Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlockerNG DNSBL Categories not working

    Scheduled Pinned Locked Moved pfBlockerNG
    19 Posts 4 Posters 4.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • GertjanG
      Gertjan
      last edited by Gertjan

      @RonpfS 👍 For DNSBL to be enabled, it should be enabled. Sounds stupid, but very true.

      Btw : I selected this 'porn' thing, and saw this at the top of the page, after validating :

      4581c896-3008-4983-9403-bcf7e6a2b9ce-image.png

      what this means is that the list is typically huge.
      "tld" condition apply : like this one eats Gigabytes of memory. If memory starts to fail, the rest of the list will get ignored.

      edit : the porn list contains 730 000 entries - it's huge.

      [ Shallalist_porn ]		 Downloading update [ 06/03/20 07:29:29 ] .
        IDN converted: [ sendesık.com ]	 [ xn--sendesk-wfb.com ].
        ----------------------------------------------------------------------
        Orig.    Unique     # Dups     # White    # TOP1M    Final                
        ----------------------------------------------------------------------
        727947   727947     449        0          0          727498               
        ----------------------------------------------------------------------
      

      Because my pfSEnse only contains 2 Gbytes of memory,I had this message :

      TLD analysis..xxxxxxx completed [ 06/03/20 07:32:18 ]
      
        ** TLD Domain count exceeded. [ 150000 ] All subsequent Domains listed as-is **
      
      TLD finalize......................
      

      as explained. For this list you'll be needing something like 4 GBytes or even more.

      When everything works, you would be able to :

      1cd85635-dcdc-46e9-ad53-789843bcdad7-image.png

      @jayb1 said in pfBlockerNG DNSBL Categories not working:

      For example "porn" but then obvious porn sites are not blocked.

      Always keep in mind that pfBlockerNG has no brains ^^
      It just download for you a list that should represent sites of a certain kind. IP addresses keep changing all the time. Especially if they contain a lot of arguable content (and a lot of publicity). The people that created the list are doing this manually, as AI can't classify the entire Internet. So, false hits always exist.

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      J 1 Reply Last reply Reply Quote 0
      • J
        jayb1 @RonpfS
        last edited by

        @RonpfS Sorry, did realise there was a pfBlockerNG forum section. Happy for a mod to shift it.

        Yes, I've run multiple forced updates and reloaded DNSBL.

        DBNSL is enabled.

        The logs show no errors. Just the usual from the forced update.

         UPDATE PROCESS START [ 06/03/20 16:17:34 ]
        
        ===[  DNSBL Process  ]================================================
        
         Loading DNSBL Statistics... completed
         Loading DNSBL SafeSearch...  disabled
         Loading DNSBL Whitelist... completed
        
        Clearing all DNSBL Feeds completed
        TLD:
        TLD analysis no changes
        
        Saving DNSBL database... completed
        Reloading Unbound Resolver..... completed [ 06/03/20 16:17:40 ]
        DNSBL update [ 0 | PASSED  ]... completed
        ------------------------------------------------------------------------
        
        ===[  GeoIP Process  ]============================================
        
        
        ===[  IPv4 Process  ]=================================================
        
        [ Abuse_Feodo_C2_v4 ]		 exists.
        [ Abuse_IPBL_v4 ]		 exists.
        [ Abuse_SSLBL_v4 ]		 exists.
        [ BBC_C2_v4 ]			 exists.
        [ CINS_army_v4 ]		 exists.
        [ ET_Block_v4 ]			 exists.
        [ ET_Comp_v4 ]			 exists.
        [ ISC_1000_30_v4 ]		 exists.
        [ ISC_Block_v4 ]		 exists.
        [ Spamhaus_Drop_v4 ]		 exists.
        [ Spamhaus_eDrop_v4 ]		 exists.
        [ Talos_BL_v4 ]			 exists.
        
        ===[  Aliastables / Rules  ]==========================================
        
        No changes to Firewall rules, skipping Filter Reload
        No Changes to Aliases, Skipping pfctl Update
        
         UPDATE PROCESS ENDED
        

        It is blocking from my computer when I check that log, but I assume this is the IPv4 ad blocking?

        Jun 3 16:12:38,1770008388,igb1,LAN,block,4,17,UDP,192.168.128.109,212.178.154.174,51149,18183,out,NL,pfB_PRI1_v4,212.178.154.174,CINS_army_v4,D4B29AAE.static.ziggozakelijk.nl,JASON,null,-
        Jun 3 16:12:38,1770008388,igb1,LAN,block,4,17,UDP,192.168.128.109,212.178.154.174,51149,18183,out,NL,pfB_PRI1_v4,212.178.154.174,CINS_army_v4,D4B29AAE.static.ziggozakelijk.nl,JASON,null,-
        

        I did have other groups enabled and it wasn't working, so I removed them all to simplify it and narrow down the problem (didn't help!).

        Thanks for your time helping, it's much appreciated.

        1 Reply Last reply Reply Quote 0
        • RonpfSR
          RonpfS
          last edited by

          That's IP blocking.

          It looks like it doesn't enable DNSBL, do you use the DNS Resolver ?

          2.4.5-RELEASE-p1 (amd64)
          Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
          Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

          J 1 Reply Last reply Reply Quote 0
          • J
            jayb1 @Gertjan
            last edited by

            @Gertjan thanks for you response.

            I have 4GB of memory and it doesn't seem to be stressing that out with only a few computers on the network.

            It's not showing a Shallalist log...

            Capture.PNG

            Perhaps I just delete pfBlockerNG and start again?

            1 Reply Last reply Reply Quote 0
            • J
              jayb1 @RonpfS
              last edited by

              @RonpfS said in pfBlockerNG DNSBL Categories not working:

              DNS Resolver

              Yes, the DNS resolver is on.

              1 Reply Last reply Reply Quote 0
              • GertjanG
                Gertjan
                last edited by

                Extra info : I activated that 'porn' list.
                unbound (the Resolver) never ended reloading- restarting.
                No more DNS :> no more surf. I had to remove it ....

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                1 Reply Last reply Reply Quote 0
                • RonpfSR
                  RonpfS
                  last edited by

                  Try to un-tick Keep Settings, disable pfblockerNG, save Settings this will clear the DB.
                  Uninstall, Install again, reconfigure, etc, remember to click on all

                  2.4.5-RELEASE-p1 (amd64)
                  Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                  Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                  J 1 Reply Last reply Reply Quote 2
                  • J
                    jayb1 @RonpfS
                    last edited by

                    @RonpfS said in pfBlockerNG DNSBL Categories not working:

                    Try to un-tick Keep Settings, disable pfblockerNG, save Settings this will clear the DB.
                    Uninstall, Install again, reconfigure, etc, remember to click on all

                    This worked. I have no idea what was wrong with the first config.

                    RonpfSR 1 Reply Last reply Reply Quote 0
                    • RonpfSR
                      RonpfS @jayb1
                      last edited by

                      @jayb1 👍

                      2.4.5-RELEASE-p1 (amd64)
                      Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                      Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                      1 Reply Last reply Reply Quote 0
                      • G
                        gurpreets
                        last edited by

                        dnsbl.png

                        category filtering not working when I enter custom domain it works, could you please help me do block things category wise

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S stephenw10 moved this topic from General pfSense Questions on
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.