• pfBlockerNG-devel v3.0.0 - No longer bound by Unbound!

    Pinned
    94
    10 Votes
    94 Posts
    87k Views
    GertjanG

    @flepti said in pfBlockerNG-devel v3.0.0 - No longer bound by Unbound!:

    my setup too

    You mean you use pfSense 2.4.5 and "007" fBlockerNG-devel ?
    Easy solution : upgrade ?!

  • Firewall Rules Order

    Pinned
    34
    0 Votes
    34 Posts
    23k Views
    V

    so happy to find the explanation relating the tables and lists!! thanks!

  • Bypassing DNSBL for specific IPs

    Pinned
    114
    5 Votes
    114 Posts
    89k Views
    JonathanLeeJ

    @mcury thanks for the reply I will test this soon and yet you know how it works out.

  • Support pfBlockerNG development!

    Pinned
    5
    4 Votes
    5 Posts
    11k Views
    A

    I can not wait to see how he is going to do the mass import for IP4 and DNSBL, I hope its just a simple text doc you can just upload just like you would a backup file on Ublock extension.
    Looking forward to it.

    I may have to get some more Ram lol only got 8 gig and I bet doing mass list imports will hit the Ram hard.

    Great work hope it's coming along well ;)

    Great job.

  • PfBlockerNG v2.1 w/TLD

    Pinned
    124
    1 Votes
    124 Posts
    264k Views
    E

    It would be really cool if it could automatically update the blocked TLDs based on the spamhaus statistics (https://www.spamhaus.org/statistics/tlds/) on a regular schedule. I realize that this may be more difficult than it sounds as I cant seem to find a spamhaus TLD feed, just a website. But if we dont dream then it will never happen!

  • PfBlockerNG v2.0 w/DNSBL

    Pinned
    1k
    2 Votes
    1k Posts
    2m Views
    RonpfSR

    @ck42 The entry is related to Firewall / pfBlockerNG/ DNSBL / DNSBL Category Blacklist.

  • PfBlockerNG

    Pinned
    1k
    2 Votes
    1k Posts
    2m Views
    K

    @breeoge said in PfBlockerNG:

    @belt9:

    I wanted to chime in here as I just updated from a month old RC to 2.4.0-RELEASE last night and ran into this problem today.

    I haven't read through all of the many pages of the many threads that seem related to this issue (show how popular pfBNG is!), so maybe this has already been covered.

    But I've seen several people state that this doesn't happen on ZFS - I have a raidz2 ZFS install, and this happened to me, just throwing that out there.

    That is good to know. Thank you for the report.  BBcan177 is currently updating it to use SQLlite and this should fix any issues in the future.  In the other thread there is a temp fix posted..

    https://create.vista.com/colors/palettes/

    Thank you
    BreeOge

    Hello my friend. Many thanks to Bbcan177 for keeping the report up to date. as a result of this, in principle, the given problems are corrected.

  • New pfblockerNG install Database Sanity check Failed

    38
    0 Votes
    38 Posts
    4k Views
    M

    @Laxarus

    Thank you Laxarus,

    It seems to have worked.

  • Kaspersky Error "Cannot guarantee authenticity of the domain"

    10
    0 Votes
    10 Posts
    1k Views
    A

    @mikekoke You should just set Null Block in the DNSBL Groups Summary section.
    As @gertjan clearly explained, HTTPS traffic cannot be intercepted and redirected like HTTP.
    This means showing a block page when accessing a blocked HTTPS domain (like stats.g.doubleclick.net) won’t work — your browser will flag a certificate error, because pfBlockerNG cannot present a valid certificate for those domains.

    ➡️ The recommended solution is to switch to Null blocking (logging), which silently blocks access without trying to show a redirect page.
    This way, users won’t see certificate errors, and the block is still effective.

    Let me know if you need help finding where to set this.

  • Issue with ADs Edge vs Firefox

    6
    0 Votes
    6 Posts
    225 Views
    W

    @Gertjan Thanks for the thoughts!!
    I find that most Windows PCs generate more traffic in general. There is lots of app and utilities that cause the traffic.

  • pfblockerng error log , any idea why? (solved, maybe)

    Moved
    1
    0 Votes
    1 Posts
    87 Views
    No one has replied
  • 0 Votes
    11 Posts
    784 Views
    N

    @Uglybrian said in LibreWolf: Block Applications from Connecting to a IP (*.googleusercontent.com):

    I myself just used a blocking method.

    Yes, I've done this before myself in another system but keep putting it off for my current, I used pfSense pfBlockerNG configuration guide. So I decided today to get this back working. Its much easeir using granular control then generic. My system diagram is like:

    Bond0 Diagram.jpg

    I will be using the above quide for the Lab-pfSense. I was trying to get blocking working just using pfBlocker alone, but unsuccessful. This guide and pfSense baseline guide with VPN, Guest and VLAN support for the Bare-bone pfSense.

    What do you think, any inputs and additions?

  • What are these numbers in pfBlockerNG widget?

    1
    0 Votes
    1 Posts
    83 Views
    No one has replied
  • 0 Votes
    12 Posts
    896 Views
    stephenw10S

    Yeah, I would use auto generated aliases in user created rules personally. That gives you complete control with all the benefits of auto updating.

  • pfBlockerng Stopped Packet Forwarding

    8
    0 Votes
    8 Posts
    433 Views
    J

    @Gertjan I specifically chose my list of public DNS servers becasue they do support DNSSEC, I've seen what DNS poisining can do. I don't need to see a movie I've lived it. Did I mention damned near 30 years in the business? BTW, doing just a root hint forward doesn't do DNSSEC as root hint servers are not DNSSEC complaint yet that.

    BTW, in the beginning of the post packet forwarding was being stopped, not just DNS being blocked when pfBlocker was enabled. Through a lot of reboots I was able to get the packet forwarding going again with pfBlocker going, but then found the DNS block.

    I did use ICMP from the firewall itself to validate the lack of packet forwarding. I wish the logs would indicate which rule has the "offending" match that caused the block, but it sounds like the process roles all the lists up into a single firewall rule.

    I really don't want to tear down all of pfBlocker and start over, but it sounds like I will have to do that. Need to see if I can pull all the data out of a backup so that I have all my lists then can just recreate them as needed.

    I'm going to look more into what @BBcan177 mentioned, although I think I am already there since I have disabled all my lists, just not 100% sure.

  • Pfblocker blocks all WAN traffic

    10
    0 Votes
    10 Posts
    897 Views
    D

    @jlw52761 Yes, I followed the suggestions in the answers and started disabling the feeds one by one and found the culprit. I checked the logs and found which feeds were mentioning the DNS address ( there were about 8) then just disabled them one at a time and found the one blocking DNS traffic.

  • Custom Aliasses for pfB GEO IP ??

    3
    0 Votes
    3 Posts
    148 Views
    S

    @thuizt You can create them as Alias Native format (eg mot Deny) and it only creates aliases not rules.

  • PfBlockerNG/-devel - Normal/unnormal reboot - No Internet (DNS?)

    8
    0 Votes
    8 Posts
    723 Views
    A

    @jlw52761 Unfortunately i didnt find a solution with pfblocker(ng). My current solution is to have switches back to my pihole setup and dont use pfblocker. Its still frustrating because of my dns force i dont have dns in lan when my server is off due to running pihole in a docker on the server.

  • Talos IP list download fail

    6
    0 Votes
    6 Posts
    3k Views
    S

    @fireodo Somehow this one escaped me.
    Didn't notice it until I updated to CE 2.8.
    Anyway, much appreciated.

  • Various d/l errors since March

    7
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.