@Gertjan said in pfblocker not blocking/working:
So DNS works ** and there is nothing to do
100% - but there are also so many things that can be done to change and control the behaviour of DNS traffic.
The first (next) step for @zachelle as you correctly point out, is to change the "client" as by default
that doesn't use the local router dns
The OP says:
I am using DHCP.
This is where the DNS address that is being handed to the client can be assigned.
That doesn't mean however, that all clients will even "listen" or "use" the address being assigned. DoH etc. IoT devices that are simply hard coded to point to the companies own DNS etc.
It does take some understanding of the individual devices traffic and planning, but all of these things can be shaped/controlled if required.
The OP is looking as step one to have the DNS go through the local DNS where DNSBL can do what it needs to do. Then there will be new observations, "it's still doing this"
BTW that Talos feed download issue. (when it fails randomly) is a volume of traffic issue at the server.
Consider this:
I setup another test box pfSense CE and did a standard pfBlockerNG install. Meaning that the cron settings for pfBlockerNG are set to run at the 00 mark of the hour. I picked a couple of lists that people complain fail often (Talos being one of them)
Shortly thereafter I noticed that the Talos feed started to randomly fail on the test box, but my main firewall wasn't having this problem. Has been downloading that feed for months without issue. Then it occurred to me that every system "out of the box" is configured the same way, (by default) and there is a high probability that most people won't change this.
Several months ago I had changed the cron timing of pfB for completely other reasons. The unknown(unrecognized) side effects at the time and since that change, is that Talos feed hasn't failed.
Then the tiny light went on, in my head, I moved the test box cron job off the top of the hour, and the Talos feed on the test bed generally hasn't failed since.
Defaults are good, Defaults are bad.