• 0 Votes
    2 Posts
    803 Views
    BBcan177B

    Select "Force Reload" in the update tab

  • Problem with pfBlockerNG List - How can I fix it? [SOLVED]

    5
    0 Votes
    5 Posts
    2k Views
    BBcan177B

    Firehol is converting those Domain based lists into an IP format… I'd not recommend that...  The pfBlockerNG package has an IP and a Domain section.... so best to use the applicable format (IP or DNSBL)...

    Yes hpHosts has individual Feeds, or the combined feed linked above... Take a look at their website for further details.

  • BBcan177 Block Lists

    4
    0 Votes
    4 Posts
    2k Views
    BBcan177B

    @guardian:

    Can you give us any idea of how they are compiled (source) so we know if they are a good match for our use case?

    Take a look at the Gist URLs… it will show a comment line for the source(s)...

  • PfBlockerNG error on package update

    4
    0 Votes
    4 Posts
    897 Views
    G

    I'll certainly defer to the developers, but I doubt that it will cause any problems.

  • Using a static block list in DNSBL / Blocking MS Telemetry and other BS

    6
    0 Votes
    6 Posts
    4k Views
    C

    I will post a much shortened list I ended up with which I got to by removing domains I know for sure are not for telemetry and also that broke other services.  The list is way shorter as expected.  But bear in mind its a game of whack a mole.  Microsoft at any point can change the domain names used or even connect directly to ip's.  This list I got here was last updated probably a year or so ago when I gave up on windows 10.

    choice.microsoft.com choice.microsoft.com.nsatc.net df.telemetry.microsoft.com diagnostics.support.microsoft.com oca.telemetry.microsoft.com oca.telemetry.microsoft.com.nsatc.net reports.wes.df.telemetry.microsoft.com services.wes.df.telemetry.microsoft.com settings-sandbox.data.microsoft.com settings-win.data.microsoft.com sqm.df.telemetry.microsoft.com sqm.telemetry.microsoft.com sqm.telemetry.microsoft.com.nsatc.net survey.watson.microsoft.com telecommand.telemetry.microsoft.com telecommand.telemetry.microsoft.com.nsatc.net telemetry.appex.bing.net telemetry.microsoft.com telemetry.urs.microsoft.com vortex.data.microsoft.com vortex-sandbox.data.microsoft.com vortex-win.data.microsoft.com watson.ppe.telemetry.microsoft.com wes.df.telemetry.microsoft.com
  • Small Typo on Firewall / pfBlockerNG / DNSBL (Need help to clarify)

    4
    0 Votes
    4 Posts
    950 Views
    BBcan177B

    Yes it needs to be in an unused network range, and is used to host the DNSBL Webserver…

  • Errors loading pfB_Europe_v4.txt

    3
    0 Votes
    3 Posts
    743 Views
    BBcan177B

    Maybe the MaxMind Database didn't get downloaded and installed correctly during installation… On the SG-1000, it might take more time to sort the MaxMind database... From looking at the partial install log from the other post, its missing the balance of the installation...

    Try to uninstall/Re-install. There is a setting in the General tab to "keep settings", uncheck that option so that it starts with a fresh installation...  Then do not move away from the installation window, until its completed its installation...

  • Getting Started with pfBlockerNG Road Map Help

    3
    0 Votes
    3 Posts
    1k Views
    P

    As for setting it up, in general just read through the info panes built into pfbng & dnsbl. That should get you going, then whatever specific questions you may have after setting up either search the forum or post a quetion.

    As for feeds, here are some good places to start. The php import that BBCan177 wrote is what I primarily use.
    https://forum.pfsense.org/index.php?topic=86212.msg508975#msg508975
    https://forum.pfsense.org/index.php?topic=86212.msg510369#msg510369
    https://forum.pfsense.org/index.php?topic=86212.msg548372#msg548372
    https://forum.pfsense.org/index.php?topic=117806.msg652480#msg652480

    I also just posted this which has some links to get you setup for really good content filtering.
    https://forum.pfsense.org/index.php?topic=124013.0

    I am not at all a computer or networking person, but through this forum and the info panes in pfbng I've been able to get it up and running and it's great.

