• Bypass AdBlock Detection

    3
    0 Votes
    3 Posts
    990 Views
    S
    Thanks for feedback. I used site.com as an example. did not realize SF had purchased that domain :P I'm hesitant to start whitelisting sources of ads as that defeats the purpose of having an adblock list. What I ended up doing was blacklisting the source of the JS file that does the validation and puts up a modal disabling the user from using the website. Solves my problem, which was being able to use this website, with ad block, by a user who is on a phone and not technical. thank you for help!
  • pfBlockerNG DNSBL service not starting/stopped but DNSBL working fine?

    5
    0 Votes
    5 Posts
    735 Views
    I
    Yes - changing default values certainly can be a pitfall, but as they are default values at the same time they can/should be changed as default port values are ultimately a standard point of entry and is actually good practice in hardening security - nes pas? Granted that not all scenarious require this, it is still a suggested practice (and has demonstrated it's validity in time). My bad here was not realizing there were 2 services using the same port as no major red flags were raised: what was surprising to me was the non-report of any errors when scrutinizing the default logs. Upon digging further I see I was not the only one in a similar situation as can be read in this post: https://forum.netgate.com/topic/133712/pfblockerng-devel-2-2-1-upgrade-fails-to-start-pfb_dnsbl-service While the issue here was an unexpected overlapping of IP ranges, the same anomaly was seen (unable to bind). The fact that there is nothing immediately reported in the logs is puzzling and only a manual restart from the shell can reveal this as shown; maybe this should be appearing in the standard log for quicker corrective actions (just my humble suggestion) keeping in mind that errare humanum est (sed perseverare diabolicum!).
  • Set up pfBlockeNG on the WAN?

    1
    0 Votes
    1 Posts
    86 Views
    No one has replied
  • Routing Issue SG3100

    1
    0 Votes
    1 Posts
    189 Views
    No one has replied
  • pfblockerNG Error

    3
    0 Votes
    3 Posts
    347 Views
    J
    @mass said in pfblockerNG Error: Increased Firewall Maximum States size to 500000 I would leave Firewall Maximum States set to default, whatever was there before you changed it The entry that you need to change is: Firewall Maximum Table Entries to 2000000.
  • BBC_C2 added www.netgate.com / docs.netgate.com

    9
    3 Votes
    9 Posts
    1k Views
    C
    Right now I have the few pri1 I have enabled as permit/logged, I will be checking logs to see if any legit traffic from matched ip's.
  • Blocking UBUNTU/Raspberry Pi/Synology

    1
    0 Votes
    1 Posts
    124 Views
    No one has replied
  • How to see logs of sites blocked by pfBlockerNG?

    1
    0 Votes
    1 Posts
    162 Views
    No one has replied
  • pfBlockerNG Crashing due to memory error

    9
    0 Votes
    9 Posts
    569 Views
    kiokomanK
    201k is ok !
  • Occasional DNS lookup failures - how to troubleshoot?

    12
    0 Votes
    12 Posts
    1k Views
    johnpozJ
    Looking at your dhcp leases should help... Most devices register a name - that should help you identify them.. If its something odd.. Looking up the mac address should tell you who made it, or atleast the nic/wifi card its using. If wired another way to figure out what a device is, if you have smart switch that will show you the mac address table is look up the mac to what port its on, and then just trace the wire. Many devices also list their mac on them, or can be found in info screen, etc. If trying to figure out which mac belongs to what - normally a reboot of said device will have it check its lease - so looking in your dhcp log for timestamp of what just asked as you rebooted it. another option - if all your devices answer ping, some iot devices don't.. Is do a ping sweep for what answers, then turn off some device you don't show in your list, and do your ping sweep again - what was the IP that answered before, and now doesn't ;) What device did you turn off ;)
  • Am I missing a whitelist somewhere? Can't block YouTube

    3
    0 Votes
    3 Posts
    1k Views
    S
    Thank you! I cannot believe I did not look at that setting. I've ensured safe search redirection, youtube restrictions and firefox DoH blocking are all disabled, which i think is the default. Problem solved. thank you very much.
  • Bug in ipv6 lists when updating

    13
    0 Votes
    13 Posts
    1k Views
    IsaacFLI
    I did the upgrade from .35 to .36 today and did not get this problem this time, so it could be that it something unique to my configuration at the time.
  • IPv4 Custom list format

    5
    0 Votes
    5 Posts
    474 Views
    noplanN
    My tech guys Use the notepad++ & m$ excel combo Means creating 100 and more lines If /24 doesn't do the trick Another way round is set an alias in FW rules For /24 and before that rule allow your Adress range
  • pfBlockerNG DNSBL service will not start

    5
    0 Votes
    5 Posts
    857 Views
    M
    All is good now. Thank you for your time. Somehow "cat" command got the service started. I don't understand it, but will take it.
  • Firewall Help

    5
    0 Votes
    5 Posts
    582 Views
    I
    Thanks guys this appears to be working.
  • GEO-IP not logging

    4
    0 Votes
    4 Posts
    646 Views
    DaddyGoD
    @llebgrate said in GEO-IP not logging: Fixed. Thanks. You Welcome
  • 0 Votes
    3 Posts
    571 Views
    J
    Hello jdeloack Thanks for the feedback. the ambassador update is scheduled for next week. I tried to replace the current package with the devel but for that I will need to update the version. Immensely grateful for the help.
  • Plex issues

    3
    0 Votes
    3 Posts
    554 Views
    R
    Soooooo........... Somehow I deleted the WAN rule the is auto added at the time you do the NAT rule. This I do not remember doing at all but I am so dumb. I really should have checked,. It came to mind when I was telling someone that "I can't figure out why the default rule is blocking it the only way that would happen is if I moved a rule to block or if I deleted it" It clicked how stupid I am as I was saying it to the person. PEBKAC
  • pfblocker-ng-devel social media

    1
    0 Votes
    1 Posts
    160 Views
    No one has replied
  • Block everything except *.avid.com

    2
    0 Votes
    2 Posts
    276 Views
    T
    So I've tried to add custom lists to IPv4 but those only seem to resolve the top level. I'm having a difficult time understanding how the technology can white list .avid.com which includes all the sub domains of avid.com, but it's impossible to block everything except what is white listed.... I mean this is a pretty typical need I imagine. A lot of people use whitelisting only for outbound traffic. On sonicwall it's based in the Alias rules themselves. But on pfsense it seems like the developers of pfblockerNG have giving the ability to whitelist .avid.com but not the ability to block all other traffic... I guess thats why i'm so confused. Because I can clearly see that i can use .avid.com on DNSBL to white list avid and all it's sub domains, but I cannot figure out how to deny all outboud traffic, except .avid.com
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.