Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlockerNG not logging everything

    Scheduled Pinned Locked Moved pfBlockerNG
    10 Posts 2 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • gregeehG
      gregeeh
      last edited by

      Hi all,

      Have just installed pfBlockerNG 3.1.0.4 onto my pfSense 2.6.0 box and I have a question regarding the logging.

      If I open a browser on the LAN and place doubleclick.net in the address it is blocked and that is reflected in the logs. All good so far.

      If I open up a command prompt on the same PC this is what I get from nslookup:

      C:\Windows\System32>nslookup doubleclick.net
      Server:  pfSense.localdomain
      Address:  192.168.10.1
      
      Name:    doubleclick.net
      Address:  10.10.10.1
      
      C:\Windows\System32>
      

      Yes, it is blocked but nothing appears in the pfBlocker logs.
      Can someone please explain why?

      TIA

      PfSense running on Qotom mini PC
      CPU N3150, 2 GB memory, 32 GB SSD & 2 Realtek Gb Ethernet ports.
      UniFi AC-Lite access point

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @gregeeh
        last edited by

        @gregeeh
        Read and apply this.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        gregeehG 1 Reply Last reply Reply Quote 0
        • gregeehG
          gregeeh @Gertjan
          last edited by gregeeh

          @gertjan - I have pfSense 2.6 CE and not 22.01 so does this still apply? Plus I don't have high CPU Usage.

          PfSense running on Qotom mini PC
          CPU N3150, 2 GB memory, 32 GB SSD & 2 Realtek Gb Ethernet ports.
          UniFi AC-Lite access point

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan @gregeeh
            last edited by

            @gregeeh
            Both use the version "pfBlockerNG 3.1.0.4" so yes.

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            gregeehG 1 Reply Last reply Reply Quote 0
            • gregeehG
              gregeeh @Gertjan
              last edited by

              @gertjan The patch did not resolve the issue, sorry.

              PfSense running on Qotom mini PC
              CPU N3150, 2 GB memory, 32 GB SSD & 2 Realtek Gb Ethernet ports.
              UniFi AC-Lite access point

              GertjanG 1 Reply Last reply Reply Quote 0
              • GertjanG
                Gertjan @gregeeh
                last edited by

                @gregeeh

                C:\Users\Gauche>nslookup doubleclick.net
                Serveur :   pfSense.xxxxxxxxx.net
                Address:  192.168.1.1
                
                Nom :    doubleclick.net
                Address:  0.0.0.0
                

                I see the resolver requests (several, for A, AAAA, etc) in the DNS Reply tab, and in the

                2ae4f037-3977-4f0c-93b6-44fbaff54565-image.png

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                gregeehG 1 Reply Last reply Reply Quote 0
                • gregeehG
                  gregeeh @Gertjan
                  last edited by gregeeh

                  @gertjan - Yep that's what I would expect but not what I'm getting. Note you're getting an address of 0.0.0.0 while I'm getting 10.10.10.1.

                  Could this point to the issue?

                  BTW - What are you calling "The DNS Reply Tab"?

                  PfSense running on Qotom mini PC
                  CPU N3150, 2 GB memory, 32 GB SSD & 2 Realtek Gb Ethernet ports.
                  UniFi AC-Lite access point

                  GertjanG 1 Reply Last reply Reply Quote 0
                  • GertjanG
                    Gertjan @gregeeh
                    last edited by

                    @gregeeh said in pfBlockerNG not logging everything:

                    "The DNS Reply Tab"?

                    e1e37236-5821-4c9c-8342-3fdeda7af606-image.png

                    @gregeeh said in pfBlockerNG not logging everything:

                    you're getting an address of 0.0.0.0 while I'm getting 10.10.10.1.

                    b1ad62a5-11d6-41b0-96c7-c044981bff44-image.png

                    10.10.10.1 point to the build in web server that could show in a browser that the domain name your trying to visit is blocked.
                    But, IMHO, that's BS as most traffic there days is https, not http. Visiting http pages could be considered as a security problem.
                    And https can't be redirected, that's what https is all about, so the browser will spit a a "complex error message" and not showing this pfBlockerng block host message page.
                    I go for the much cleaner 0.0.0.0 solution.

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    gregeehG 1 Reply Last reply Reply Quote 0
                    • gregeehG
                      gregeeh @Gertjan
                      last edited by

                      @gertjan I don't seem to have a DNS Reply Tab:

                      alt text

                      PfSense running on Qotom mini PC
                      CPU N3150, 2 GB memory, 32 GB SSD & 2 Realtek Gb Ethernet ports.
                      UniFi AC-Lite access point

                      GertjanG 1 Reply Last reply Reply Quote 0
                      • GertjanG
                        Gertjan @gregeeh
                        last edited by

                        @gregeeh

                        Ah, right : you are not using the "Python mode" but the Unbound mode.

                        No "help me" PM's please. Use the forum, the community will thank you.
                        Edit : and where are the logs ??

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.