• 0 Votes
    5 Posts
    686 Views
    fireodoF

    @ertnec said in pfBlockerNG-devel v3.0.0_15 not clearing down tmp files, slowly fills /tmp up.:

    @bbcan177 said in pfBlockerNG-devel v3.0.0_15 not clearing down tmp files, slowly fills /tmp up.:

    @ertnec
    Download an updated script for ASN processing and see how that goes.

    curl -o /usr/local/pkg/pfblockerng/pfblockerng.sh "https://gist.githubusercontent.com/BBcan177/3aabea5edf7b40554d93085bff380b6f/raw"

    Hi, I've replaced the file you suggested, however, it still seems to be leaving these files alone & /tmp is still filling up.

    I can confirm this.
    Update: Still present in v3.0.0_16
    (I added a cron-job: rm /tmp/pfbt* )

    Regards,
    fireodo

  • 0 Votes
    2 Posts
    304 Views
    provelsP

    @rk0
    I'd just reinstall if you think you have the 'Save Settings' checkbox marked. You could always just build fresh and restore the config, too.

  • pfBlockerNG in an Active Directory environment

    10
    0 Votes
    10 Posts
    3k Views
    EveningStarNME

    @tzvia Thank you! I should have thought about adding in-addr.arpa to domain overrides. I added one for each 24-bit subnet, and that did the job.

  • pfBlockerNG - FireWall rules

    1
    0 Votes
    1 Posts
    240 Views
    No one has replied
  • Switched to Python unbound Mode and now have issue

    35
    0 Votes
    35 Posts
    6k Views
    N

    @gertjan Downloads are instant.
    Filtering through 1m takes most of the time.
    And no, the pipes are not saturated @100Mbits

    And dns doesn't suffer overall.
    If I get the dreaded error in resolver logs, no resolution is possible.
    Ping with ip works great.

    I need to experiment a bit more, but since this is service affecting during normal hours

  • Anti-fringement list from Iblock

    1
    0 Votes
    1 Posts
    211 Views
    No one has replied
  • deleted

    1
    0 Votes
    1 Posts
    189 Views
    No one has replied
  • Disable NAT rule creation

    9
    0 Votes
    9 Posts
    632 Views
    ?

    @derelict said in Disable NAT rule creation:

    @thisisme It can also render the page much less pleasant, with broken image placeholders (browser-dependent), ALT text, etc.

    Adaway for Android does the same. Im fine with that. Why am I not allowed to decide this myself?

  • I am trying to configure pfsense inline mode (not route) with pfBlocker

    12
    0 Votes
    12 Posts
    1k Views
    ocernaO

    @mind12 Hello,

    I have reviewed each of the recommended steps:
    1- DNS resolver is listening for all interfaces, if I configure that it only listens for the Bridge interfaces, it presents us with the same result.

    2- Modify the validation code for the virtual IP, add an IP of the example segment 192.168.1.203 and the same result still does not block domains, for verification use nslookup and it continues to show the original IP of the domain which was used as test, in few words is not blocking.

    3- Well my opinion about this is that apparently there is a link between the DHCP service and the DNSBL to work with it, but as I said this is only my opinion.

    Previously I was looking for more information and I was with that unknown that if I wanted to make a bridge interface with DNS blocking, I would have to configure one of the interfaces that comprise the Bridge for this case the LAN will activate the DHCP service.

  • Packet Counts Not Updating in pfBlockerNG Widget

    36
    1 Votes
    36 Posts
    4k Views
    ?

    @digdug3 thank you

  • pfBlockerNG-devel v3.0.0_15

    39
    7 Votes
    39 Posts
    5k Views
    RonpfSR

    @xentrk If you have huge log files, the Report Alert Filter may timeout. Grep the log files from a Shell instead.

  • ship pfblockerbg-devl logs?

    4
    1 Votes
    4 Posts
    624 Views
    R

    @bbcan177 said in ship pfblockerbg-devl logs?:

    @rtw915
    As an example:
    https://www.reddit.com/r/pfBlockerNG/comments/bu0ms0/pfblockerngtelegrafinfluxdb_ip_block_list/

    That is cool! I did not know that was possible. I saw in your Reddit post that you stated "pfSense doesn't have a lot of graphing/logging functionality." I 100% agree with you that it should not be part of the firewall, but it would be awesome to have a Netgate preferred solution like Graylog with a step by step guide to integrate the logging from the firewall and its common packages into a centralized visualization platform.

  • GeoIP vs Feed discrepancy

    2
    0 Votes
    2 Posts
    438 Views
    M

    Looks like this is related to the GeoIP2 Lite lists for representative countries. Details in this forum post and the Max Mind release notes.

  • DNSBL not creating firewall rules

    24
    0 Votes
    24 Posts
    4k Views
    F

    @bob-dig
    I temporarily disabled my feed and added reddit.com and www.reddit.com to the DNSBL Custom_List and the website (and others) is still not blocked. (Yes, I did a force update all)

    I have tried on different computers on the network and they can still access it.

    I have also tried on three different browsers.

    I am really confused why some sites are blocked while others are not.

  • iTalkBB, 3CX and whitelisting

    2
    0 Votes
    2 Posts
    520 Views
    R

    I'm not an expert but I used 3cx with pfsense for 3 years at my previous job.

    I had the same issue with no audio on one side on two different occasions with 3cx. 1. was when I did not have the full cone NAT configured properly. I don't have access to 3cx anymore but I remember there was a network troubleshooting utility. Until I fixed the NAT problem it would not return successful. This might help https://www.3cx.com/docs/pfsense-firewall/

    The other time I had a similar issue was because the user vpn was not routing and using NAT instead. After I changed the OpenVPN config to routing and added the VPN static routes in pfsense pointing to the VPN server it worked.

    I also remember there were instances where we would receive calls from external entities that used VOIP and those connections did not need to go through our SIP provider. I realized this because I had originally opened the SIP ports with the src address of the SIP provider, and most calls would work except from some specific vendors. After opening up the the SIP ports from "any" those vendors started working as well.

    As far as iTalkBB, I have never used it, but pfBlockerNG just uses regular firewall rules. You can turn on logging and see if something is a miss. Or even faster test just temporarily disable the firewall rules and see if stuff starts working.

    I have noticed the Geo IP is not 100%, so maybe you are running into an issue there. It was recommended somewhere that you don't block the world. I prefer to do the reverse which is just to allow specific countries.

    Hope this helps!

  • Cannot disable logging

    1
    0 Votes
    1 Posts
    267 Views
    No one has replied
  • Talos IP-blacklist download fail

    7
    0 Votes
    7 Posts
    3k Views
    R

    @bbcan177 Thanks. I fixed it the usual way: delete and add it back in :-)

  • When DCHP enabled then DNSBL is terminating Python mode....

    11
    0 Votes
    11 Posts
    1k Views
    Cool_CoronaC

    @gertjan You misunderstand me...

    Firewall has a LAN IP.

    I installed it from a workstation with a fixed ip.... not given by DHCP

  • Website Blocking from PfblockerNG.

    5
    0 Votes
    5 Posts
    576 Views
    M

    @gertjan Can you share me Skype id or phone number for help. if you no issue.

  • Log to pfBlocker Alerts only instead of the firewall logs

    5
    0 Votes
    5 Posts
    1k Views
    M

    I turned off inbound filtering completely instead and left the logging on for the outbound traffic.
    It would be great if we could configure inbound and outbound logging separately in pfBlocker.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.