Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    With 3.1.0 same issue as with 3.0.0: pfBlockerNG DNSBL service can not start

    Scheduled Pinned Locked Moved pfBlockerNG
    1 Posts 1 Posters 380 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • PfostenP
      Pfosten
      last edited by Pfosten

      • pfBlockerNG 3.0.0 never worked as the old version 2.x
      • removed the old package 3.0.0 - rebooted.
      • upgraded pfsense from 2.6.0.a to 2.6.0.b
      • installed pfBlockerNG 3.1.0 - same bug symptoms as before: DNSBL does not start.

      Some extracts from error log:

      #######################################################################
      /var/log/pfblockerng/pfblockerng.log:

      Database Sanity check [ PASSED ]

      Masterfile/Deny folder uniq check
      Deny folder/Masterfile uniq check

      Sync check (Pass=No IPs reported)

      Alias table IP Counts

      17713 /var/db/aliastables/pfB_PRI1_v4.txt

      pfSense Table Stats

      table-entries hard limit 400000
      Table Usage Count 19150

      UPDATE PROCESS ENDED [ 12/30/21 14:02:13 ]

      Saving configuration [ 12/30/21 14:11:44 ]

      Saving configuration [ 12/30/21 14:13:45 ]

      ** Starting firewall filter daemon **

      Saving configuration [ 12/30/21 14:16:21 ]

      Saving new DNSBL web server configuration to port [ 7777 and 7778 ]
      Unbound stopped in 1 sec.
      Additional mounts:
      No changes required.
      Starting Unbound Resolver.
      DNSBL disabled - Unbound conf update FAIL *** Fix error(s) and a Force Reload required! ***

      ====================

      [1640870181] unbound[98453:0] error: bind: address already in use
      [1640870181] unbound[98453:0] fatal error: could not open ports

      ====================

      Unbound stopped in 1 sec.
      Additional mounts:
      Starting Unbound Resolver Not completed.
      [1640870181] unbound[99432:0] error: bind: address already in use
      [1640870181] unbound[99432:0] fatal error: could not open ports

      *** DNSBL update [ 0 ] [ 100502 ] ... OUT OF SYNC ! ***

      ** Starting firewall filter daemon **

      Saving configuration [ 12/30/21 14:21:39 ]

      ** Starting firewall filter daemon **

      Saving configuration [ 12/30/21 14:21:41 ]

      ** Starting firewall filter daemon **
      CRON PROCESS START [ v3.1.0 ] [ 12/30/21 15:00:00 ]
      [ Abuse_Feodo_C2_v4 ]
      Remote timestamp: Thu, 30 Dec 2021 13:55:03 GMT
      Local timestamp: Thu, 30 Dec 2021 12:55:03 GMT Update found
      [ Abuse_IPBL_v4 ]
      Previous download failed. Re-attempt download
      [ Abuse_SSLBL_v4 ]
      Remote timestamp: Thu, 30 Dec 2021 13:55:02 GMT
      Local timestamp: Thu, 30 Dec 2021 12:55:02 GMT Update found
      [ CINS_army_v4 ] [ 12/30/21 15:00:01 ]
      Remote timestamp: Thu, 30 Dec 2021 13:17:55 GMT
      Local timestamp: Thu, 30 Dec 2021 12:17:48 GMT Update found
      [ ET_Block_v4 ]
      Remote timestamp: Wed, 29 Dec 2021 05:30:02 GMT
      Local timestamp: Wed, 29 Dec 2021 05:30:02 GMT Update not required
      [ ET_Comp_v4 ] [ 12/30/21 15:00:05 ]
      Remote timestamp: Wed, 29 Dec 2021 22:46:22 GMT
      Local timestamp: Wed, 29 Dec 2021 22:46:22 GMT Update not required
      [ ISC_Block_v4 ] [ 12/30/21 15:00:06 ]
      Remote timestamp: Thu, 30 Dec 2021 13:55:13 GMT
      Local timestamp: Thu, 30 Dec 2021 11:55:12 GMT Update found
      [ Spamhaus_Drop_v4 ] [ 12/30/21 15:00:07 ]
      Remote timestamp: Wed, 29 Dec 2021 17:33:42 GMT
      Local timestamp: Wed, 29 Dec 2021 17:33:42 GMT Update not required
      [ Spamhaus_eDrop_v4 ]
      Remote timestamp: Sun, 19 Dec 2021 06:22:47 GMT
      Local timestamp: Sun, 19 Dec 2021 06:22:47 GMT Update not required
      [ Talos_BL_v4 ]
      ( md5 feed ) . 503 Service Unavailable
      Failed to download Feed for md5 comparison! Update skipped
      UPDATE PROCESS START [ v3.1.0 ] [ 12/30/21 15:00:08 ]

