Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlockerNG-devel doesn't block anything

    Scheduled Pinned Locked Moved pfBlockerNG
    11 Posts 3 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      georgrade
      last edited by

      Now I just got an error message about a Download Fail. Has it something to do with it?

      pf6.png

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @georgrade
        last edited by

        @georgrade

        458b2411-f38b-462e-adc0-bccb820ffeac-image.png

        If the Resolver doesn't see any requests, it can't act upon them.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        NogBadTheBadN 1 Reply Last reply Reply Quote 0
        • NogBadTheBadN
          NogBadTheBad @Gertjan
          last edited by

          https://learn.akamai.com/en-us/webhelp/enterprise-threat-protector/etp-client-configuration-guide/GUID-04D2A852-CB51-4210-9CE3-7F6ABB3B84E2.html

          Andy

          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

          1 Reply Last reply Reply Quote 0
          • G
            georgrade
            last edited by georgrade

            Thank you very much for your help. After I disabled DNS over HTTPS in the browser, ads disapeared as they should. Also there are some stats that tell me blocking is going on.

            Nevertheless some issues/error messages remain (on my virtualbox-installation and on my thinkcentre-installation of pfSense in the same way):

            pf7.png

            pf8.png

            (1) After every update of pfBlockerNG, I get messages of the type
            1.[pfB_PRI1_v4 - Abuse_ IPBL_v4]Download FAIL [12/14/21 18:22:58]

            (2) No "Unbound Resolver Queries since last clearing" are registered. (On the thinkcentre I have additionaly configured DNS Redirect over pfSense (that is over Unbound, if I understand it right), but the same situation there).

            (3) Under "Installed Packages" I get
            Package is configured but not (fully) installed or deprecated.

            GertjanG 1 Reply Last reply Reply Quote 0
            • GertjanG
              Gertjan @georgrade
              last edited by

              @georgrade

              1. That feed has a problem. I see the same message :

              dd328952-79f1-4ff5-a022-fe8d75e780d8-image.png

              1. Dono what to say. Goto Services > DNS Resolver > Advanced Settings page and crank up the Log level to "level 3" and check out the Resolver log.

              2. That red message is an example : if a package name (left colum) is shown in red, then you know what this means.
                Same for yellow etc.

              568b3043-7335-4bb1-85e2-e5c55498079d-image.png

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              1 Reply Last reply Reply Quote 0
              • G
                georgrade
                last edited by georgrade

                To point 2: How long do I have to wait until the next clearing? Can I force a clearing? At the moment I'm running pfsense not 24/7, but always only for a few hours to try it out. Maybe that was never long enough to go through one clearing cycle? When I hover over the clock symbol with the round arrow it says "(...) Last clear: Unknown".

                GertjanG 1 Reply Last reply Reply Quote 0
                • GertjanG
                  Gertjan @georgrade
                  last edited by Gertjan

                  @georgrade said in pfBlockerNG-devel doesn't block anything:

                  How long do I have to wait until the next clearing?

                  Clearing : Click on the wrench to see what is ment by that :

                  f4a481c1-c405-438e-bfe8-e2995dcda9e1-image.png

                  You can choose for yourself when counters are reset. By default it's once a week.

                  edit : what is your DNSBL setting ? Python mode ?

                  c3ab1a70-635b-45c8-99d5-9e862fbb3c73-image.png

                  No "help me" PM's please. Use the forum, the community will thank you.
                  Edit : and where are the logs ??

                  1 Reply Last reply Reply Quote 0
                  • G
                    georgrade
                    last edited by georgrade

                    Problem (2) seems to be solved either, but only under proxmox.

                    pf10.png

                    I set up pfsense under proxmox with only very basic configuration, then installed pfBlockerNG-devel and within a day Unbound Resolver Queries-registrations came up as you see on the picture. [And this worked even with the clearing frequency default setting on "Never".]

                    Next step is that I will try to replicate this under virtualbox and on bare metal.

                    Thanks again for your kind help.

                    My DNSBL Mode is "Unbound". When I tried "Unbound python mode" (under the proxmox setup) DNSBL got shut down automaticaly. Should I normaly use python mode?

                    GertjanG 1 Reply Last reply Reply Quote 0
                    • GertjanG
                      Gertjan @georgrade
                      last edited by

                      @georgrade said in pfBlockerNG-devel doesn't block anything:

                      DNSBL got shut down automaticaly. Should I normaly use python mode?

                      unbound mode : is the old way of doing so.
                      Python method : the new way. Advantages are : better log facilities, faster to restart unbound, better control over what en when gets blocked.

                      What do you mean : "DNSBL got shut down automaticaly" ?
                      "Python" IS DNSBL.
                      Out of the box, Python mode works well.

                      No "help me" PM's please. Use the forum, the community will thank you.
                      Edit : and where are the logs ??

                      1 Reply Last reply Reply Quote 0
                      • G
                        georgrade
                        last edited by georgrade

                        By shut down automaticaly I meant, that it looked like this:

                        Bildschirmfoto_2021-12-26_18-15-06.png

                        But as I noticed now, that was, because I forgot to do a Reload after changing to Python Mode.

                        I now was able to get pfBlockerNG-devel runing as it should in the virtualbox, so everything is good so far.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.