• Could not open ISO

    3
    0 Votes
    3 Posts
    806 Views
    A

    @steveits We created the new key with your instructions. We also changed after the key, the field: MaxMind CSV Updates. Cleared: Check to disable MaxMind CSV updates. And after updating, the download directory /usr/local/share/GeoIP/cc/ populated with files and can select the countries. Problem solved, thank you Steve!

  • MaxMind configuration to update list GeoIP

    11
    0 Votes
    11 Posts
    3k Views
    S

    @johnpoz said in MaxMind configuration to update list GeoIP:

    create the alias with the feeds you want to use

    John is correct, just wanted to note for you that this is accomplished via "Alias Native" which creates an alias without a deny rule.

  • pfBlocker not logging after 2.5.2 pfSense upgrade

    53
    6 Votes
    53 Posts
    10k Views
    GertjanG

    @MG85

    Here is my regex.
    It's more test-of-proof sample for me. I remember finding it somewhere on Reddit.

    ^(.+[_.-])?adse?rv(er?|ice)?s?[0-9]*[_.-] #Regex RGX1 ^(.+[_.-])?telemetry[_.-] #Regex RGX2 ^ad([sxv]?[0-9]*|system)[_.-]([^.[:space:]]+\.){1,}|[_.-]ad([sxv]?[0-9]*|system)[_.-] #test RGX3 ^adim(age|g)s?[0-9]*[_.-] #Regex RGX4 ^adtrack(er|ing)?[0-9]*[_.-] #Regex RGX5 ^advert(s|is(ing|ements?))?[0-9]*[_.-] #Regex RGX6 ^aff(iliat(es?|ion))?[_.-] #Regex RGX7 ^analytics?[_.-] #Regex RGX8 ^banners?[_.-] #Regex RGX9 ^beacons?[0-9]*[_.-] #Regex RGX10 ^count(ers?)?[0-9]*[_.-] #Regex RGX11 ^mads\. #Regex RGX12 ^pixels?[-.] #Regex RGX13 ^stat(s|istics)?[0-9]*[_.-] #Regex RGX14

    Keep in mind : the ending
    "Space # text string" needs to be unique.

  • pfblockerNG slows network traffic and I get an error

    1
    0 Votes
    1 Posts
    186 Views
    No one has replied
  • How to Whitelist Single IP address of users in PFBLOCKER

    1
    0 Votes
    1 Posts
    224 Views
    No one has replied
  • appears to be working, but reports are empty

    1
    0 Votes
    1 Posts
    288 Views
    No one has replied
  • Logging when using IP “ALIAS DENY/PERMIT” lists

    1
    0 Votes
    1 Posts
    144 Views
    No one has replied
  • Unbound reliability goes down when using pfBlockerNG

    1
    0 Votes
    1 Posts
    189 Views
    No one has replied
  • Recommended staple IPv4, IPv6, DNSBL lists

    8
    0 Votes
    8 Posts
    1k Views
    S

    @code4food23 said in Recommended staple IPv4, IPv6, DNSBL lists:

    why not use both? and how can tell if they show up in rulesets

    There's no point in scanning for DROP packets in Snort if they were blocked by the firewall. Category emerging-drop.rules is the Spamhaus DROP list. Click the category name to open the file and it usually has a note explaining what it is.

  • Unable to Connect to Outbound IP Address

    1
    0 Votes
    1 Posts
    201 Views
    No one has replied
  • Custom DNSBL rules or Group Alias [FQDN]

    7
    0 Votes
    7 Posts
    1k Views
    N

    Alright, thanks for the help, @keyser!

  • Why can't i add ip to whitelist?

    1
    0 Votes
    1 Posts
    193 Views
    No one has replied
  • 'Catch 22' with fresh install, pfBlockerNG 3.0.0.16 and Python enabled

    10
    0 Votes
    10 Posts
    1k Views
    fireodoF

    @gertjan said in 'Catch 22' with fresh install, pfBlockerNG 3.0.0.16 and Python enabled:

    A solution was posted https://redmine.pfsense.org/issues/12274.

    The 'patch' should be installed with the pfSense patch package.

    Thank you! Done.

    Can't really test it, as I have to re install pfSense, something I've never had to to (for the last 10 years), I just upgraded .....

    Lucky You! 😀

    Regards,
    fireodo

  • pfblockerng ssl interception

    8
    0 Votes
    8 Posts
    3k Views
    GertjanG

    @tomtheone said in pfblockerng ssl interception:

    My goal would be to prevent the SSL warning

    You can't. I can't. An the day some one manages to do so, we can all power down our pfSense and do other thing, as the final judgement day had arrived.

    See here why you can't - the browser will always show an error.

    True, browsers could show a more "friendlier" message.

    And true, with a proxy solution, you could make all involved browser (all your local LAN devices) trust the cert of the DNSBL pfBlokcerNG web server. But that means you control every device involved and in that case you could simply tell every user involved : "If a site doesn't seem to show up, don't worry - you didn't want to look at it anyway".

    Btw : all this isn't related to pfSense, as pfSense doesn't care about encryption protocols etc. https, or TLS. It's about how and why web servers and web browsers allow secured connections.
    Install Youtube, ask for some "TLS" videos' and a couple of instances later you will become aware of how it all works.

  • VLAN interface rules deleted after pfBlockerNG cron update runs

    1
    0 Votes
    1 Posts
    130 Views
    No one has replied
  • pfBlockerNG Reports DNSBL Block HTTPS empty

    8
    0 Votes
    8 Posts
    1k Views
    keyserK

    @focheur91300 Unfortunately I can’t. I’m on a SG-2100 with a 8Gb eMMC that would be worn out in a year by using python mode, so I’m using Unbound Mode like you.

    But there are several posts here on how to configure python mode, and it’s very easy.

  • GeoIP blocking with IP supression

    4
    0 Votes
    4 Posts
    431 Views
    johnpozJ

    Doesn't have to be on floating, but that would be one way to put it before a rule on interface. It needs to be above the rule your using for pfblocker.

  • pfBlockerNG-devel net

    7
    0 Votes
    7 Posts
    1k Views
    GertjanG

    @naveen7355 said in pfBlockerNG-devel net:

    https://gist.githubusercontent.com/BBcan177/4a8bf37c131be4803cb2/raw

    Why would you show that one ?
    Of course it works.

    You should test the urls in YOUR setup - not mine.

    @naveen7355 said in pfBlockerNG-devel net:

    its updated now but still website is not blocking

    ?+?+?

    And again, You do not mention details about your setup.
    Neither that you tried to visit hosts that are blocked (== list in the DNSBL feeds).

    What about this test :

    dc519cea-556e-453c-85e3-43e29270a59e-image.png

    From any of these 3 lists, take some domain names listed in these feeds (again : do not use my example feeds I use, use YOUR DNSBL lists) and test them in your browser.
    The counters should start to increment.
    The Firewallpf > BlockerNG > Alerts should show that that domain name was blocked and reference the feed you got it from.

  • pfBlockerNG Script

    2
    0 Votes
    2 Posts
    383 Views
    GertjanG

    @yorke

    PfBlockerNG hooks into unbound, being a resolver.
    All it sees are DNS requests, going and coming from some DNS servers.

  • pfBlockerNG-devel Reports Show Blocked IPv6 as SRC Outbound (Backwards)

    1
    1 Votes
    1 Posts
    174 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.