Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    TLD processing with pfBlockerNG-devel v3.1.0_4

    Scheduled Pinned Locked Moved pfBlockerNG
    4 Posts 3 Posters 805 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      Leonardo 2
      last edited by

      Dear Community,

      I included UT1 feed to block adult sites and enabled Wildcard Blocking (TLD) option with Unbound python mode.

      I tried some tests to understand how pfBlockerNG manage domains and sub-domains.

      In the UT1 adult's list there is domains like you..orn.com or animalyou..orn.com and gratisyou..orn.com and I expected all of these are managed il the same manner.

      Instead only animalyou..orn.com is inserted in pfb_py_zone.txt, others in pfb_py_zone.txt.

      As a result if I search for www.you..orn.com I not obtain the virtal-IP but the public IP and I can view the site.

      There is a reason for this?

      Thank you

      GertjanG 1 Reply Last reply Reply Quote 0
      • M
        mare
        last edited by

        I have exact same problem

        youp...n.com
        po...hub.com

        are blocked.

        www.youp...n.com
        www.po...hub.com

        are accessible.
        TLD enabled.

        This is a big problem.

        How do I fix this? Non-devel version worked without problem.

        1 Reply Last reply Reply Quote 0
        • M
          mare
          last edited by

          Any suggestions or support? No other people with the same problem?

          1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan @Leonardo 2
            last edited by

            @leonardo-2 said in TLD processing with pfBlockerNG-devel v3.1.0_4:

            In the UT1 adult's list there is

            This list :

            04208776-cd2c-4281-ac47-c775491ab58f-image.png

            ?

            Read :

            This is an Advanced process to determine if all Sub-Domains should be wildcard blocked for each listed Domain.
            Click infoblock before enabling this feature! 
            Definition: TLD -  represents the last segment of a domain name. IE: example.com (TLD = com), example.uk.com (TLD = uk.com)

            When enabled and after all downloads for DNSBL Feeds have completed; TLD will process the Domains.
            TLD uses a predetermined list of TLDs, to determine if the listed Domains should be wildcard blocked (Block all sub-Domains).
            The predetermined TLD list can be found in  /usr/local/pkg/pfblockerng/dnsbl_tld

            To exclude a TLD/Domain from the TLD process, add the TLD/Domain to the TLD Exclusion custom list:
            • This only excludes the domain from the TLD process, it doesn't whitelist the domain.
            • Only the specific Sub-Domains/Domains listed in the DNSBL Feeds will be blocked.
            • A Force Reload - DNSBL, is required after manually adding to the TLD Exclusion

            Note:  Whitelisting a "sub-Domain" for a TLD Blocked "Domain" in the Custom Domain Whitelist will not whitelist a TLD Wildcard Blocked domain!
                Either add the domain to the TLD Exclusion, or wildcard Whitelist the whole domain.

            TLD Blacklist, can be used to block whole TLDs.  IE: xyz
            When Enabling/Disabling this option, a Force Reload - DNSBL is required.

            And when you and observe a force reload of pfblockerng-devel, do you see this :

            ee037757-0500-4944-9ce1-34e45bcae8ff-image.png

            Note the x's

            My advise : when the x's show up, stop uisng "Wildcard Blocking (TLD)" or use smaller feed/lists.

            @leonardo-2 said in TLD processing with pfBlockerNG-devel v3.1.0_4:

            is inserted in pfb_py_zone.txt, others in pfb_py_zone.txt

            That's just pfb_py_zone.txt ;)

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.