• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Just updated to pfsense 22.05, is it fully compatible with 3.1.0_4?

pfBlockerNG
3
15
1.2k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P
    paul2019
    last edited by Aug 31, 2022, 2:46 PM

    I was on version 22.01 and my VOIP clients worked fine, then after updating to version 22.05 some (not all) clients are having trouble with outbound calls, incoming calls are fine.

    Does pfblocker version 3.1.0_4 have any known issues with versions after 22.01?

    Downgrading pfsense to 22.01 doesn't seem to be an easy task so hoping pfblocker has a more recent beta that could help me out if that's the case.

    M 1 Reply Last reply Aug 31, 2022, 2:54 PM Reply Quote 0
    • M
      mcury @paul2019
      last edited by Aug 31, 2022, 2:54 PM

      @paul2019 There is a problem, but nothing related to VOIP.
      The problem is related to high CPU usage.

      There is a patch for that however you are going to need to apply it manually editing a file.

      You can read more about here:
      https://redmine.pfsense.org/issues/13154
      https://forum.netgate.com/topic/173083/22-05-and-pfblocker/8
      https://www.reddit.com/r/pfBlockerNG/comments/v7zp72/ip_block_logging_not_working_in_2205_plus_release/

      dead on arrival, nowhere to be found.

      P 1 Reply Last reply Aug 31, 2022, 3:21 PM Reply Quote 0
      • P
        paul2019 @mcury
        last edited by Aug 31, 2022, 3:21 PM

        @mcury Thank you, applied the patch. Even though there are no known issues with VOIP per se if that glitch affected pfblocker I'm wondering if it messes with the traffic somehow.

        alt text

        M 1 Reply Last reply Aug 31, 2022, 3:25 PM Reply Quote 0
        • S SteveITS referenced this topic on Aug 31, 2022, 3:22 PM
        • M
          mcury @paul2019
          last edited by Aug 31, 2022, 3:25 PM

          @paul2019 If it does, this would be the 1st comment about it.. At least I didn't see anything else about VOIP and pfblocker here in the forum.

          Since pfblockerng works blocking IPs, geoIP and DNSBL, you can check the reports tab to check if its blocking.

          Or, you could disable pfblockerng and its features to test.

          dead on arrival, nowhere to be found.

          P 2 Replies Last reply Aug 31, 2022, 3:31 PM Reply Quote 0
          • P paul2019 referenced this topic on Aug 31, 2022, 3:28 PM
          • P
            paul2019 @mcury
            last edited by Aug 31, 2022, 3:31 PM

            @mcury said in Just updated to pfsense 22.05, is it fully compatible with 3.1.0_4?:

            @paul2019 If it does, this would be the 1st comment about it.. At least I didn't see anything else about VOIP and pfblocker here in the forum.

            Since pfblockerng works blocking IPs, geoIP and DNSBL, you can check the reports tab to check if its blocking.

            Or, you could disable pfblockerng and its features to test.

            When I tried to disable it I got a few warnings regarding my rules "Unresolvable source alias 'pfB_COUNTRIES_PERMIT_v4' for rule 'NAT " and everything stopped working, should I stop the service or uncheck the "Enable" checkbox (that's what threw the warnings)?

            M 1 Reply Last reply Aug 31, 2022, 3:37 PM Reply Quote 0
            • P
              paul2019 @mcury
              last edited by Aug 31, 2022, 3:34 PM

              @mcury said in Just updated to pfsense 22.05, is it fully compatible with 3.1.0_4?:

              @paul2019 If it does, this would be the 1st comment about it.. At least I didn't see anything else about VOIP and pfblocker here in the forum.

              Since pfblockerng works blocking IPs, geoIP and DNSBL, you can check the reports tab to check if its blocking.

              Or, you could disable pfblockerng and its features to test.

              the traffic seems to pass fine:
              alt text

              1 Reply Last reply Reply Quote 0
              • M
                mcury @paul2019
                last edited by Aug 31, 2022, 3:37 PM

                @paul2019 said in Just updated to pfsense 22.05, is it fully compatible with 3.1.0_4?:

                everything stopped working

                That shouldn't happen.
                Check the reports tab to confirm before taking actions, you will be able to see something related to VOIP if that is the case.

                You can run an update

                login-to-view

                Once its complete, check the logs during the process to confirm if that list 'pfB_COUNTRIES_PERMIT_v4' for rule 'NAT was downloaded.

                @paul2019 said in Just updated to pfsense 22.05, is it fully compatible with 3.1.0_4?:

                should I stop the service or uncheck the "Enable" checkbox (that's what threw the warnings)?

