-
Give valid e-mail address (used to send you the link)
My License Key | Generate Key
Do NOT use geoipupdate
Save key ID someplace safe
Create link
-
Test by pasting link into browser. It will download a zip file
Create alias in opnSense
Firewall | Aliases | GeoIP
-
Click Apply
Firewall Aliases | New (Plus Sign)
Name - Something you can remember, alpha-numeric and underscored only
Type - GeoIP
Select regions/countries to be included
NOTE: If you are wanting to exclude everything but some countries, ie block all but, you can simply list the countries you want to have access, then use the NOT value in the rules
Enter an optional description
Click Apply
Firewall | Rules | WAN
Action - Block
Quick - Apply acction immediately on match (check box)
Interface - WAN
Direction - in
Source/Invert - Put a check if you need to invert the GeoIP selection
Source - name of alias you created for GeoIP
Everything else is any/any, ie don't allow to anyplace
Log - put a check in Log Packets if you want them kept in your logs
Category - Attacks
Description - Block access from other countries (or whatever you want
Note: On the rules, order is important. Any Pass rule that exists prior to this rule will negate it. For example, if you have your VPN rules before this, VPN will work from other countries. Put this as high in the list as possible.