• First run pfBlockerNG - false positive?

    6
    0 Votes
    6 Posts
    625 Views
    F
    @gertjan said in First run pfBlockerNG - false positive?: But you, as the admin, have added dnsbl feeds (or IP feeds) to pfBlockerng. Hostnames (or IP's) in these feeds will get blocked. Did you have a look at these lists ? ;) Thank you for a nice and informative answer! I will try with the address you suggest, and no... I have not looked at the lists in detail, but looks like a good idea to get a better understandning of this... :)
  • switch from pfblockerng-devel to pfblockerng

    3
    1 Votes
    3 Posts
    745 Views
    G
    Thank you for the answer. I should have thought to check there instead of just looking at the normal backup / restore. Appreciate your help.
  • pfblockerng.log and de-duplication ?

    3
    0 Votes
    3 Posts
    432 Views
    S
    @jrey I think that’s the “uniq[ue] check.” Note if using Alias Deny pfB will dedupe across the deny lists, even if used for different rules. Might be what you’re seeing given the label. Alias Native does not.
  • Cannot access dns resolver settings

    12
    0 Votes
    12 Posts
    1k Views
    J
    @steveits said in Cannot access dns resolver settings: Looks to me like it was restarted on request...settings change? DHCP lease registration? I have all of my clients are using pfSense for DNS although there are a few on my network where google is programed into the firmware. There was no manual restart (I did do a manual restart of unbound today but not at that time) nor were any changes to client dhcp being done at that time. That said, I'll use my 7th decade age as an excuse and therefor I'll pay more attention in the future. You are correct, I'm not using forwarding resolver and I am aware of the DNSSEC requirement to not be used. These frequent periods of no response (hanging?) were not experienced in 22.04 and pfBlockerNG-devel.
  • pfBlocker blocking all DNS

    13
    0 Votes
    13 Posts
    3k Views
    P
    I checked and mine is not using a forwarder but is set to use DNSSEC. Right now I have a cron job set to simply restart unbound at 02:00 every day. If not seen a recurrence of this issue since doing that.
  • Pfblocker search CIDR

    1
    0 Votes
    1 Posts
    228 Views
    No one has replied
  • 3.1.0_9 Advanced Inbound Firewall Rule Settings broken

    5
    0 Votes
    5 Posts
    858 Views
    S
    The overlay for selecting a Alias out of the already created ones does not appear and leave empty. Just entering a "known" alias and try to save lead in a empty field of the "Custom Destination"
  • PFBlocker and SNORT issues after upgrade from 22.05 to 23.01

    Moved
    9
    0 Votes
    9 Posts
    1k Views
    D
    @bmeeks Got it. Thanks a lot
  • Snort Alert for IP on blocklist

    3
    0 Votes
    3 Posts
    377 Views
    NollipfSenseN
    @efriedman Snort would see things before pfBlockerNG, I believe...
  • pfBlockerNG/pfBlockerNG-devel v3.2.0_2

    57
    10 Votes
    57 Posts
    27k Views
    P
    Update, I just moved from 3.2.0.1 to pfBlockerNG 3.2.0_3, no issues so far. Network throughput, memory and CPU usage all within normal parameters. Thank you @BBcan177 for all your work on this excellent package!
  • pfBlockerNG HA CARP issues

    4
    0 Votes
    4 Posts
    377 Views
    V
    @fluvannait You changed to type to CARP without editing it? A CARP VIP for DNSBL is an imbecility. This IP is only needed at the master. So it can be a simple IP alias. If you want to have it on both, you can hook it up on a CARP.
  • Talos_BL erros

    4
    0 Votes
    4 Posts
    1k Views
    J
    @creationguy I second that. "Its not uncommon for this feed." I don't worry about it, just clear the message on the widget whenever you see it. the most I've ever seen it miss is 3 in a row stacked up. it is usually just 1 miss and it gets it next cycle. less than stable feed i suspect. All the others I use are fine.
  • GeoIP unk after recent update

    16
    0 Votes
    16 Posts
    2k Views
    B
    @bbcan177 Thx, fpr your support! :) I have since uninstalled and reinstalled the pfBlockerNG-devel package. I also deleted the directories (/usr/local/share/GeoIP and /var/db/pfblockerng). Since then, I have not noticed any more such entries. If an entry appears again, I will test the commands and report in this thread.
  • Post 23.0.1 Upgrade Floating Firewall Rule Error

    3
    0 Votes
    3 Posts
    318 Views
    P
    @bbcan177 Thanks for the response, I have found the thread and the redmine: https://redmine.pfsense.org/issues/13953 https://forum.netgate.com/topic/177884/pfblockerng-devel-v3-2-0-crashing-repeatedly-on-pfsense-23-01/7?_=1676563838954 Its not a pfblocker issue its related to openvpn clean up.
  • V 3.2.0 with pfsense 23.01 RC 20230202

    34
    1 Votes
    34 Posts
    8k Views
    O
    Yes, working now. THX
  • pfBlockerNG-devel v3.2.0 crashing repeatedly on pfSense 23.01

    25
    0 Votes
    25 Posts
    2k Views
    P
    @bbcan177 the new version fixed my issue thanks a lot. Great and super duper fast job
  • 0 Votes
    4 Posts
    459 Views
    S
    @shaw222 see https://docs.netgate.com/pfsense/en/latest/troubleshooting/firewall.html#new-rules-are-not-applied
  • Firehol level 1 list blocking LAN resources

    27
    0 Votes
    27 Posts
    14k Views
    M
    @seanr22a Just found this and started using them. THX!
  • 0 Votes
    8 Posts
    2k Views
    dennypageD
    @marco-42 Welcome
  • grep -vF commands do not complete

    4
    0 Votes
    4 Posts
    708 Views
    M
    @SteveITS : Thank you for the link.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.