                I don't think there is a difference, I would tick the enable option to disable the service, both pfblockerng and dnsbl.

                dead on arrival, nowhere to be found.

                P 2 Replies Last reply Aug 31, 2022, 3:53 PM Reply Quote 0
                • P
                  paul2019 @mcury
                  last edited by Aug 31, 2022, 3:53 PM

                  @mcury Did the update but still disabling pfblockerng makes the phone not work at all, I get a bunch of "Unresolvable source alias...." for all rules I have in place that forward the necessary ports.

                  alt text

                  alt text

                  M 1 Reply Last reply Aug 31, 2022, 3:56 PM Reply Quote 0
                  • M
                    mcury @paul2019
                    last edited by Aug 31, 2022, 3:56 PM

                    @paul2019 Edit that rule, check if the alias is correctly set, then save the rule again.

                    dead on arrival, nowhere to be found.

                    1 Reply Last reply Reply Quote 0
                    • P
                      paul2019 @mcury
                      last edited by Aug 31, 2022, 3:56 PM

                      @mcury The service "pfb_dnsbl" is not starting, is that normal? I never checked this before.

                      alt text

                      M 1 Reply Last reply Aug 31, 2022, 3:56 PM Reply Quote 0
                      • M
                        mcury @paul2019
                        last edited by Aug 31, 2022, 3:56 PM

                        @paul2019 said in Just updated to pfsense 22.05, is it fully compatible with 3.1.0_4?:

                        @mcury The service "pfb_dnsbl" is not starting, is that normal? I never checked this before.

                        alt text

                        No, this is not normal

                        dead on arrival, nowhere to be found.

                        P S 3 Replies Last reply Aug 31, 2022, 3:58 PM Reply Quote 0
                        • P
                          paul2019 @mcury
                          last edited by Aug 31, 2022, 3:58 PM

                          @mcury said in Just updated to pfsense 22.05, is it fully compatible with 3.1.0_4?:

                          @paul2019 said in Just updated to pfsense 22.05, is it fully compatible with 3.1.0_4?:

                          @mcury The service "pfb_dnsbl" is not starting, is that normal? I never checked this before.

                          alt text

                          No, this is not normal

                          There we go, must have happened after the update, how I can troubleshoot it?

                          1 Reply Last reply Reply Quote 0
                          • P
                            paul2019 @mcury
                            last edited by Aug 31, 2022, 4:04 PM

                            @mcury said in Just updated to pfsense 22.05, is it fully compatible with 3.1.0_4?:

                            @paul2019 said in Just updated to pfsense 22.05, is it fully compatible with 3.1.0_4?:

                            @mcury The service "pfb_dnsbl" is not starting, is that normal? I never checked this before.

                            alt text

                            No, this is not normal

                            Checking here the DNSBL tab, the Enabled DNSBL is unchecked, I don't remember turn it on before, not sure if that's related.

                            M 1 Reply Last reply Aug 31, 2022, 4:26 PM Reply Quote 0
                            • M
                              mcury @paul2019
                              last edited by Aug 31, 2022, 4:26 PM

                              @paul2019 Tick enable, but I doubt that is related to the voip issue.

                              dead on arrival, nowhere to be found.

                              1 Reply Last reply Reply Quote 0
                              • S
                                SteveITS Galactic Empire @mcury
                                last edited by Aug 31, 2022, 8:11 PM

                                @mcury said in Just updated to pfsense 22.05, is it fully compatible with 3.1.0_4?:

                                @paul2019 said in Just updated to pfsense 22.05, is it fully compatible with 3.1.0_4?:

                                @mcury The service "pfb_dnsbl" is not starting, is that normal? I never checked this before.

                                No, this is not normal

                                It is normal if DNSBL is not enabled. Many of our installs we use pfB for block lists and not DNSBL so it's off.

                                @paul2019 said in Just updated to pfsense 22.05, is it fully compatible with 3.1.0_4?:

                                Unresolvable source alias

                                If the alias doesn't exist pfSense will throw that error, if a firewall or NAT rule uses the alias. It can happen for instance when uninstalling pfBlocker in order to install an update to pfSense...years ago I locked myself out that way, installing an update to our office at night through a pfB NAT rule, but fortunately had other ways to get connected. I have also seen it on rare occasions after a reboot. Just run an update in pfB to recreate the alias.

                                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                                Upvote 👍 helpful posts!

                                1 Reply Last reply Reply Quote 0
                                • G Gertjan referenced this topic on Sep 21, 2022, 6:31 AM
                                • G Gertjan referenced this topic on Oct 3, 2022, 5:52 AM
                                10 out of 15
                                • First post
                                  10/15
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.