Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfblocker not working after upgrading to Pfsense 21.05.1-RELEASE (arm)

    Scheduled Pinned Locked Moved pfBlockerNG
    11 Posts 2 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      SteveITS Galactic Empire @mikej47
      last edited by

      @mikej47 said in Pfblocker not working after upgrading to Pfsense 21.05.1-RELEASE (arm):

      Possibly increasing the size of the Pfsense state table

      Probably not the state table, but "Firewall Maximum Table Entries." (System/Advanced/Firewall & NAT) However pfSense should log an error when it tries to load things and runs out of space.

      Do you need aliases for all those? It's less resource heavy to allow certain countries rather than block the world. (said without knowing what's in the aliases)

      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
      Upvote 👍 helpful posts!

      M 1 Reply Last reply Reply Quote 0
      • M
        mikej47 @SteveITS
        last edited by

        @steveits I uninstalled whatever version of Pfblocker I had and installed pfBlockerNG-devel 3.0.0_16 and that seems to have resolved the issue.

        I would like to get rid of the aliases and block on a per country basis to improve resource utilization.

        With the new version I don't see where I can select the countries. I will have to poke around some more.

        S 1 Reply Last reply Reply Quote 0
        • S
          SteveITS Galactic Empire @mikej47
          last edited by

          @mikej47 said in Pfblocker not working after upgrading to Pfsense 21.05.1-RELEASE (arm):

          With the new version I don't see where I can select the countries

          IP/GeoIP, then click the pencil icon for each continent.

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote 👍 helpful posts!

          M 1 Reply Last reply Reply Quote 0
          • M
            mikej47 @SteveITS
            last edited by

            @steveits For some reason I am missing that pencil icon for each continent. I do have a MaxMind license key that I registered for.

            S 1 Reply Last reply Reply Quote 0
            • S
              SteveITS Galactic Empire @mikej47
              last edited by SteveITS

              @mikej47 said in Pfblocker not working after upgrading to Pfsense 21.05.1-RELEASE (arm):

              missing that pencil icon

              On the far right? like:
              173a225c-d9fc-4e58-bc2b-bf12022a4ccf-image.png

              Edit: I saw pfB 3.1.0 is out today, or will be shortly.

              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
              Upvote 👍 helpful posts!

              M 2 Replies Last reply Reply Quote 0
              • M
                mikej47 @SteveITS
                last edited by

                @steveits Yes, the blue pencils don't exist.

                b6decf3c-4e00-4dfd-b676-70f9c71972c2-image.png

                I tried Chrome and Edge thinking it may have been my browser but the issue persists in both.

                1 Reply Last reply Reply Quote 0
                • M
                  mikej47 @SteveITS
                  last edited by

                  @steveits I noticed when I do a manual update I get the below 401 Unauthorized for the GeoLite2-Country-CSV.zip. I verified I am using my correct license key for Max Mind. Other stuff does seem to update.

                  UPDATE PROCESS START [ v3.1.0 ] [ 09/10/21 16:01:50 ]

                  ===[ DNSBL Process ]================================================

                  ===[ GeoIP Process ]============================================

                  MaxMind Database downloading and processing ( approx 4MB ) ... Please wait ...

                  Download Process Starting [ 09/10/21 16:01:52 ]
                  /usr/local/share/GeoIP/GeoLite2-Country.tar.gz 401 Unauthorized

                  Failed to Download GeoLite2-Country.mmdb
                  /usr/local/share/GeoIP/GeoLite2-Country-CSV.zip 401 Unauthorized

                  Failed to Download
                  Download Process Ended [ 09/10/21 16:02:12 ]

                  Could not open ISO [ SH_rep_v4 ]

                  Could not open ISO [ EH_rep_v4 ]

                  [ pfB_Africa_v4 ] exists. [ 09/10/21 16:02:13 ]
                  Could not open ISO [ CC_rep_v4 ]

                  [ pfB_Asia_v4 ] exists.
                  [ pfB_Europe_v4 ] exists. [ 09/10/21 16:02:14 ]

                  S 1 Reply Last reply Reply Quote 0
                  • S
                    SteveITS Galactic Empire @mikej47
                    last edited by

                    @mikej47 said in Pfblocker not working after upgrading to Pfsense 21.05.1-RELEASE (arm):

                    401 Unauthorized for the GeoLite2-Country-CSV.zip

                    Was your Maxmind key created as a 3.1.1 version? See this thread. Looks like that poster wasn't using the -devel version either which is the only way I got Maxmind to work.

                    Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                    When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                    Upvote 👍 helpful posts!

                    M 1 Reply Last reply Reply Quote 0
                    • M
                      mikej47 @SteveITS
                      last edited by

                      @steveits That did the trick. I created a new license key from Max Mind, the updates are now fully successful, and the pencil icons are there!

                      Should I delete my old pfB_Africa_v4, pfB_xxx, aliases now?

                      S 1 Reply Last reply Reply Quote 0
                      • S
                        SteveITS Galactic Empire @mikej47
                        last edited by

                        @mikej47 said in Pfblocker not working after upgrading to Pfsense 21.05.1-RELEASE (arm):

                        Should I delete my old pfB_Africa_v4, pfB_xxx, aliases now

                        If you're not using them I would, otherwise (I assume) they would use memory.

                        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                        Upvote 👍 helpful posts!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.