      ===[ DNSBL Process ]================================================

      Loading DNSBL Statistics... completed
      Missing DNSBL stats and/or Unbound DNSBL files - Rebuilding

      Loading DNSBL SafeSearch... disabled
      Loading DNSBL Whitelist... completed

      [ StevenBlack_ADs ] Reload . completed ..
      Whitelist: 5726.bapi.adsafeprotected.com|6063.bapi.adsafeprotected.com|aan.amazon-adsystem.com|aax-cpm.amazon-adsystem.com|aax-eu-retail-direct.amazon-adsystem.com|aax-eu.amazon-adsystem.com|aax-fe-sin.amazon-adsystem.com|aax-fe.amazon-adsystem.com|aax-us-east-rtb.amazon-adsystem.com|aax-us-east.amazon-adsystem.com|aax-us-pdx.amazon-adsystem.com|aax-us.amazon-adsystem.com|aax.amazon-adsystem.com|adsafeprotected.com|amazon-adsystem.com|anycast.dt.adsafeprotected.com|appvast.adsafeprotected.com|banners.itunes.apple.com|bs.eyeblaster.akadns.net|bs.serving-sys.com|bsla.eyeblaster.akadns.net|c.amazon-adsystem.com|ca.iadsdk.apple.com|cdn-a.amazon-adsystem.com|cdn.adsafeprotected.com|cf.iadsdk.apple.com|control.kochava.com|device-metrics-us-2.amazon.com|dra.amazon-adsystem.com|dt.adsafeprotected.com|dtvc.adsafeprotected.com|fls-eu.amazon-adsystem.com|fls-fe.amazon-adsystem.com|fls-na.amazon-adsystem.com|fw.adsafeprotected.com|fwvc.adsafeprotected.com|iadsdk.apple.com|images-aud.sourceforge.net|imp.control.kochava.com|ir-de.amazon-adsystem.com|ir-jp.amazon-adsystem.com|ir-na.amazon-adsystem.com|ir-uk.amazon-adsystem.com|localhost.localdomain|mads.amazon-adsystem.com|metrics.apple.com|mobile-static.adsafeprotected.com|mobile.adsafeprotected.com|news.iadsdk.apple.com|notes-analytics-events.apple.com|nyidt.adsafeprotected.com|orfw.adsafeprotected.com|orpixel.adsafeprotected.com|pixel.adsafeprotected.com|pm.adsafeprotected.com|ps-eu.amazon-adsystem.com|ps-jp.amazon-adsystem.com|ps-us.amazon-adsystem.com|px.moatads.com|rcm-eu.amazon-adsystem.com|rcm-fe.amazon-adsystem.com|rcm-na.amazon-adsystem.com|s.amazon-adsystem.com|secure-gl.imrworldwide.com|securemetrics.apple.com|sgfw.adsafeprotected.com|sgpixel.adsafeprotected.com|spixel.adsafeprotected.com|static.adsafeprotected.com|stocks-analytics-events.apple.com|tr.iadsdk.apple.com|unified.adsafeprotected.com|ut.iadsdk.apple.com|vaes.amazon-adsystem.com|vafw.adsafeprotected.com|vapixel.adsafeprotected.com|vast.adsafeprotected.com|video.adsafeprotected.com|weather-analytics-events.apple.com|web-sdk.control.kochava.com|wildcard.moatads.com.edgekey.net|wms-eu.amazon-adsystem.com|wms-na.amazon-adsystem.com|wrapper-vast.adsafeprotected.com|ws-ea.amazon-adsystem.com|ws-eu.amazon-adsystem.com|ws-fe.amazon-adsystem.com|ws-na.amazon-adsystem.com|z-eu.amazon-adsystem.com|z-na.amazon-adsystem.com|

