• pfBlockerNG-devel DNSBL Event Timeline - increase dnsbl log size

    3
    0 Votes
    3 Posts
    312 Views
    O

    @keyser oh thank you very much for helping! now I feel really dumb, I swear I've looked at that page a dozen times!

  • v3.2.0 python module missing

    6
    0 Votes
    6 Posts
    857 Views
    B

    Ended up working in this thread

    https://forum.netgate.com/topic/177212/pfblockerng-devel-v3-1-0_19-10/76

    To get resolution and there was a hung upgrade between 23.01 Beta and 23.01 RC that held back the unbound version which kept me on the old python version.

    Running pkg upgrade via shell and rebooting fixed all of my issues.

  • Blocking custom urls(different website sections).....not domains

    3
    0 Votes
    3 Posts
    337 Views
    F

    @johnpoz Thank you for the quick response, understood, OK, can squid transparent proxy and pfblocker coexist? Would you advise using squid guard or just regular squid? I've never installed the packages before but will try get them to co-exist.

  • Geoblocking the world except for home

    11
    0 Votes
    11 Posts
    2k Views
    NogBadTheBadN

    @steveits said in Geoblocking the world except for home:

    @nogbadthebad Since you showed "alias permit" just be aware that reportedly de-dupes across other permit or deny lists. There was a thread last year sometime where someone pointed out IPs were being removed. Alias Native will leave the lists unchanged.

    Cheers I've changed them :)

  • V3.2.0 + RC23.01

    1
    0 Votes
    1 Posts
    257 Views
    No one has replied
  • Can't turn off DNSBL feeds

    1
    0 Votes
    1 Posts
    353 Views
    No one has replied
  • v3.1.0_11: Unable to download the MaxMind GeoLite2 DB

    3
    0 Votes
    3 Posts
    471 Views
    U

    @freph533

    @freph533

    I think I figured it out after reading some other posts. I was using a "real" domain name in System>General Setup and that was somehow causing this issue. I set it back to "home.apra" and it works fine now. I'm not sure how to get a "real" domain to work. Maybe I need a "Domain Override" or something in the DNS Resolver to get a real domain to work?

    Anyways, for now, setting back to something like arpa, localdomain, etc worked to resolve this issue.

    screenshot.jpg

    Hope that helps!

  • pfBlockerNG-devel v3.1.0_11 UT1 Header Field cannot be empty

    1
    0 Votes
    1 Posts
    240 Views
    No one has replied
  • Error messages from pfb_unbound.py in resolver log

    1
    0 Votes
    1 Posts
    252 Views
    No one has replied
  • GeoIP database missing US ISP IP range

    6
    0 Votes
    6 Posts
    658 Views
    johnpozJ

    @lk777 That IP is in there.

    But that is not your isp space.. that is owned by rackspace

    NetRange: 69.20.0.0 - 69.20.127.255 CIDR: 69.20.0.0/17 NetName: RSPC-NET-4 NetHandle: NET-69-20-0-0-1 Parent: NET69 (NET-69-0-0-0-0) NetType: Direct Allocation OriginAS: AS10532, AS33070, AS19994, AS27357 Organization: Rackspace Hosting (RACKS-8)

    Your isp owns this space for example

    NetRange: 69.112.0.0 - 69.127.255.255 CIDR: 69.112.0.0/12 NetName: NETBLK-OOL-6BLK NetHandle: NET-69-112-0-0-1 Parent: NET69 (NET-69-0-0-0-0) NetType: Direct Allocation OriginAS: AS6148 Organization: Optimum Online (OPTO)

    Your IP that you talk to the forum is in that space - its not in a 69.20/16

    And both of those ranges are in the geoio db that pfblocker downloads for US space..

    ranges.jpg

    You understand it condenses down ranges the so might not always be a exact cidr match, but your isp space in that range is included in that 69.112/12 (69.112.0.0 - 69.127.255.255) and that other US space you mention that is not your isp, is also included..

    As to it being 100% accurate - you understand IP space moves around right.. Global companies, IP space is rented and sold, transferred to other companies... There is no freaking way its 100%

    https://support.maxmind.com/hc/en-us/articles/4407630607131-Geolocation-Accuracy
    It is not possible for us to guarantee 100% geolocation accuracy.

