Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Various sites and services being blocked - how to fix?

    Scheduled Pinned Locked Moved Firewalling
    130 Posts 5 Posters 24.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      Elmojo @A Former User
      last edited by

      @silence
      I could I guess.
      Please tell me what you'd like to see specifically, so I can do it all at once to save time.
      You mentioned the dashboard, but also the firewall logs?
      Those are on different screens, right?

      ? 1 Reply Last reply Reply Quote 0
      • ?
        A Former User @Elmojo
        last edited by

        @elmojo, Status > System logs > Firewall

        and System information in dasboard

        E 1 Reply Last reply Reply Quote 0
        • E
          Elmojo @A Former User
          last edited by

          @silence Album Link: https://ibb.co/album/rGsxLQ
          I'll add to this if needed as we discuss...
          Thanks!

          ? 3 Replies Last reply Reply Quote 0
          • ?
            A Former User @Elmojo
            last edited by

            @elmojo, System > General Setup > DNS SERVER SETTINS > DNS SERVER = 8.8.8.8

            a28845db-1131-4dc6-b603-5bcc22491afd-image.png

            1 Reply Last reply Reply Quote 0
            • ?
              A Former User @Elmojo
              last edited by

              @elmojo, Firewall> Rules> Wan and send screenshot

              And Firewall> Rules> Lan and send screenshot

              1 Reply Last reply Reply Quote 0
              • ?
                A Former User @Elmojo
                last edited by

                @elmojo, Status> System logs> Firewall and then share new logs

                2a3e4598-a5fb-49ef-955c-09622b242661-image.png

                E 1 Reply Last reply Reply Quote 0
                • E
                  Elmojo @A Former User
                  last edited by Elmojo

                  @silence
                  I'm sorry, I don't understand what you're saying.
                  If you're telling me to set my DNS to Google's 8.8.8.8, then no.
                  I just got that fixed earlier in this thread with @Gertjan's help. Having a DNS specified in my settings we preventing most anything from working.
                  Removing the DNS entry entirely and using the default setting has got it working to this point.

                  As for the other screenshots, I'll add them to the album shortly.

                  EDIT: Album updated.

                  ? 2 Replies Last reply Reply Quote 0
                  • ?
                    A Former User @Elmojo
                    last edited by A Former User

                    @elmojo, I have multiple pfsense and everything has this configuration, I never have any problem.

                    127.0.0.1 is wrong

                    E 1 Reply Last reply Reply Quote 0
                    • ?
                      A Former User @Elmojo
                      last edited by

                      @elmojo, I am a bit confused because it has wan interfaces?

                      I try to understand what use you want to give your pfsense to help with a configuration.

                      1 Reply Last reply Reply Quote 0
                      • E
                        Elmojo @A Former User
                        last edited by Elmojo

                        @silence said in Various sites and services being blocked - how to fix?:

                        @elmojo, I have multiple pfsense and everything has this configuration, I never have any problem.

                        127.0.0.1 is wrong

                        I dunno man, I'm just going by what I was told by @Gertjan. Maybe you know more than he (she?) does, maybe it's the other way around. I guarantee you both know more than me! lol
                        All I know is that I had it set to 8.8.8.8 when I first set it up, and nothing worked right. Removing that entry and letting it default caused a few things to work a bit better, but not everything.
                        I don't see anything in my rules about port 53. What do you mean? It set those up during the wizard, I have not set any rules myself.

                        @silence said in Various sites and services being blocked - how to fix?:

                        @elmojo, I am a bit confused because it has wan interfaces?

                        I try to understand what use you want to give your pfsense to help with a configuration.

                        What's confusing about the WAN interfaces? Do you mean the rules, or the blocking entries, or ???

                        ? 1 Reply Last reply Reply Quote 0
                        • ?
                          A Former User @Elmojo
                          last edited by A Former User

                          @elmojo, Status > System Logs > System > DNS Resolver
                          and send screenshot

                          Diagnostics > DNS Lookup >
                          d65eeff9-383a-410c-b5f9-072e1144bc72-image.png

                          E 1 Reply Last reply Reply Quote 0
                          • E
                            Elmojo @A Former User
                            last edited by

                            @silence album updated
                            I really appreciate your help, by the way.
                            I realize something is super sketchy here. Do you think this is fixable, or should I just burn this thing back to factory defaults and start over? I don't have much configured, so if you think it would help, I can (hopefully) get it set back up again. :)

                            I'm most worried about getting the WAN configured to play nice with my DSL, but I think we got that sorted out now.

                            ? 1 Reply Last reply Reply Quote 0
                            • ?
                              A Former User @Elmojo
                              last edited by

                              @elmojo, Firewall> Rules> Wan> Add

                              Create this rule in your wan interfaces to block all

                              Then go to Interfaces> wan and uncheck this option

                              4c7c2d4f-d4a6-49b7-96b5-babd0ac1a5ff-image.png

                              27cbf161-8fec-468f-950c-e7be6e7d6232-image.png

                              E 1 Reply Last reply Reply Quote 0
                              • E
                                Elmojo @A Former User
                                last edited by

                                @silence
                                I'm willing to try, but can you explain the idea first please? All documentation and videos I've watched say to not disable that "bogon blocking" feature.

                                ? 1 Reply Last reply Reply Quote 0
                                • ?
                                  A Former User @Elmojo
                                  last edited by

                                  @elmojo I am not very theoretical, it is simply the logical thing that I do when I configure new pfsense to disable default rules and I add this rule to block and monitor all traffic in the wan.

                                  E 1 Reply Last reply Reply Quote 0
                                  • E
                                    Elmojo @A Former User
                                    last edited by Elmojo

                                    @silence That makes sense. Please excuse my (extreme) ignorance, but if we block all WAN traffic, won't that block pretty much all incoming data? Or is it only for requests that originate outside my LAN, thus making them likely to be malicious?

                                    EDIT: I did as you show above. The logs look like this now... https://ibb.co/xL9k0cf

                                    ? 2 Replies Last reply Reply Quote 0
                                    • ?
                                      A Former User @Elmojo
                                      last edited by

                                      @elmojo, Apply this setting just as the image shows.

                                      a28845db-1131-4dc6-b603-5bcc22491afd-image.png

                                      1 Reply Last reply Reply Quote 0
                                      • ?
                                        A Former User @Elmojo
                                        last edited by

                                        @elmojo, Switches from (Lan Net) To (*) In both rules

                                        9fdd379c-85a7-4239-9515-b934f7a27e1c-image.png

                                        E 1 Reply Last reply Reply Quote 0
                                        • E
                                          Elmojo @A Former User
                                          last edited by Elmojo

                                          @silence
                                          Okay, both done, no improvement.
                                          I have now lost access to the Amazon app again on my phone, likely due to the DNS change.
                                          I still cannot access the FireTV home screen, or Netflix. I can, oddly, access Amazon Prime Video on my TV. I'm not sure if that was working before or not, I never tried.

                                          ? 2 Replies Last reply Reply Quote 0
                                          • ?
                                            A Former User @Elmojo
                                            last edited by

                                            @elmojo, try to enter again and then go to firewall logs and send me a screenshot ...

                                            It must be quick. I want to see what blocks this.

                                            E 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.