Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNSBL native support?

    Scheduled Pinned Locked Moved General pfSense Questions
    9 Posts 3 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • CreationGuyC
      CreationGuy
      last edited by

      I've been playing with OPNsense and found that it's unbound has built in dnsbl where I can add lists to it. I've done that and it is not taking up the amount of RAM that it does on pfsense and pfblockerNG using default settings (Stephen blocklist) and only added this one list: https://unbound.oisd.nl/nsfw/.

      Does pfsense have plants to support a native dnsbl like opnsense?

      GertjanG Bob.DigB 2 Replies Last reply Reply Quote 0
      • GertjanG
        Gertjan @CreationGuy
        last edited by

        @creationguy said in DNSBL native support?:

        Does pfsense have plants to support a native dnsbl

        For DNSBL you don't need pfblocker.

        Download your oisd_unbound_nsfw.txt file into (example) the /root/ folder.

        Then, do what we all did before : inform unbound to use the list :

        051b8771-1b8a-4853-94ed-d35ce0a8b99f-image.png

        Remember : pfblockerng is nothing more then a tool that download (updates) lists.
        It also handles the doubles between lists, makes stats, etc etc etc
        But it does not do the actual DNSBL job : that's still unbound.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        CreationGuyC 1 Reply Last reply Reply Quote 1
        • Bob.DigB
          Bob.Dig LAYER 8 @CreationGuy
          last edited by

          @creationguy said in DNSBL native support?:

          Does pfsense have plants to support a native dnsbl like opnsense?

          It took them quite a while for that GUI support... but they step up their game lately it seems.

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan @Bob.Dig
            last edited by Gertjan

            @bob-dig said in DNSBL native support?:

            It took them quite a while for that GUI support.

            I would call pfBlockerNG-devel DNSBL GUI support ;)

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            Bob.DigB 1 Reply Last reply Reply Quote 1
            • Bob.DigB
              Bob.Dig LAYER 8 @Gertjan
              last edited by

              @gertjan I meant the other guys.

              And you have to make some kind of Suppression for your local IPs though when using IP-Block lists (not DNSBL) there, so pfBlockerNG on pfSense is still superior.

              1 Reply Last reply Reply Quote 1
              • CreationGuyC
                CreationGuy
                last edited by

                Thank you, I'll give it a try. I do prefer pfsense over opnsense although it has its strong points as well.

                I want to buy an appliance rather than build a new, mini computer for it to support the devs but also to reduce my power consumption. I just wish that the 4100 had more RAM, pfblockerng is such a hog.

                1 Reply Last reply Reply Quote 0
                • CreationGuyC
                  CreationGuy @Gertjan
                  last edited by

                  @gertjan said in DNSBL native support?:

                  @creationguy said in DNSBL native support?:

                  Does pfsense have plants to support a native dnsbl

                  For DNSBL you don't need pfblocker.

                  Download your oisd_unbound_nsfw.txt file into (example) the /root/ folder.

                  Then, do what we all did before : inform unbound to use the list :

                  051b8771-1b8a-4853-94ed-d35ce0a8b99f-image.png

                  Remember : pfblockerng is nothing more then a tool that download (updates) lists.
                  It also handles the doubles between lists, makes stats, etc etc etc
                  But it does not do the actual DNSBL job : that's still unbound.

                  If I wanted a white list, what is the process and would I be able to use regex?

                  GertjanG 1 Reply Last reply Reply Quote 0
                  • GertjanG
                    Gertjan @CreationGuy
                    last edited by

                    @creationguy said in DNSBL native support?:

                    If I wanted a white list, what is the process

                    Download your list, or several lists,
                    Merge them,
                    Remove the doubles,
                    And then, one by one, remove all the DNSBL that you wanted to have white listed.

                    Or install pfblokcerng-devel, as it does exactly that for you.

                    regex : you need to intercept every dns request with a script. That is what the python-mode is all about.

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    CreationGuyC 1 Reply Last reply Reply Quote 0
                    • CreationGuyC
                      CreationGuy @Gertjan
                      last edited by

                      @gertjan Thanks for your preferential answer on trying to gear me in another direction. I simply wanted to know how to do this in a technical manor. I'll research else where.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.