  • weird reports for LAN and Guest blocks

    15
    0 Votes
    15 Posts
    1k Views
    M

    @motivio lets get that pcap started on pfsense.
    Not sure how often it's querying for snapchat but let it run until the alert in pfblocker comes up.
    Make sure count is set to 0
    Stop the capture
    Download the capture
    Open the capture
    search for the string in the capture. Edit > Find Packet > Set to string

    0a9cbe25-36eb-4bb1-9944-8306efaa8b03-image.png

  • 0 Votes
    11 Posts
    603 Views
    J

    @jdeloach
    Yes, of course. :-)

  • pfBlocker blocks outgoing traffic when it should not

    3
    0 Votes
    3 Posts
    507 Views
    F

    @gblenn Thanks to you,
    I just turned off the floating rules.
    I think it will work.

  • pfBlocker suddenly blocks all DNS lookups

    9
    1 Votes
    9 Posts
    1k Views
    G

    It's now been more than a month and this issue seem to be resolved. The only significant change was to stop using floating rules for pfBlocker.

  • pfBlockerNG showing unknown in Reports

    6
    0 Votes
    6 Posts
    1k Views
    M

    @manilx I did run the commands from the above referenced post:

    cd /usr/local/share/GeoIP /usr/bin/tar -xzf GeoLite2-Country.tar.gz --strip=1

    Fixed this for the time being. As I'm running the latest .11 pfblockerng update I do think that this issues has been fixed. The only thing was that installing the update didn't also run the command, which I think it should.

  • pfBlockerNG-devel v3.1.0_9 / v3.1.0_15

    54
    13 Votes
    54 Posts
    22k Views
    M

    @BBcan177 , @smoke_aj, Good news, I assigned the DNSBL webserver to localhost instead of the DMZ1 interface. Now everything is working and I am not seeing the error message again. Also after a filter reload the error stays away. So I guess as soon as you chose a physical interface (in my case LAN or DMZ1 or DMZ2) instead of localhost for the webserver, and in my case also a non default port number (8080 8443) and enabling Ipv6 the bug manifests itself. Can you replicate this behaviour ?

  • DNSBL Group Disabled

    11
    0 Votes
    11 Posts
    845 Views
    N

    @nimrod Thanks for showing me where to delete. I won't bother you again.

  • pfBlockerNG-devel with AdGuard DNSBL not working -- HELP

    2
    0 Votes
    2 Posts
    2k Views
    keyserK

    @ssingh That’s going to take some “creative” configuration to work. PfSense comes with the UNBOUND DNS server which pfBlockerNG-devel modifies to answer DNS requests pr. Your allowed/denied lists. Adguard is another DNS filter service on its own, so now you have two competing services wanting to offer DNS services on port 53 - only one can prevail (seems adguard did in your case).
    I would seriously recommend you keep adguard away from pfsense itself. It’s not designed to run on there, and pfSense’s default setup and UI settings expects its own services to resolve DNS.

    Unless you know what you are doing, you’ll never get it to work as it would require quite at lot of “tinkering and custom setup”.

    pfBlockerNG-devel can do everyting adguard does - you can even have it use the same blocklists, so there is no need for both.
    So stick with that and stay away from the adguard service.

    It you insist, then install adguard on a raspberry pi and have pfsense and unbound use that as an upstream DNS server (forwarding mode).

  • Error on Permit Inbound rule IPv4 part

    3
    0 Votes
    3 Posts
    617 Views
    S

    Just verified this on 2 boxes each after a fresh re-flash back to pf 22.05 after changing repos on the updates tab corrupted my conf files and then led to persistent certificate errors at boot, going back to restore configurations I ran into this on each, and in IPv6 whitelists as well. Config.xml restoration went smoothly and re-installed the packages after fine also. Previously saved IP whitelists I created in 21.05 that I haven't edited since show the correct configuration settings when I inspect them inside pfblocker and verified are still working at the auto generated firewall rules in creates. Verified still present in pfblockerng-devel 3.1.0_9, I can no longer edit nor can I create any IPv4/IPv6 whitelist with the available "permit inbound" or "permit both" options as they previously used to function. "Alias permit" does work though with manually configuring a new firewall filter for the alias. Just located this after posting about it too:

    BBcan177BBcan177 MODERATOR 12 days ago
    @bob-dig @cjbujold

    See the patch here and report back pls.

    From the Shell or pfSense GUI > Diagnostics > Command Prompt > Execute Shell Command, run this command to download the patch.

    curl -o /usr/local/www/pfblockerng/pfblockerng_category_edit.php "https://gist.githubusercontent.com/BBcan177/1a33c42d0a61f3ddd9c2f1b1d514ed83/raw"
    "Experience is something you don't get until just after you need it."

  • Odd DNS requests

    7
    0 Votes
    7 Posts
    548 Views
    johnpozJ

    @nogbadthebad that is odd nslookup behavior..

    oh tip on windows, you could try adding . as the search suffix.. since it won't let you use nothing.. this seems to quiet it down.. Atlease from respect of nslookup debug.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.