• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

pfBlockerNG Shallalist and UT1 failed

pfBlockerNG
5
27
4.7k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • N
    nimrod
    last edited by nimrod Jun 10, 2022, 6:00 PM Jun 10, 2022, 6:00 PM

    I have the same issue, and it think i know what the problem is. It seems like pfBlockerNG is trying to download UT1 blacklist from this link:

    ftp://ftp.ut-capitole.fr/pub/reseau/cache/squidguard_contrib/blacklists.tar.gz
    

    And it fails because that link is no longer valid even though its listed here.

    This is the link that pfBlockerNG should use:

    https://dsi.ut-capitole.fr/blacklists/download/blacklists.tar.gz
    

    I think pfBlockerNG needs to be updated to use the new link. @BBcan177 please correct me if im wrong.

    A M R 3 Replies Last reply Jun 13, 2022, 12:14 AM Reply Quote 0
    • A
      aspiringnetworkadmin @nimrod
      last edited by Jun 13, 2022, 12:14 AM

      @nimrod thank for this information Sir

      1 Reply Last reply Reply Quote 0
      • M
        Miguel 1 @nimrod
        last edited by Jun 16, 2022, 2:29 PM

        @nimrod Where do I go to update the link in pfBlockerNG?

        F 1 Reply Last reply Jun 16, 2022, 2:46 PM Reply Quote 0
        • F
          fireodo @Miguel 1
          last edited by Jun 16, 2022, 2:46 PM

          @miguel-1 said in pfBlockerNG Shallalist and UT1 failed:

          Where do I go to update the link in pfBlockerNG?

          Not in the GUI. You have to edit the file:
          /usr/local/pkg/pfblockerng/ut1_global_usage

          @BBcan177 Correct me if I'm wrong ...

          Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
          SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
          pfsense 2.7.2 CE
          Packages: Apcupsd Cron Iftop Iperf LCDproc Nmap pfBlockerNG RRD_Summary Shellcmd Snort Speedtest System_Patches.

          N 1 Reply Last reply Jun 16, 2022, 3:01 PM Reply Quote 0
          • N
            nimrod @fireodo
            last edited by Jun 16, 2022, 3:01 PM

            I think there is no need to update anything, because, since yesterday, UT1 list update is working again. Whatever the problem was, its gone now. This could be some temporary issue on UT1 servers.

            I forced list update 20 minutes ago, and its working just fine.

            F 1 Reply Last reply Jun 16, 2022, 3:03 PM Reply Quote 1
            • F
              fireodo @nimrod
              last edited by Jun 16, 2022, 3:03 PM

              @nimrod said in pfBlockerNG Shallalist and UT1 failed:

              I think there is no need to update anything, because, since yesterday, UT1 list update is working again. Whatever the problem was, its gone now. This could be some temporary issue on UT1 servers.
              I forced list update 20 minutes ago, and its working just fine.

              Then everything is fine and that manual edit of pfblocker file "/usr/local/pkg/pfblockerng/ut1_global_usage" isnt necessary anymore.

              Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
              SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
              pfsense 2.7.2 CE
              Packages: Apcupsd Cron Iftop Iperf LCDproc Nmap pfBlockerNG RRD_Summary Shellcmd Snort Speedtest System_Patches.

              M 1 Reply Last reply Jun 16, 2022, 5:32 PM Reply Quote 0
              • M
                Miguel 1 @fireodo
                last edited by Jun 16, 2022, 5:32 PM

                @fireodo if I update but it does not block the contents.

                F 1 Reply Last reply Jun 16, 2022, 5:43 PM Reply Quote 0
                • F
                  fireodo @Miguel 1
                  last edited by Jun 16, 2022, 5:43 PM

                  @miguel-1 Force Reload All in pfblocker to be shure all changements get active.

                  Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                  SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                  pfsense 2.7.2 CE
                  Packages: Apcupsd Cron Iftop Iperf LCDproc Nmap pfBlockerNG RRD_Summary Shellcmd Snort Speedtest System_Patches.

                  M 1 Reply Last reply Jun 16, 2022, 6:34 PM Reply Quote 0
                  • M
                    Miguel 1 @fireodo
                    last edited by Jun 16, 2022, 6:34 PM

                    @fireodo I already did the forced restart, I also restarted pfsense but it only blocks some pages and not others.

