• pfBlockerNG IPV4 problem

    Moved
    18
    0 Votes
    18 Posts
    1k Views
    BBcan177B
    @rtkluttz said in pfBlockerNG IPV4 problem: Upgrade to pfBlockerNG-devel.
  • pfBlockerNG-devel 3.0.0_3 DNSBL alerts no longer showing source IP

    9
    0 Votes
    9 Posts
    1k Views
    P
    I am running Version 2.4.5-RELEASE-p1 and pfBlocker DEVEL 3.0.0_3
  • Revert to latest 2.2.5 dev

    11
    0 Votes
    11 Posts
    941 Views
    kiokomanK
    @chpalmer no it's not... we are going out of topic ... but I prefer cappuccino when I wake up https://www.youtube.com/watch?v=yWKu8ammTlA
  • DSNBL out of sync

    5
    0 Votes
    5 Posts
    633 Views
    P
    @bbcan177 that worked. thanks a lot.
  • DNSBL service unable to enable

    8
    0 Votes
    8 Posts
    1k Views
    T
    @trewflight48 gonna watch this video I guess I have alot to learn still. How To Setup ACME, Let's Encrypt, and HAProxy HTTPS offloading on pfsense.
  • pfBlockerNG-devel 3.0.0_3 upgrade hangs

    3
    0 Votes
    3 Posts
    462 Views
    RonpfSR
    When it hang like that during pkg install, wait maybe 10 minutes, restart Unbound from Services Tab. To prevent this from happening : Disable pfBlockerNG before doing the update Update pfBlockerNG Review pfBlockerNG settings Enable pfBlockerNG Force Reload All to be on the safe side. Who might have to synchronize your Groups with the Feeds tab.
  • maxmind -- do i need it for mysite?

    4
    0 Votes
    4 Posts
    495 Views
    johnpozJ
    @tross9 said in maxmind -- do i need it for mysite?: Outside the U.S. thus allowing outside the U.S. to possibly gain access. but I think that is Highly unlikely, only possible if a company goes out of business and their IP is sold. No that is not true at all - IPs are exchanged all the time.. Company does not have to go out of business. We recently sold off some IPs out of your /16, those IPs are now outside the US. What if company X has locations in countries A B and C.. And now is using some of their IP space in B vs A, etc. Geoip data is updated all the time. While it at first entry might just use the companies HQ that is in country X, at some point they determine that IP range xyz while owned by company in country A, is actually used in country B, etc.. Lets be clear - the geoip database is a lets call it best guess at best ;) But if your concerned with only allowing IPs from XYZ via geoip data. Then it behooves you to make sure list of IPs your using is current. A maxmind account is free, while the data might not be perfect.. Using the current data is going to be more accurate then using old data. Even using the best and latest to the minute geoip data doesn't mean its correct.. If you are concerned with who can access your resource you have opened to the public. The best solution is to use their IPs, and only allow those. While I understand that can become problematic - especially with users that have no idea IP even is ;) If your concerned - get them to setup a ddns for their connection. Then use that ddns for your alias and only allow that. I do this for my son's connection. I manage his network remotely via his unifi devices (router and ap) being part of my controller... For that to happen they need to talk to my controller. I sure and the hell would not open my controller to the public internet, even I could limit the IPs to be on his block ;) let alone his city or country.. So I setup to only allow his IP, which sure changes now and then. So I use his ddns in the alias.. [image: 1607006745924-iplist.png] But for example my plex server - my users access this not only from their homes, but from their mobile devices.. It not really possible to know for sure what IP they might come from.. But I sure do not want to open that up to the whole internet. So I lock it down to only the countries they should be coming from.. So I use the listings for those.. Currently only US, but a buddies son was working in Honduras for a while - and so it was allowing US and Honduras, etc.. The geoip listings can be useful.. But if the data is dated, its going to be less useful than current data. If my friends and family were more tech savy I would lock down their plex server access to only vpn access. But that is a pipe dream to expect normal users how to do that, and sure and the hell not going to spend the time to manage all of their devices and networks to use vpn to access my network. So I do atleast something to limit who can access my plex server. Be it far from perfect or optimally secure setup, etc. edit: Here I ran across this just a bit ago in my browsing.. This is perfect example of how things get messed up with geoip dbs https://www.reddit.com/r/networking/comments/k61a5j/geolocation_issue/ The NL company has a location in the US, they got a line in the US and IP from the isp - but for some reason this ip is showing from the NL for geoip, etc.. This sort of thing happens all the time - and yes it can be a real pain the ass to get corrected.. I had a /24 from our /16 that was showing up as being from vietnam... Tried for months to get it corrected.. That IP range had never been used in vietnam, and clearly anyone doing a simple traceroute could see it was in florida.. It was causing issues with users accessing some stuff that was doing geoip filtering, like banks and stuff.. Just more example of why if you want to do geoip filtering, there will be mistakes in the db. And you should use current a db as possible.
  • The domain is not listed in DNSBL!

