• Rulesets

    2
    0 Votes
    2 Posts
    695 Views
    BBcan177B

    Here is a URL for the MalwareBytes hpHosts feeds:    https://www.hosts-file.net/

    Feed URLs here:  https://hosts-file.net/?s=Download

    I would not recommend to use the  hphosts.zip feed, as that is only updated once per month… There are new malicious domains added daily, and any False positive domains will not be removed for the full month....  This also applies to the hphosts-partial Feed… 
    So instead use the individual Feeds for DNSBL...

    Hope that helps!

  • Update / cron job [Error]

    2
    0 Votes
    2 Posts
    620 Views
    BBcan177B

    When you see "Update not required", then the Feed that the pkg is downloading is already up to date, so there is no reason to re-download and re-process the same feed again….  It also shows the Remote and Local timestamps in the logs...

  • Blocking 239.255.255.250

    10
    0 Votes
    10 Posts
    3k Views
    BBcan177B

    I have had poor results with that Feed… I'd disable due to the FPs in the feed...

  • PfBlockerNG GeoIP Log Surpress?

    3
    0 Votes
    3 Posts
    1k Views
    BBcan177B

    Turn "Global logging" off… Then in the TOP20 Tab disable the Logging...

    Alternatively, instead of using the TOP20 tab, you can make an IPv4/6 Alias with any GeoIP combinations and configure the options as required. Click on the Blue Infoblock icons for further details.

  • New Version?

    2
    0 Votes
    2 Posts
    506 Views
    D

    That is a LEGEND.

  • Network Configuration with snort VLANs…..and PfBlocker?

    20
    0 Votes
    20 Posts
    5k Views
    BBcan177B

    Here is the PR to fix this bug… Thanks!

    https://github.com/pfsense/FreeBSD-ports/pull/424/files

  • Crash report on 2.4-RC

    2
    0 Votes
    2 Posts
    506 Views
    BBcan177B

    Here is the PR to fix this bug… Thanks!

    https://github.com/pfsense/FreeBSD-ports/pull/424/files

  • Not logging

    3
    0 Votes
    3 Posts
    884 Views
    K

    Well that actually makes sense. I wasn't making the mental distinction between the IP logging vs DNS logging. Sure enough, under alerts they are there. Alerts also shows which DNSBL list it is on too which the log file doesn't appear to show.

    Thanks.

  • Could not open ISO and Deny folder/Masterfile uniq check - pfB 2.1.1_10

    2
    0 Votes
    2 Posts
    540 Views
    BBcan177B

    This is addressed in the upcoming release of the package.

    MaxMind contains a "Represented" list of IPs for Countries. Unfortunately, MaxMind can list IPs in a GeoIP one month, but list none for the following month. The Database doesn't contain any blank dummy data to act as a placeholder.

    So its safe to ignore the log message as there were no IPs listed by MaxMind for those Represented GeoIPs for this specific month.

    The next release will create a placeholder GeoIP file for each empty represented GeoIP.

  • Question?

    3
    0 Votes
    3 Posts
    603 Views
    mtarboxM

    I saw that they appeared different.
    Went to the rules, then floating rules, and saw what you meant, source and destination.
    Thank you dok.

  • Slow DNS resolution with PfBlocker/DNSBL

    5
    0 Votes
    5 Posts
    3k Views
    ?

    I know this thread is 3+ months old, but I stumbled upon it and think I know what the issue was. I had stumbled upon this Reddit thread and added the WindowsTelemetry hostslist. After I added to a DNSBL feed and forced an update, DNS resolution slowed to a crawl. After removing it, forcing another update and then rebooting pfSense via CLI, everything was resolved.

  • ROKU Issues with pfBlockerNG (CBS All Access, PBS, CNET) not working

    22
    0 Votes
    22 Posts
    8k Views
    XentrkX

    The above solution was a false positive. It did not work.  I ended up removing the Host Overrides in DNS Resolver to get it working. However, ads are now appearing.  We'll, I am paying for the lower tier with ads. So I can live with it. Enjoying it ad free was nice while it lasted though.

  • Dnsbl geoblocking unselected country

    3
    0 Votes
    3 Posts
    740 Views
    R

    HI BBCan..

    Your link shows this:

    IP information 191.238.35.129
    IP address 191.238.35.129
    Location Boydton, Virginia, United States (US) flag
    Registry lacnic

    Is there a difference between physical IP location and GEO based lookups?

    Jon

  • Vip 80, 8081 work but 443 and 8444 won't

    3
    0 Votes
    3 Posts
    564 Views
    BBcan177B

    Each lan segment should be able to access the DNSBL VIP via ping and browsing to the IP. There is a DNSBL permit rule option that you can select which will create a floating permit rule for the selected lan segments.

    Also check the NAT rules and see if there is another NAT rule that is interfering with the DNSBL NAT rules.

  • What dos the "Enable TLD" block do?

    4
    0 Votes
    4 Posts
    919 Views
    BBcan177B

    With this domain as an example:

    api.content-ad.net

    With TLD enabled, it will not block all sub-domains unless content-ad.net is in the blocklist, since net is the TLD. So you could add that domain to a cuatomlist and Reload for it to take effect.

  • Using Tor Network and pfBlockerNG

    4
    0 Votes
    4 Posts
    2k Views
    BBcan177B

    if you want to use GEOIP and TOR, you can create a TOR alias and add the TOR exit node feeds. Set the Action to "Permit Outbound".  Then ensure that the Rule Order option has the permit rules above the Block/Reject rules. Firewall rules are processed top to bottom.

  • Firehole and 192.168.0.0/16

    10
    0 Votes
    10 Posts
    2k Views
    BBcan177B

    Thank you. I've gone ahead and recreated the LVL1 with direct feeds without the bogons. Great idea.

    NP… I always recommend to use the original source of a feed.

    Regarding the "Suppression" feature I'm wondering whether it applies to me.

    Suppression, when enabled will remove RFC1918 and loopback addresses from a blocklist that are sometimes added incorrectly by a feed maintainer. Suppression will will also add a "+"icon to each blocked IP address (/32 and /24 only) in the Alerts tab  Clicking that icon will allow removing the selected IP from the blocklists.  Otherwise, to overcome an IP that is blocked, you will have to create a "Permit outbound" alias and add the Whitelisted IPs to the customlist. Then ensure that this permit rule is above the block/reject rules (rule order option).

  • PFBlockerNG not working.

    19
    0 Votes
    19 Posts
    4k Views
    C

    Welp said screw it, and went to do your suggestion and just worry about guests, and figure something else for the servers.

    Nope lol, doesn't work, well it does work, when I disable the guest captive portal :(. So do I have any other options? I have to have captive portal and I cannot filter their Network.

  • Using blacklists for certain IP groups, but not all

    2
    0 Votes
    2 Posts
    444 Views
    RonpfSR

    There can only be 1 DNSBL running per pfsense box.
    So I you have many pfsense boxes, you can have many DNSBL setup.

    Devices can then point to different DNS Server on different pfsense boxes.

  • No pfBlockerNG 2.1.1_10 update for 2.4-RC

    2
    0 Votes
    2 Posts
    683 Views
    jimpJ

    2.4 packages are only updated when new snapshots are built so that every part of it can be updated at the same time. Otherwise we run the risk of a package depending on a new change in base that isn't out there yet, or other similar mismatch situations.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.