                    F 1 Reply Last reply Jun 16, 2022, 6:54 PM Reply Quote 0
                    • F
                      fireodo @Miguel 1
                      last edited by Jun 16, 2022, 6:54 PM

                      @miguel-1 said in pfBlockerNG Shallalist and UT1 failed:

                      but it only blocks some pages and not others

                      That means its working - why it not block some other pages that you have to investigate yourself - maybe they arent on the blacklists ...

                      Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                      SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                      pfsense 2.7.2 CE
                      Packages: Apcupsd Cron Iftop Iperf LCDproc Nmap pfBlockerNG RRD_Summary Shellcmd Snort Speedtest System_Patches.

                      M 1 Reply Last reply Jun 16, 2022, 7:01 PM Reply Quote 0
                      • M
                        Miguel 1 @fireodo
                        last edited by Jun 16, 2022, 7:01 PM

                        @fireodo How can I include more sites in the list?

                        F 1 Reply Last reply Jun 17, 2022, 7:09 AM Reply Quote 0
                        • F
                          fireodo @Miguel 1
                          last edited by Jun 17, 2022, 7:09 AM

                          @miguel-1 said in pfBlockerNG Shallalist and UT1 failed:

                          How can I include more sites in the list?

                          In pfblocker under UT1 you have a list of categories - choose here the category that fits the best the type of site you want to block - if that site is not included in any category you have to block it individually. I recommend to read the pfblocker documentation.

                          Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                          SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                          pfsense 2.7.2 CE
                          Packages: Apcupsd Cron Iftop Iperf LCDproc Nmap pfBlockerNG RRD_Summary Shellcmd Snort Speedtest System_Patches.

                          1 Reply Last reply Reply Quote 0
                          • R
                            reberhar @nimrod
                            last edited by reberhar Mar 1, 2024, 4:57 AM Feb 29, 2024, 11:35 PM

                            This post is deleted!
                            N 1 Reply Last reply Mar 1, 2024, 1:54 PM Reply Quote 0
                            • R reberhar referenced this topic on Mar 1, 2024, 3:27 AM
                            • N
                              nimrod @reberhar
                              last edited by Mar 1, 2024, 1:54 PM

                              @reberhar said in pfBlockerNG Shallalist and UT1 failed:

                              @nimrod I recently came up against this problem and changed the link as suggested here without result.

                              As the problem moved with a configuration file, I went ahead and changed the indicated link in the config.xml, which was still pointing to the squidguard link.

                              This gave partial success, but I am still having some problems that I am waiting for a reply from BBcan177.

                              However I think that the suggestion in the post of using the https link is wrong in this case. It suggests the https link. For pfblocker the ftp link should be used, but not the one that has squidguard in it, but this one.

                              ftp://ftp.ut-capitole.fr/blacklist/

                              That doesnt work any more. It was long time ago.

                              Use this instead: https://github.com/olbat/ut1-blacklists

                              R 2 Replies Last reply Mar 1, 2024, 3:56 PM Reply Quote 1
                              • R
                                reberhar @nimrod
                                last edited by Mar 1, 2024, 3:56 PM

                                @nimrod Thanks

                                1 Reply Last reply Reply Quote 0
                                • R
                                  reberhar @nimrod
                                  last edited by Mar 4, 2024, 8:00 PM

                                  @nimrod So Nimrod, I am assuming that these lists are not all formatted in the same way, and that part of my problem is the pfblockerng is expecting a certain format for the ut1 list and that the data I am getting from these links is not formatted that way.

                                  I can just download those list to groups and that works.

                                  I don't feel much like writing parsing software to massage the data.

                                  The next thing to do is look at the source code and see what it is expecting.

                                  R 1 Reply Last reply Mar 4, 2024, 11:56 PM Reply Quote 0
                                  • R
                                    reberhar @reberhar
                                    last edited by Mar 4, 2024, 11:56 PM

                                    @reberhar So I had two similar machines acting exactly the sameway. They only shared the config file. I am preparing for HA.

                                    Trying lots of links for the UT1 list and changing many settings, one started to work with the squidguard list. Which means that my config file is corrupted. I am not looking forward to doing a pfblocker clean install, but it seems that that is what it needs.

                                    SIGH

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.