    2
    0 Votes
    2 Posts
    235 Views
    M
    So I solved it myself. Turned off "keep settings", uninstalled and reinstalled pfblocker, making sure to delete the DNSBL default packages before running my first force reload.
  • New update but wrong link to release notes??

    1
    0 Votes
    1 Posts
    112 Views
    No one has replied
  • DNSBL to Syslog?

    3
    0 Votes
    3 Posts
    539 Views
    NogBadTheBadN
    Use the cron package.
  • Route for DNSBL VIP through site to site OpenVPN tunnel

    1
    0 Votes
    1 Posts
    128 Views
    No one has replied
  • devel 3.0.0/_1 Error loading rules.debug

    1
    0 Votes
    1 Posts
    127 Views
    No one has replied
  • pfBlockerNG and Chrome

    10
    0 Votes
    10 Posts
    1k Views
    D
    @ihavealegohead: Yes, I know about the Chrome settings, but I am more concerned with dealing with this globally, not browser by browser. Also with my IoT devices that hardwire access (e.g. 8.8.8.8 over HTTPS). It seems I've gotten rid of the last of those devices, since a floating rule I put in place to detect HTTPS connections to DNS servers is no longer getting hits. As for pfBlocker displaying a secure page: if it blocks an HTTPS page, your browser will never show it to you. The certificate in use at that moment is an internal pfBlocker cert, while the browser is expecting to see a certificate for the domain name you entered (while it is asked to show the internal pfBlocker SITE BLOCKED page). Ergo there will always be a certificate mismatch.
  • DNSBL doesn't work

    4
    0 Votes
    4 Posts
    547 Views
    GertjanG
    Actually, some thinking on my side was needed ;) @Abdulkarim said in DNSBL doesn't work: [ DNSBL FAIL ] [ Skipping : Social ]. Do you see this message in an pfBlocker 'update log' ? Doesn't this mean that the download of feed that implements social blocking failed ? Which would explain the non blocking. Can you give more info / context ?
  • Phishtank list download fail

    35
    0 Votes
    35 Posts
    2k Views
    R
    @provels Thanks, I may update the version. I know that the author recommends the devel version for a long time, but for me this always sounded too much like "beta". Cheers!
  • 0 Votes
    1 Posts
    191 Views
    No one has replied
  • High CPU from lighttp_pfd

    3
    0 Votes
    3 Posts
    197 Views
    infosamu.itI
    @provels said in High CPU from lighttp_pfd: .malwarebytes.com thank you very much! also in my case your suggestion solved the issue.
  • pfblocker on a bridge interface

    1
    0 Votes
    1 Posts
    123 Views
    No one has replied
  • pfblockerng blocking Alexa

    8
    0 Votes
    8 Posts
    1k Views
    RicoR
    You need to force reload after adding whitelist entries. Also clear the clients DNS cache. -Rico
  • Wrong geoip classification

    2
    0 Votes
    2 Posts
    206 Views
    GertjanG
    @Jack37 said in Wrong geoip classification: Is there a chance to reclassify the ip? The theory : As you might know, "pfBlockerNG" doesn't know anything about an IP and their location. The info comes from lists, like the "MaxMind GeoIP " -where you took a subscription to have access to their lists. Contact them if you want something gets changed. The reality : As said often : because the stock with IPv4 has been totally depleted, their is a real traffic of IPv4 going on. Thye are sold and bought all the time in big blocks or small chunks. This traffic is a world wide thing. It's close to impossible to trace - or keep up to date - the exact IP location. It's nice if it works - but often GEOIP info is plain wrong - and/or takes time to mute to another place. Keep in mind : with IPv6 things will get worse as just make a list == mission impossible.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.