• export pfBlocker logs incl feed name via syslog.

    10
    0 Votes
    10 Posts
    2k Views
    J

    @jacol Thanks, I got it working. Turns out that my config was right but I noticed from PFSense syslog that I get login 401 to my ELK server. Changed the user and now it works!

  • Pfsense blocking api.particle.io

    8
    0 Votes
    8 Posts
    1k Views
    N

    @NogBadTheBad $90 is a lot more expensive than most TLDs, so I don't understand why that would be a reason to block an entire TLD.

    Ouch, glad I don't have any .tk domains then!

  • pfBlockerNG remote logging

    5
    0 Votes
    5 Posts
    1k Views
    J

    @RonpfS

    That is understandable. Thanks for the answers. I'll try to find a way to use these logs in my need.

  • Thousands of outgoing DNS(?) blocked per hour

    17
    0 Votes
    17 Posts
    2k Views
    RonpfSR

    This DNS server will only be used when you use the Alerts Tab "+" icon to whitelist a Domain.

  • Correlate abuse with use?

    1
    0 Votes
    1 Posts
    213 Views
    No one has replied
  • Block Facebook.com

    19
    0 Votes
    19 Posts
    2k Views
    M

    @NollipfSense I'll for sure try to import the DNSBL cert to my browser later in the day.
    My dns over https is also disabled :)

  • Pfblockerng Sallalist historial logs

    1
    0 Votes
    1 Posts
    167 Views
    No one has replied
  • PfblockerNG opens ports when enabled

    5
    0 Votes
    5 Posts
    1k Views
    A

    Figured this out.
    I replaced pfBlcokerNG with pfBlockerNG-Devel but the behavior remained the same. Creating a rule based on a GeoIP alias containing a country, opens ports 81 and 53 to the world (despite ports 81 and 53 are not included in the alias settings; only the required ports are included). To avoid this, in addition to (or instead of) having Custom DST Port in Firewall > pfBlockerNG > IP > GeoIP > Continent > Advanced Inbound Firewall Rule Settings, the ports are also required to be set in the Destination Port Range of the Rule, otherwise ports 81 and 53 (in addition to other opened ports) would be opened to the world. In my case I disabled the Custom DST Port and set the Destination Ports Range in the rule. I am not sure about the purpose of the "Custom DST Port" in GeoIP.

  • 0 Votes
    26 Posts
    5k Views
    nzkiwi68N

    @BBcan177 Thanks for your help.

    Sorry I have wasted your time.

    lastly, pfBlockerNG is amazing. It just makes pfSense so much more powerful as a great firewall solution.

  • How to fully uninstall pfBlockerNG

    17
    0 Votes
    17 Posts
    7k Views
    GertjanG

    These settings are all and only stored in the main pfsense config xml file.
    All other files on the disk should be removed. It's not a "setting", after all.

    @gabric098 said in How to fully uninstall pfBlockerNG:

    zero knowledge about pfblockerNG

    Me neither.
    That's why I read the installation manual(aka : the php and xml files that install pfblockerNG are in plain old school English ...).

  • please help

    22
    0 Votes
    22 Posts
    2k Views
    M

    @Gertjan i will keep watching
    thanks again

  • MalwareDomainList Down?

    4
    0 Votes
    4 Posts
    847 Views
    provelsP

    @wormuths Up again.

  • Upgrade to pfBlockerNG 2.1.4_20 - Block Rules Gone?

    13
    0 Votes
    13 Posts
    1k Views
    nfld_republicN

    @provels - Hi, I am running pfBlockerNG (v. 2.1.4_20).

    I don't use DNSBL, just the IPs. I started readding the blocklist IPs (e.g., BinaryDefense, EmergingThreats, firehol Level 1 to 3) and they now work.

  • Unbound error log

    4
    0 Votes
    4 Posts
    678 Views
    W

    Hi guys,

    I came back again and unbound is now working.

    Thanks for all of your replies.

  • Errors loading rules

    21
    0 Votes
    21 Posts
    2k Views
    P

    Ok Thanks for all the help John.

  • pfBlockerNG rule download failure log entry- false positive?

    3
    0 Votes
    3 Posts
    632 Views
    S

    I was not aware of the role of the .orig files. I tried clearing both (AfunList.orig from /var/db/pfblockerng/dnsblorig and AfunList.txt in /var/db/pfblockerng/dnsbl) and then force updating DNSBL. Both the orig and txt files were regenerated from the list feed

    As far as I can tell, the feed is correctly synced.

    @RonpfS said in pfBlockerNG rule download failure log entry- false positive?:

    Can you access the URL for AfunList in a browser?

    Yes.

    So I'm not sure why the log is reporting an error

  • 0 Votes
    1 Posts
    150 Views
    No one has replied
  • pfBlockerNG Firewall Filter Service (Solved)

    8
    0 Votes
    8 Posts
    1k Views
    provelsP

    @NollipfSense Good deal. Package probably didn't completely reinstall when you upgraded. If you install the daily snapshots now, it will go a lot faster as it just installs the update without package reinstalls (like 5 minutes total).

  • NoThink Feeds

    2
    0 Votes
    2 Posts
    240 Views
    provelsP

    @Qinn Looks like it, at least for the present.

  • Missing download fail cleanup

    4
    0 Votes
    4 Posts
    495 Views
    BBcan177B

    @Qinn
    If you see the line about "MaxMind last updated..." Then there is no failed download errors. Otherwise, you have more than 4 failed downloads, and you need to scroll the widget window down to see the last event and there should be the trashcan icon. Going from memory on this one.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.