• What is the proper way to allow Geo access to specific country?

    16
    0 Votes
    16 Posts
    5k Views
    chudakC
    @jegr That's what I do :) The goal for initial questions was to learn how-tos , but general discussion about how users use home network is very useful ! Thank you all!
  • Suppress IP still being blocked

    4
    0 Votes
    4 Posts
    2k Views
    B
    Yeah, due to my blocked Server (as Portforwarding inbound within the 10.0.0.0 /8) Range I just switched to Alias Deny to getting able to Suppress this /32 and it worked. On first Testings the Server responds and a page is being delivered. If you read this in the future: Native Alias works good. As I have seen Deny Alias works better. I just didn't had to set my Suppress up (List is empty, just checked it!) I only can suggest that with the Deny Alias maybe pfBlockerNG recognizes / admits the Portforwarding as a higher Priority and lets the Traffic to that IP pass. I will just have to figure out if this happens only eg from my own Adresses or whether even Contacts from IPs within the defined Block Lists will also get passed / "ignored"... If anybody is aware of that case or knows an Answer I'd highly appreciate your effort here, as it saves many time seizing the Logs for denied Inbounds by each List. Edit: As I just saw that I did not mention that clearly... I was before using the Native Alias and just shortly switched to use the lists as a Deny Alias. The portforwarding did not work before as the lists were set to Native Alias.
  • [SOLVED] SEC-WAY | Rules for equal "Native Aliases"

    1
    0 Votes
    1 Posts
    174 Views
    No one has replied
  • Unable to re run wizard

    5
    0 Votes
    5 Posts
    897 Views
    M
    @grimson Sorted, thanks, have a nice Christmas, I am off to specsavers!
  • DNSBL is out of sync. Perform a Force Reload to correct.

    3
    0 Votes
    3 Posts
    7k Views
    B
    @ronpfs Thanks for the reply. I JUST finished updating all of the packages I have and updating PFsense to the newest version. After restoring a fully working config from a few months ago and it seems to be working okay now.
  • Iblocklist How to add my IP Lists

    14
    0 Votes
    14 Posts
    4k Views
    B
    That's an awesome List, thank you for sharing it @anttechs I was just surfing all the way up and down to find sth similar, here it is. Just amazing! Edit I really do not know if it should have had been mentioned here but on http://iplists.firehol.org/ there is a comparison of several free accessible Lists. As it surely needs a little "work-in" imo it got the option to provide a good overview over several lists and even how individual lists overlaps one with an other. I just found it shortly. As I see it might provide one with a nice and unique overview though it might even need some time to get even this. Anyway, I guess it might be a good addition for any searches.
  • IPv6 Feeds won't show up in list

    1
    0 Votes
    1 Posts
    163 Views
    No one has replied
  • white list to domains amazonaws.com

    1
    0 Votes
    1 Posts
    153 Views
    No one has replied
  • Replace 1x1 with whitelist options?

    1
    0 Votes
    1 Posts
    194 Views
    No one has replied
  • CIDR Aggregation?

    1
    0 Votes
    1 Posts
    334 Views
    No one has replied
  • 0 Votes
    3 Posts
    815 Views
    RonpfSR
    Try this : grep "maxmind.com" /var/db/pfblockerng/dnsbl/*.txt /var/db/pfblockerng/dnsblorig/*.orig /var/unbound/pfb_dnsbl.conf /usr/local/pkg/pfblockerng/dnsbl_tld it provides some more info about pfblockerNG db.
  • PfBlockerNG and Plex port problems

    5
    0 Votes
    5 Posts
    2k Views
    chudakC
    @tac57 I don't use Plex anymore, so no comments, sorry
  • Another feed "down" - www.malwaredomainlist.com

    2
    0 Votes
    2 Posts
    426 Views
    RonpfSR
    Change the State to Flex
  • How allow (disable pfblocker) to my tivo vlan?

    3
    0 Votes
    3 Posts
    534 Views
    R
    That must have felt good. Happy holidays.
  • Unbound restarting more frequently?

    8
    0 Votes
    8 Posts
    1k Views
    GertjanG
    Exact. Static ones are ok, they are known - and when the lease is renewed, DNS doesn't restart. Classic DHCP, if checked, will restart DNS. This is a known subject (I won't call it an issue, but if unbound has a lot of work to do at startup, like rowing through all these pfBlockerNG 's feeds files; and you have a 'light' system (processor, disk, whatever) then yes, it starts to take time).
  • Activated Feed group name missing

    1
    0 Votes
    1 Posts
    140 Views
    No one has replied
  • pfblocker defend rdp/rds brute force attacks

    5
    0 Votes
    5 Posts
    1k Views
    chpalmerC
    Security through obscurity.. (if you believe that..) Use a different port number. That will keep some of it down.
  • Ram used

    4
    0 Votes
    4 Posts
    668 Views
    L
    @bbcan177 I am already using pfBlockerNG-devel, and i read yesterday about this bug with unbound reported after @RonpfS told me. Pfblocker is doing his job from what i saw,i was just curios about the ram behavior. Thanks both for the help .
  • Does it really matter????

    3
    0 Votes
    3 Posts
    685 Views
    A
    @ronpfs said in Does it really matter????: A SSD could improve processing, but a decent HD should be ok. Many thanks that's all I needed to know really. bless you, my friend, and have a happy xmass and new year ;)
  • PfBlockerNG 2.0 & BIND 9.4

    6
    1 Votes
    6 Posts
    3k Views
    G
    Won't this option work from my previous post: DNSBL is hardcoded to only use Unbound. However, you can still use Bind but would have to set Binds Outbound Forwarder to point to the pfSense Resolver so that DNSBL could be utilized. Sure, I've succesfully tried to use unbound as bind's forwarder to allow DNSBL. The downside of this solution is the poor dns performance and the overall complexity of the setup. The advantages of a setup using pfBlockerNG and bind are: an autoritative dns server to host local zones DNSBL features in place per view (which can be similiar as defining DNSBL per Interface) the functionalities from bind itsself few dependencies I found a very nice way to put all the zones from pfBlockerNG into bind using RPZ feature. (http://www.zytrax.com/books/dns/ch9/rpz.html) This way I've added ~300.000 blocklist zones into several views with very low memory footprint :) I'll update the script into my github repo.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.