• Is IPinfo safe?

    15
    0 Votes
    15 Posts
    2k Views
    J
    @Gertjan Just a friendly poke -- I took your post as "funny, as it is meant to be" - others it appears, assumed you were serious about avoiding it because it is "free". I'm a "paid free" user as well, with real netgate gear, but that wasn't the point. The person raising the question has a configuration (or other issue) it has nothing to do with it being product or list being "free" or "spam".
  • Problem with pfBlockerNG DNS Filtering in Multi-Network Setup

    1
    1 Votes
    1 Posts
    153 Views
    No one has replied
  • 1 Votes
    2 Posts
    256 Views
    GertjanG
    @chrcoluk Yep. Is known : Problem with Python Group Policy - Cached Domains
  • PfBlockerNG high CPU

    89
    0 Votes
    89 Posts
    33k Views
    C
    Hit the same issue myself, everything ran fine for years, but two things happened. Letting neighbour use my network currently, as they got no broadband, and they have a TV that is absolutely unreal in terms of DNS traffic, hence recently all me doing stuff on pfblockerng. Decided to change pfblockerng cron from hourly to daily as I had nothing updating more often than daily anyway. This combination seems to have unsettled the pfblockerng web server, I wouldnt personally call this a sinkhole as its a webserver responding to requests, a sinkhole is a null route like replying with 0.0.0.0. Obvious solution is to stop using the VIP filtering, if that keeps all the dnsbl logging then no issue, but I read in the thread VIP, stats only accrue from VIP traffic. I see a ton of states in fin wait, so looking to see if the time outs can be reduced, seeing also if the web server is actually caching content or fetching its index from storage every time. I see its configured with 4096 bit keys, over kill for this sort of thing and also a top end EC. The index.php seems to be deliberatly configured to not cache, but I can see why, as its used for logging stuff, which would break if cached by the client, I think I will just move some stuff of the web server.
  • PfblockerNG blocking Speedtest tracker but which rule ?

    5
    0 Votes
    5 Posts
    437 Views
    C
    I have made an observation with the speedtest android app, it looks like it does sneaky DoH queries to bypass your network's DNS, after I added a DoH blocklist, the app will report connectivity issues with the go button a red colour, however any tests still run fine, so it does fall back to system DNS.
  • How to unblock all subdomains?

    4
    0 Votes
    4 Posts
    358 Views
    tinfoilmattT
    @UncleBilly Ah, right! Apologies for the unproofed reply. The infoblocks are always key wherever they appear.
  • pfBlocker re-enables floating rule logging even after disabling

    7
    0 Votes
    7 Posts
    552 Views
    M
    @Bob-Dig Super; thank you for taking the time to help. This has been driving me bananas.
  • Live Reload

    1
    0 Votes
    1 Posts
    150 Views
    No one has replied
  • 0 Votes
    5 Posts
    454 Views
    V
    @Antibiotic I assume, you're talking about a VPN service provider to access the internet. So yes, then you have to select your LAN. pfBlockerNG adds rules for outbound traffic to the internal interface, e.g. LAN, likewise as you manually can restrict the outbound traffic by rules.
  • Custom logging disable

    2
    0 Votes
    2 Posts
    176 Views
    A
    @Antibiotic Oh, sorry finally found this option. Can close this question))
  • Differentiated filtering by interface with pfBlockerNG: a solution?

    2
    0 Votes
    2 Posts
    212 Views
    M
    @ephedan In short, pfsense is not a content filtering device. pfblocker is very limited in this regards in that there are not per interface dnsbl rules. Any vlan that uses pfsense for DNS is subject to the same content policy on pfblockerng. If this is a home situation, my advice would be to use Adguard or Pihole which has greater functionality.
  • Default Whitelist

    2
    0 Votes
    2 Posts
    310 Views
    S
    @aivxtla Here you are: s3.amazonaws.com s3-1.amazonaws.com # CNAME for (s3.amazonaws.com) .github.com .githubusercontent.com github.map.fastly.net # CNAME for (raw.githubusercontent.com) .gitlab.com .sourceforge.net .fls-na.amazon.com # alexa .control.kochava.com # alexa 2 .device-metrics-us-2.amazon.com # alexa 3 .amazon-adsystem.com # amazon app ads .px.moatads.com # amazon app 2 .wildcard.moatads.com.edgekey.net # CNAME for (px.moatads.com) .e13136.g.akamaiedge.net # CNAME for (px.moatads.com) .secure-gl.imrworldwide.com # amazon app 3 .pixel.adsafeprotected.com # amazon app 4 .anycast.pixel.adsafeprotected.com # CNAME for (pixel.adsafeprotected.com) .bs.serving-sys.com # amazon app 5 .bs.eyeblaster.akadns.net # CNAME for (bs.serving-sys.com) .bsla.eyeblaster.akadns.net # CNAME for (bs.serving-sys.com) .adsafeprotected.com # amazon app 6 .anycast.static.adsafeprotected.com # CNAME for (static.adsafeprotected.com) google.com www.google.com youtube.com www.youtube.com youtube-ui.l.google.com # CNAME for (youtube.com) stackoverflow.com www.stackoverflow.com dropbox.com www.dropbox.com www.dropbox-dns.com # CNAME for (dropbox.com) .adsafeprotected.com control.kochava.com secure-gl.imrworldwide.com pbs.twimg.com # twitter images www.pbs.twimg.com # twitter images cs196.wac.edgecastcdn.net # CNAME for (pbs.twimg.com) cs2-wac.apr-8315.edgecastdns.net # CNAME for (pbs.twimg.com) cs2-wac-us.8315.ecdns.net # CNAME for (pbs.twimg.com) cs45.wac.edgecastcdn.net # CNAME for (pbs.twimg.com) cs2-wac.apr-8315.edgecastdns.net # CNAME for (pbs.twimg.com) cs2-wac-us.8315.ecdns.net # CNAME for (pbs.twimg.com) cs45.wac.edgecastcdn.net # CNAME for (pbs.twimg.com) .pfsense.org .netgate.com
  • Problemas acceso sap arib

    1
    0 Votes
    1 Posts
    226 Views
    No one has replied
  • 0 Votes
    1 Posts
    144 Views
    No one has replied
  • Unblocking Viafoura

    1
    0 Votes
    1 Posts
    177 Views
    No one has replied
  • PRI1 Spamhaus_drop, permanent error for update, already one week

    1
    0 Votes
    1 Posts
    157 Views
    No one has replied
  • No able to access some features of google email, documents, share account.

    17
    0 Votes
    17 Posts
    1k Views
    JonathanLeeJ
    Google tag manager might be causing this as it gets blocked a lot, it might be required now as a whitelisted item, can anyone confirm this?
  • pfBlockerNG-devel 3.2.0_20 DNSBL Category UTI Database Download Issue

    1
    0 Votes
    1 Posts
    220 Views
    No one has replied
  • Reload log shows (unrequested) whitelisted entries

    1
    0 Votes
    1 Posts
    219 Views
    No one has replied
  • PfBlockerNG WAN Inbound Rule

    3
    0 Votes
    3 Posts
    278 Views
    D
    @Gertjan I do have the MAXMind ID set up. How do I apply the same settings to inbound access rules, such as VOIP, and IIS,?
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.