    IMO it's the single most useful package for a home or small office looking to filter their network.

  • Using tracker.h3x.eu

    2
    0 Votes
    2 Posts
    1k Views
    RonpfSR

    @BBcan177:

    PR # 156/157 have been posted for pfBlockerNG v2.1.1

    CHANGELOG:

    Other Improvements

    Add Malware Corpus Tracker to the DNSBL parser www.h3x.eu

    @BBcan177:

    Here are the links for Malware Corpus Tracker which can be used w/ pfBlockerNG DNSBL:

    Site:
    http://track.h3x.eu/about/400

    Available Feeds:
    https://tracker.h3x.eu/api/sites_1month.php
    https://tracker.h3x.eu/api/sites_1week.php
    https://tracker.h3x.eu/api/sites_1day.php
    https://tracker.h3x.eu/api/sites_1hour.php

    DO NOT Select all of these Feeds. You should pick only one Feed. For example: the "1Month" will include the "1Week/1Day/1Hour".

    [ Edit - change to https ]

    Twitter:
    https://twitter.com/h3x2b

  • DNS breaks after installing pfBlockerNG?

    20
    0 Votes
    20 Posts
    4k Views
    C

    sure

    I used SECOIT GmbH's solution (crediting the original guy).

    His post is here.

    https://forum.pfsense.org/index.php?topic=89589.msg517047#msg517047

    Be aware with this solution, if you do an action that requires a unbound restart/configure, you will manually need to stop and then start in the gui. pfblockerng will still be fine tho.

  • 1 Votes
    2 Posts
    1k Views
    No one has replied
  • Ipv4 updates not running when should?

    6
    0 Votes
    6 Posts
    1k Views
    C

    ok will keep that in mind, thanks.

  • ASN download ipv6

    3
    0 Votes
    3 Posts
    823 Views
    C

    sorry I didnt think of the obvious :)

  • Allow a port from only select countries & block all others

    3
    0 Votes
    3 Posts
    664 Views
    Y

    awesome… thanks a ton

  • Traffic to FQDN is blocked by pfbNG even if its on a pass rule

    6
    0 Votes
    6 Posts
    1k Views
    BBcan177B

    @lpallard:

    @BBcan177:

    Typically best to use "Permit Outbound", so that it only allows access to those IPs when the LAN makes the request…

    Also ensure that the Permit rule is above the Block rules on the LAN interface. If you're using "Auto type" rules, you might need to select the correct "Rule Order" option in the General Tab.

    Thanks for you reply.  I think the rules order was the problem.  I completely forgot to change it from defaults after I had reinstalled the package and did not click the checkbox to retain the settings..

    Thanks Anthony!

    Anytime my friend :)

  • PfBlockerNG 2.1.1_5 and issue with url/alias

    14
    0 Votes
    14 Posts
    4k Views
    R

    Excellent!!! Thank you so much. It 's because i didn't known if it was a normal behaviour or not :)
    Thanks! I will keep an eye to see if everything seems to be fine with the update and the catch of any ip listed in the list.

  • Whitelist doesn't stay whitelisted

    9
    0 Votes
    9 Posts
    1k Views
    P

    Any suggestions as to which lists would be better to use?

  • PfBlockerNG 2.1.1_5 / Pfsense 2.4

    43
    0 Votes
    43 Posts
    50k Views
    J

    Thank you this has now worked for me
    Which I have also added to the page https://www.facebook.com/groups/pfsense.official/ to help others…

  • Blacklists UT1

    2
    0 Votes
    2 Posts
    1k Views
    BBcan177B

    There was a request for this awhile back… Hasn't really gone anywhere, so I'm working on it as time permits... 
        https://twitter.com/pfsense/status/788203605950025728

    Here is a sneak peak of what it will look like...

  • [SOLVED] Defining ports on GEOIP allow rule does not work

    7
    0 Votes
    7 Posts
    1k Views
    BBcan177B

    @gabrimonfa:

    IMHO it would be better to warn the user if he/she sets the ports and protocol is left to any.

    Or maybe the UI should be made consistent with the "Add rule".
    Default protocol is TCP and choosing any hide source and dest ports

    This is already fixed in the next package release… Just in testing phase now ...

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.