain text, public files:
https://www.cloudflare.com/ips-v4/#
https://www.cloudflare.com/ips-v6/#

I guess Netgate can have a process to read these files in a recurring schedule, either from each pfSense device, or centrally (and the pfSense devices will read it from a pfSense server, also in recurring schedule) - and make out of it a fixed System Alias objects, like Cloudflare_IPv4 , Cloudflare_IPv6 and Cloudflare_IP_All, which users will be able to add to fw rules and they will know they will always get the exact, correct and real-time updated IP ranges that CF publish, automatically.

Thank you.

Actions #1

Updated by Wolfgang Thegreat 7 months ago

I posted this feature request also at the community forum, at https://forum.netgate.com/topic/183570/feature-request-system-aliases and I was informed there that this feature is mostly already exists as "URL Table (IPs)", which is great, but still - it will be nice if Netgate will have ready objects for user just to use, out of the box, without them needing to go look for these URL sources, it will save lots of time for them.

Actions #2

Updated by Jim Pingle 7 months ago

  • Status changed from New to Rejected

This is already possible both via URL table aliases and also via pfBlockerNG and various methods in there such as building lists by AS number.

Actions

Also available in: Atom PDF