• [SOLVED]Domain blocked but not URI

    1
    1
    0 Votes
    1 Posts
    372 Views
    No one has replied
  • 0 Votes
    23 Posts
    4k Views
    N
    @stephenw10 said in pfBlockerNG - unbound-control process spikes CPU to 100% every few seconds [SOLVED]: So just the list containing a bunch of obsolete domains? Not sure how many domains in that list are obsolete, and if that was the issue, however, what led me to actually remove the list is the fact that there are tons of legit domains in that list that pfBlocker was blocking. If you check the list, you will see asus.com and sony.com in there. And there is absolutely no reason to blacklist those sites. They are legit. Then I thought this was actually a whitelist that i was using as blacklist, but then you find all those porn sites in there and tons of other entries that are present in legit block lists. Its a mess. I just removed it and it all works.
  • Whitelisting IP addresses

    2
    0 Votes
    2 Posts
    599 Views
    M
    @deanfourie How do you know pfblockerng is blocking your VPN? Screenshot your log showing the block.
  • pfblockerng failed to parse

    Moved
    1
    0 Votes
    1 Posts
    460 Views
    No one has replied
  • pfBlockerNG]: Failed to parse:

    1
    0 Votes
    1 Posts
    398 Views
    No one has replied
  • Microsoft hostname resolving to pfBlocker virtual IP?

    2
    1
    0 Votes
    2 Posts
    391 Views
    johnpozJ
    @deanfourie said in Microsoft hostname resolving to pfBlocker virtual IP?: Any idea how this could be? You have it blocked in pfblocker.. its not blocked here ;; QUESTION SECTION: ;v10.events.data.microsoft.com. IN A ;; ANSWER SECTION: v10.events.data.microsoft.com. 3600 IN CNAME global.asimov.events.data.trafficmanager.net. global.asimov.events.data.trafficmanager.net. 3600 IN CNAME onedscolprdwus11.westus.cloudapp.azure.com. onedscolprdwus11.westus.cloudapp.azure.com. 3600 IN A 20.189.173.12
  • Is this expected for /31 ?

    6
    0 Votes
    6 Posts
    1k Views
    J
    @anna-count It's probably expected. I guess the question would be "Why would you want to block a point to point?" but that's just a guess. I use /31's for my VPN connections so pfSense does work with them but pfBlocker probably does not. Just a guess though.
  • 0 Votes
    3 Posts
    407 Views
    NollipfSenseN
    @justme2 Here is the answer as Gertjan said: "A ping to 127.0.0.1 should always work. Consider a non working 127.0.0.1 as a massive failure."
  • PfblockerNG crashes when configs saved

    5
    0 Votes
    5 Posts
    976 Views
    P
    @gertjan Thanks again. Since I dont have 2.6 running but am interested once the problems I have are resolved allow me to ask whether with 2.6 it will find the ASN number (as 2.5.2 did) as I type in the domain name. Or do I have to go and find the ASN number first. Parry
  • GeoIP not working? Where is rule?

    4
    0 Votes
    4 Posts
    1k Views
    S
    @patrick999 said in GeoIP not working? Where is rule?: I set it to deny inbound for every region except North America It should take less resources to do it the other way, allow North America. I usually use Alias Native and then can use it in my own rules, such as the Source on a NAT rule.
  • Twitter Ads Server

    6
    0 Votes
    6 Posts
    951 Views
    NollipfSenseN
    @provels It depends on whether one leaves the tab open as I do and how often one post to the site. If one goes to more when logged into account Settings and privacy > Ads preference > Interest, you could see thousands of interest Twitter Algorithm selected base on one's interaction with each tweet. I even selected that I don't want to see ads. So, there is a browser container add on from Github to prevent cookie snooping.
  • Email reports?

    3
    0 Votes
    3 Posts
    709 Views
    P
    @viragomann said in Email reports?: @pyrodex said in Email reports?: I've looked at the the wonderful pfB reports for dnsbl but not sure how we can obtain the same data to be emailed out on a daily basis. pfBlocker might write this into log files. You can use the mailreport package to send the log to you. mailreport also lets you apply a filter to the file, so you can limit the lines to the actual date or to specific errors or whatever you want. I tried this with the dnsbl.log and switched off VIP mode to NULL (0.0.0.0) which logs it into the file. However, I am seeing LARGE discrepancies between what the report shows for a 24 hour period vs what the log shows when I parse it. I even wrote a simple script to give me some data from the log and in fact do use the email reporting tool for that output but once again huge differences.
  • Can't get devices on VLANs to go through DNSBL

    1
    0 Votes
    1 Posts
    209 Views
    No one has replied
  • Blocking my VPN

    1
    0 Votes
    1 Posts
    284 Views
    No one has replied
  • Failed to load python module 'maxminddb': No module named 'maxminddb'

    3
    0 Votes
    3 Posts
    880 Views
    Cool_CoronaC
    Just deleted the py.error.log and it went away. On 2.5.2 still and havent upgraded yet. PFB 3.1.0_1
  • pfBlocker log files (another one)

    1
    2
    0 Votes
    1 Posts
    261 Views
    No one has replied
  • ip_block.log entry query - direction

    3
    0 Votes
    3 Posts
    1k Views
    D
    Redmine ticket logged through support channel: https://redmine.pfsense.org/issues/13209?next_issue_id=13207&prev_issue_id=13210
  • There were error(s) loading the rules: /tmp/rules.debug:35

    6
    0 Votes
    6 Posts
    837 Views
    S
    @nasheayahu If it helps (you or others) I have a note from several years ago to, when installing pfBlocker, double the default Firewall Maximum Table Entries (with a minimum of 2 million). Note however there is (or was, don't have 22.05 yet) a bug where the sentence "On this system the default size is" shows the current setting, whatever it's set to.
  • Whitelist dnsbl entire domain

    1
    0 Votes
    1 Posts
    375 Views
    No one has replied
  • Using Large List on netgate 1100

    3
    0 Votes
    3 Posts
    665 Views
    R
    @steveits said in Using Large List on netgate 1100: The CPU on the 1100 is not exactly fast The CPU is half the battle here. That large list will quickly chew up the remains of the 1GB RAM.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.