• PfBlockerNG v2.1.1_8 not showing in Package Manager

    10
    0 Votes
    10 Posts
    994 Views
    K

    pfBlockerNG 2.1.1_7 is now showing as out of date.  I updated, and now I have pfBlockerNG 2.1.1_8

    Thanks to BBcan177 for pfBlockerNG, and thanks to JimP for sorting things out with this update.

  • Re: DNSBL Interface

    7
    0 Votes
    7 Posts
    2k Views
    H

    @BBcan177:

    @HeatmiserNYC:

    Hey BBCan,
    Ran into some strangeness over the last few days. Why would I only be getting this in my logs? It appears that nothing else is resolving….

    If your referring to the "unknown" msg, then that is normal for HTTPS alerts, the browser fails to load the DNSBL webserver (as expected) and as such only a portion of the alert can be logged. Hover over the key icon.

    Did something change in with the logging? I'm fairly certain I never saw those messages on a regular basis. It was always source/destination of visited websites…..

  • IP not being blocked

    4
    0 Votes
    4 Posts
    914 Views
    BBcan177B

    If you manually add IPs to a customlist, you need to check the "Update custom list" checkbox, then goto the Update tab, and Force Update. Otherwise the Customlist is updated as per the "Frequency" setting of the Alias.

    The next version will be more intuitive to know when the Customlist has changed…

  • DNSBL doesn't block search engine links

    3
    0 Votes
    3 Posts
    665 Views
    S

    @BBcan177:

    Did you enable the "TLD" option? Without TLD, only the listed domain/sub-domain is blocked…

    So without TLD:

    example.com will be blocked
        sub.example.com will not be blocked

    With TLD:

    All sub-domains are blocked.

    Thanks!  I figured I was missing something simple  ::)  the search result link was going through because it had a "www." on the front.  Enabling TLD fixed it.

  • How to find tracker and ad domains to build your own list?

    9
    0 Votes
    9 Posts
    2k Views
    T

    @BBcan177:

    The next version of the package will have a "Feeds Management" Tab, that lists the recommended IPv4/IPv6/DNSBL feeds… So this will be easier to manage... Also when Feeds change, those changes will be visible in the Feeds Tab...

    This sounds like a fantastic feature. Can't wait to play with it!

  • URL List Formatting

    2
    0 Votes
    2 Posts
    739 Views
    BBcan177B

    You can use the pfBlockerNG Log Tab.

    Goto "Original IP Files", then view the contents of the original Feed.

    Goto "Deny" or "Permit" or "Match" (Depending on how you configured the Alias), and view the parsed IP file contents.

    Or goto the shell, and view the files from the subfolders in  /var/db/pfblockerng/

  • Smites

    10
    0 Votes
    10 Posts
    2k Views
    M

    Those people should be sent to North-Korea, BB  :-*

    (Having said that: it could also be possible people hit the wrong button by accident - and never bothered to inform you about it. I think I've read somewhere in the past board mods can reset your count to 0).

  • PfblockerNG and DNSBL

    3
    0 Votes
    3 Posts
    1k Views
    M

    SAME ISSUE here..

    i blocked youtube via win10 machines via the host file…

  • I found a weird "bug" in pfblockerng

    3
    0 Votes
    3 Posts
    791 Views
    M

    Thank you for your fast reply, and good information.

  • 0 Votes
    5 Posts
    5k Views
    P

    I forgot to mention, since you are hardening your system to defend against active attackers, securing your DNS queries is a very important piece of that. Unbound is a very secure resolver so I would recommend taking some time to familiarize yourself with it and optimizing and hardening its settings. By using Unbound, hardening it and only sending queries out through a VPN you are probably effectively impervious to DNS attacks from the massive majority of hacking. Check out this article and here are some suggestions for settings. https://calomel.org/unbound_dns.html

    Enable DNSSEC Support (this is authentication for your DNS queries to avoid spoofing attacks, kind of like SHA)

    NO Forwarding Mode
    NO DHCP Registration
    NO Static DHCP
    Hide Identity
    Hide Version
    Prefetch Support
    Prefetch DNS Key Support
    Harden DNSSEC Data

    You might be interested in the Unwanted Reply Threshold, but I've never used it and know nothing about it

    Experimental Bit 0x20 Support

  • Reinstall pfB deps

    6
    0 Votes
    6 Posts
    1k Views
    BBcan177B

    Which rules are you referring to?

  • General - Rule Order

    2
    0 Votes
    2 Posts
    970 Views
    BBcan177B

    You can try to use the "Adv. In/out" rule settings to create a pfB rule. The customlist at the bottom of the alias settings can be used to add IPs. Entering "0.0.0.0/0" for "any".

    Alternatively, use "Alias type" rules and configure the pfB rules as required.

  • Internal Blacklist SSL Certificate

    3
    0 Votes
    3 Posts
    2k Views
    BBcan177B

    In the Ipv4/6 tabs, you can set the State setting to "Flex" which will lower the ssl requirements. Click on the blue infoblock icons for further details.

  • User c0210021 needs help

    3
    0 Votes
    3 Posts
    759 Views
    P

    Yeah TLD + More lists + Force Google Safe Search & Block other search engines, block TOR, block VPNs, and you'll still have leaks in your ship.

    Like you said, it's an impossible feat to actually block porn unless you whitelist the internet.

    But you can do a really good job of avoiding it unless it is overtly searched for. That's about the best you can search for without going to extremes.

  • Exception for DNSBL Rule

    7
    0 Votes
    7 Posts
    3k Views
    D

    @Nic12:

    Ok, it seems that I misunderstood some basic principles of pfBlockerNG.
    "Advanced Outbound Firewall Rule Settings" and "Floating rules" misled me.
    Sorry for the newbie questions… ???

    Please, read the description there:

    Configure settings for Firewall Rules when any DNSBL Feed contain IP Addresses

  • External DNSBL

    8
    0 Votes
    8 Posts
    2k Views
    P

    I'm using pfBNG & DNSBL on 2.4.0 BETA with Unbound and it works great.

  • PfBlockerNG v2.1.1_7

    6
    0 Votes
    6 Posts
    2k Views
    BBcan177B

    @Wolf666:

    I don't see it available on 2.4 repository.

    Thanks, I sent the devs a message!

  • Easylist seems not to be working

    12
    0 Votes
    12 Posts
    4k Views
    C

    Thanks BBcan177.  I was confused, I thought the "Terminated - Easylists cannot be used" message was referring to the easylists provided by default in pfblocker.  I removed the incompatible lists and the message went away.

  • Pfblockerng stops working….

    6
    0 Votes
    6 Posts
    1k Views
    BBcan177B

    @micropone:

    using my WAn (comcast) pfb DNSBLIP has many ip address in it… have no clue how the ip addresses got there..

    In DNSBL, you added the "DNSBL IP" option that collects any IP address that's found in a DNSBL Feed and adds it to a block firewall rule.  All DNSBL Domains are blocked via DNS Resolver (Unbound).

    I don't recommend to use the Firehole Level 1 for Outbound. That list contains Bogon IP Addresses…

  • DNSBL Weirdness

    10
    0 Votes
    10 Posts
    2k Views
    BBcan177B

    The pkg doesn't have that option. You could create another pfSense Box and use the XMLRPC Sync tab to copy the settings.

    The next version of the pkg will have a Feed Management Tab that will have auto-import capabilities…

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.