• pfBlockerNG Cron Kills all my connections

    1
    0 Votes
    1 Posts
    144 Views
    No one has replied
  • xxx.xxx.xxx.xxx.in-addr.arpa [TLD]

    1
    0 Votes
    1 Posts
    137 Views
    No one has replied
  • WAN open ports problem

    8
    0 Votes
    8 Posts
    853 Views
    S

    @manuelgop Did you apply the changes after reordering the rules? They apply in order, though as I said pfBlocker might reorder them.

  • pfBlockerNG 2.2.5_30 & pfSense 2.4.4-p3

    1
    0 Votes
    1 Posts
    140 Views
    No one has replied
  • Pfblocker-NG blocking white-listed website

    3
    0 Votes
    3 Posts
    395 Views
    H

    You mean a IPv4 List you created is now not working?

    I'm having the same problem with a brand new setup + List.

    Cant create it, when it tries to update it gives me custom error list!

  • Error in updating PFblockerNG

    4
    0 Votes
    4 Posts
    589 Views
    W

    Thanks all.

  • When will pfBlockerNG 2.2 be stable

    4
    0 Votes
    4 Posts
    587 Views
    ?

    I just came here to check if there was an eta on 2.2 being not marked as development - I normally just look in the package manager for updates.

    @NollipfSense said in When will pfBlockerNG 2.2 be stable:

    @zjgn said in When will pfBlockerNG 2.2 be stable:

    pfBlockerNG-devel 2.2.5_30

    Has been stable getting close to 2yrs now.

    So is the 2.1 branch no longer recommended?

  • Cant create Ipv4 custom list

    1
    0 Votes
    1 Posts
    573 Views
    No one has replied
  • pfBlocker, blocking the wrong countries

    8
    0 Votes
    8 Posts
    797 Views
    bmeeksB

    @IsaacFL said in pfBlocker, blocking the wrong countries:

    @bmeeks maybe someone who is using pfblocker more than I, could verify if that is really the case.

    This is a /10 owned by Microsoft in Ireland so a pretty big error in the data base.

    I know it was pointed out that the orig file was not in numerical order, but at least the csv file I downloaded from Maxmind, was in numerical order so I expected the country extraction would also have resulted in something also in numerical order.

    But i didn’t spend much time on it so could have been something I did wrong.

    Sorry, but I don't use pfBlocker. I was just responding to the general issue of GeoIP inaccuracies. This effects things other than just pfBlocker.

    My personal opinion is that GeoIP is slowly losing its utility due to these errors.

  • lighttpd taking > 30% cpu

    4
    0 Votes
    4 Posts
    375 Views
    GertjanG

    @gabacho4 said in lighttpd taking > 30% cpu:

    Turning off the pfblockerng service does

    Leave it on. With the default settings. With no feeds what so ever.
    Now you have the same config as I have, and the same as the author has. he wouldn't release it if it would explode the usage of certain( lighttpd ) processes.
    All will be fine - guaranteed.

    Now, add your feeds - your config, step .... by ... step...... and test a lot.
    As soon as you see strange things, like lighttpd going haywire, undo that step - reboot, drink cofee, take a break, and test that step ones more.
    Still a no go ?
    Detail your step on the forum : you'll be having something that can be reproduced. That's worth a lot !
    If you find something : do not forget to detail your entire setup without omitting anything.

    Btw : You could even disable lighttpd, as it only servers a 1 by 1 pixel in most times (I guess, never tried it).

    @gabacho4 said in lighttpd taking > 30% cpu:

    Is there really only a couple of us having this issue?

    Just you ;)
    tazmo resolved the issue by putting things in place. A reboot is rarely needed, but it never hurts.

  • Allow Port Exceptions In Floating Rule for GeoIP

    1
    0 Votes
    1 Posts
    69 Views
    No one has replied
  • Correct pfBlockerNG Set Up?

    21
    0 Votes
    21 Posts
    2k Views
    GertjanG

    Added to that, "names" = host names exists for humans.
    DNS exists sot that all these names are converted to IP's, something that device actually can use.
    You could throw away all host names.

    Try visiting https://[2610:160:11:18::199]/ or https://208.123.73.199/ - your browser will yell at you because the cert of that web site doesn't have 2610:160:11:18::199 or 208.123.73.199 in it's ALT DNS list, so for the sake of testing, just override the warning, accepts it, and you'll see ...... this forum. Without using names (URLs).

    Edit : when you see these browser certificate warniong, inspect the cert. drill down to the cert info list, and you will find :

    219e97a7-a3fe-4b91-8519-73eccf73fa58-image.png

    so you know that you are connected to netgate.com or any sub domain of that site - forum.netgate.com in this example.

    @WannabeMKII : when you call someone, do you enter his name, or his phone number ?
    => Well, you use your contact list, a sort of DNS lookup, to have the phone select the according phone number. The phone circuit isn't aware of 'names'. Just numbers. Setting up a contact list without phone numbers ... that's .... not useful.

  • This problem is driving me nuts! Please help.

    9
    0 Votes
    9 Posts
    919 Views
    jimpJ

    "Cannot allocate memory" on 2.4.5 does not mean you don't have enough table entries. On 2.4.5 that error will be "Too many elements" if you need to increase the table entries limit.

    "Cannot allocate memory" is likely just what it says, it ran out of kernel memory trying to load the table. Usually this is only temporary and will resolve itself in the next filter reload. See https://redmine.pfsense.org/issues/10310 for more info.

  • mobile.pipe.aria.microsoft.com

    1
    0 Votes
    1 Posts
    327 Views
    No one has replied
  • pfBlocker doesn't create any rule or alias

    4
    0 Votes
    4 Posts
    1k Views
    S

    The Force option Update will download the IP lists and create the aliases. If you're getting an error with the update, then it probably didn't create the aliases. In other words it has no information to work with. I've not run into an error there, let alone mentioning an ISO.

    Generally when I've created them I use Alias Native and then create my own firewall rules.

  • pfBlocker genrates 12GBs of logs a day

    3
    0 Votes
    3 Posts
    479 Views
    T

    Alright... I'll give that a try next.

    Had to resort to a cron tab that did a:
    /bin/cat /dev/null > /var/log/pfblockerng/dnsbl_error.log

    every 15 minutes. That's a hack!

    Will try the dev version next...

    Thx,
    Bob

  • pfBlockerNG logs

    6
    0 Votes
    6 Posts
    3k Views
    BBcan177B

    @siam yes

  • Can not check my email, outlook.live.com Cert Error

    17
    0 Votes
    17 Posts
    1k Views
    S

    @RonpfS
    I just did a test. You need to "Force Reload" and "Force Reload DNSBL" in case If you remove an entity from custom white list. The entity behavior will change to blocking. You don't need to restart pfsense.

    Thanks for clarification.

  • Trying to run pfBlockerNG-devel update automatically after reboot

    2
    0 Votes
    2 Posts
    191 Views
    provelsP

    Just bumping this in case someone has a thought on it. I've also tried running this script as a shellcmd, but w/o success.

    #!/bin/sh sleep 120 /usr/local/bin/php /usr/local/www/pfblockerng/pfblockerng.php update >> /var/log/pfblockerng/pfblockerng.log exit
  • 0 Votes
    8 Posts
    1k Views
    P

    Thank you for that information. I will downgrade now pfSense. Would you @getcom mind to set up a bug-report? Your reputation is surely better than mine and i expect you can describe the problem better i could ever do.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.