      Orig. Unique # Dups # White # TOP1M Final

      100592 100592 0 90 0 100502

      Saving DNSBL statistics... completed [ 12/30/21 15:00:09 ]

      Assembling DNSBL database...... completed [ 12/30/21 15:00:10 ]
      Unbound stopped in 1 sec.
      Additional mounts:
      No changes required.
      Starting Unbound Resolver.
      DNSBL - Unbound conf update FAIL *** Fix error(s) and a Force Reload required! ***

      ====================

      [1640872810] unbound[87321:0] error: bind: address already in use
      [1640872810] unbound[87321:0] fatal error: could not open ports

      ====================

      Unbound stopped in 1 sec.
      Additional mounts:
      Starting Unbound Resolver Not completed.
      [1640872810] unbound[88812:0] error: bind: address already in use
      [1640872810] unbound[88812:0] fatal error: could not open ports

      DNSBL update [ 100502 | PASSED ]... completed

      ===[ IPv4 Process ]=================================================

      [ Abuse_Feodo_C2_v4 ] Downloading update [ 12/30/21 19:00:30 ] .. 200 OK. completed ..

      Original Master Final

      320 243 243 [ Pass ]

      [ Abuse_IPBL_v4 ] Downloading update .. 503 Service Unavailable

      [ pfB_PRI1_v4 - Abuse_IPBL_v4 ] Download FAIL [ 12/30/21 19:03:11 ]
      Firewall and/or IDS (Legacy mode only) are not blocking download.

      Restoring previously downloaded file contents... completed ..
      Empty file, Adding '127.1.7.7' to avoid download failure.

      Original Master Final

      0 1 1 [ Pass ]

      [ Abuse_SSLBL_v4 ] Downloading update .. 200 OK. completed ..

      Original Master Final

      65 58 58 [ Pass ]

      ############################################################################

      /var/log/pfblockerng/error.log:

      DNSBL - Unbound conf update FAIL *** Fix error(s) and a Force Reload required! ***

      ====================

      [1640872810] unbound[87321:0] error: bind: address already in use
      [1640872810] unbound[87321:0] fatal error: could not open ports

      ====================

      [ pfB_PRI1_v4 - Abuse_IPBL_v4 ] Download FAIL [ 12/30/21 15:02:01 ]
      Firewall and/or IDS (Legacy mode only) are not blocking download.

      Restoring previously downloaded file contents...

      [ pfB_PRI1_v4 - Abuse_IPBL_v4 ] Download FAIL [ 12/30/21 16:02:11 ]
      Firewall and/or IDS (Legacy mode only) are not blocking download.

      Restoring previously downloaded file contents...

      [ pfB_PRI1_v4 - Abuse_IPBL_v4 ] Download FAIL [ 12/30/21 17:02:22 ]
      Firewall and/or IDS (Legacy mode only) are not blocking download.

      Restoring previously downloaded file contents...

      [ pfB_PRI1_v4 - Abuse_IPBL_v4 ] Download FAIL [ 12/30/21 18:02:10 ]
      Firewall and/or IDS (Legacy mode only) are not blocking download.

      Restoring previously downloaded file contents...

      [ pfB_PRI1_v4 - Abuse_IPBL_v4 ] Download FAIL [ 12/30/21 19:03:11 ]
      Firewall and/or IDS (Legacy mode only) are not blocking download.

      Restoring previously downloaded file contents...

      ##############################################################################

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.