• How to tell which block lists haven't been used?

    3
    0 Votes
    3 Posts
    447 Views
    O
    @steveits thank you, I see it now.
  • cn(Removed due to SafeSearch conflict)

    3
    0 Votes
    3 Posts
    831 Views
    GertjanG
    @wolfsden3 said in cn(Removed due to SafeSearch conflict): [ v3.1.0_11 ] ??? Not round 2 - you are many round late. [image: 1679387484607-98fc1b3e-7e3a-4324-ba89-bcac894837e8-image.png]
  • Is it working correctly??

    Moved
    5
    0 Votes
    5 Posts
    845 Views
    S
    @wc2l Does Diagnostics/tables show it has content?
  • pfBlockerNG-devel - 3.2.0_3

    8
    0 Votes
    8 Posts
    1k Views
    fireodoF
    @freddy-0 said in pfBlockerNG-devel - 3.2.0_3: Still seems to be at line 729 but not too concerned as everything seems to be working. You are probably running pfblocker in pfsense+ 23.01 - I saw in my lab machine (with 23.01) that there the line in question is at 728 ;-)
  • IPv4 Custom_List entries wrong

    12
    0 Votes
    12 Posts
    887 Views
    S
    @jrey well then, hello again :) Yeah to be clear it’s not always a problem. One also has to have the dedupe option checked. However it’s not intuitive and potentially dangerous, so I try to call it out.
  • pfBlockerNG Widget Counters Incorrectly Cleared Daily

    4
    0 Votes
    4 Posts
    863 Views
    L
    @steveits Yup, that was it! Thanks!!
  • howto keep manual floating rule on top

    6
    0 Votes
    6 Posts
    596 Views
    M
    @steveits Awesome! That one passed me until now. Thx.
  • IP not covered in generated deny alias

    19
    0 Votes
    19 Posts
    3k Views
    S
    I am guessing the deduplication is just using the same mechanism as the normal deny rules. This makes using the alias function pointless. Each alias should be de-duplicted individually otherwise you cannot tell what aliases is blocking what therefore you cannot create individual blocking rules and even if all rules were enables as recommended by BBcan177 your logging would not be accurate.
  • Configure pfBlockerNG to Filter 1-1 NAT and/or Port Forwards

    3
    0 Votes
    3 Posts
    631 Views
    M
    @steveits Thanks for your suggestion. I got it to work after a fashion. The autoconfiguration of pfBlockerNG puts the blocking on only the LAN. When I added to the WAN, it began to operate as I desired. I wonder why the autoconfigure ever puts the rule on the LAN instead of the WAN when the purpose of pfBlocker is to keep bad crap out of your system. Thanks, Mike
  • pfblocker blocking odd requests from pfsense.. i think

    10
    0 Votes
    10 Posts
    1k Views
    GertjanG
    @omethe well, if you add a feed that is hosted 'off-site', some where on the internet I guess you want to be able to resolve that host nam, and not getting a 0.0.0.0 as an answer ..... if not, whats the point of adding / using that host name in a feed URL
  • How to backup pfblockerng please?

    18
    0 Votes
    18 Posts
    5k Views
    D
    @gertjan Rarely am I so happy to be shown that I am wrong. Thank you for your detailed rundown (and to @BBcan177 for confirming that all custom lists are base64 encoded)!
  • pfBlockerNG-devel v3.1.0_19/10

    77
    10 Votes
    77 Posts
    25k Views
    D
    @BBcan177 Just wanted to confirm that I inserted the (most recent) link to the JSON file and it is parsing just fine. Much easier than manual downloads, thanks!
  • Internal Web Server: how to protect with pfBlockerNG

    4
    0 Votes
    4 Posts
    813 Views
    R
    @prx can you let me know if you're using a previous version of Magento 1? That can be a problem for you since users are updating their sites from an earlier version to the most recent version of Magento 2.4.6. You may look into Magento 2 Upgrade.
  • IP Alias List Creation Issue

    4
    0 Votes
    4 Posts
    724 Views
    S
    @jcook-atlas. this is the exact setup i was using before switching to pfblockerng. i switched because of needing to touch the alias file and change the date to older to make it actually update. I'll check my notes on it. Thanks for the suggestion. This may work in the interim but I would love to see the designed functionality of PFBlocker fixed.
  • MD5 hashes list ?

    1
    0 Votes
    1 Posts
    287 Views
    No one has replied
  • Issue with CARP in DNSBL

    14
    0 Votes
    14 Posts
    2k Views
    K
    @viragomann @juliokele Changing it to LAN did not help, either :( Attached a few images. I just can not seem to find the log files, please see attached images. Changed Web GUI https port of pfSense to 500 Set pfBlockerNG DNSBL to CARP with unique settings Made sure subnet is not in use Reloaded DNSBL still no success... [image: 1678746050065-bildschirmfoto-2023-03-13-um-23.19.08.png] [image: 1678746049981-bildschirmfoto-2023-03-13-um-23.06.12.png] [image: 1678746049909-bildschirmfoto-2023-03-13-um-23.05.24.png] [image: 1678746049844-bildschirmfoto-2023-03-13-um-23.02.44.png]
  • MalwarePatrol - domain based Feeds

    1
    0 Votes
    1 Posts
    294 Views
    No one has replied
  • PFBlockerNG strips out private IP addresses?

    3
    0 Votes
    3 Posts
    706 Views
    J
    Give this a try - I had a similar issue to yours and I used Alias lists in native pfSense. See my post
  • pfBlockerNG and Bogon

    1
    0 Votes
    1 Posts
    374 Views
    No one has replied
  • Properly whitelisting IP addresses

    4
    0 Votes
    4 Posts
    2k Views
    T
    @kkit I initially thought that but as you mentioned opening both ways and it asking about ports incoming, I re-thought it.. What PFSense is essentially doing, is providing an easy way to see a list of commonly used lists of advertising, trackers, coinblockers and malicious sites, and automate a way to download and update, with an easy to navigate interface. If you have an allow outgoing list setup, (example, I have the InterNIC root DNS servers in a allow out to make sure they aren't blocked), you can just jump into pfBlockerNG/IP/IPv4, select that IPV4 list, scroll down to IPv4 Custom_List and add them there, quick and dirty... You could also just create a firewall ALIAS and manually add what you want to that and use it in a allow outbound rule. I did this for my work's ASNs, 11 IPV4 ranges and 1 IPV6, so that I don't run into issues as I work from home 3 days a week. Another way is if the IP that is being blocked is normally reached by a domain name, like your typical website, you can add the domain to the DNSBL/DNSBL Whitelist as the domain name. Maybe 90% of the time I just add the domain that corresponds with the IP, to the DNSBL whitelist and that takes care of it.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.