Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlockerNG-devel v3.1.0_0

    Scheduled Pinned Locked Moved pfBlockerNG
    22 Posts 12 Posters 13.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      p32spaceblaster
      last edited by

      Is anyone else having issues upgrading? I get the following:
      Confirmation Required to upgrade package pfSense-pkg-pfBlockerNG-devel from 3.0.0_16 to 3.1.0.

      Then this

      Upgrading pfSense-pkg-pfBlockerNG-devel...
      Updating pfSense-core repository catalogue...
      pfSense-core repository is up to date.
      Updating pfSense repository catalogue...
      pfSense repository is up to date.
      All repositories are up to date.
      Failed

      1 Reply Last reply Reply Quote 0
      • L
        ltolbert @BBcan177
        last edited by

        This post is deleted!
        1 Reply Last reply Reply Quote 0
        • M
          miquim
          last edited by

          I can not update the UT1 & ShallaList categories.

          my log is allways this:

          UPDATE PROCESS START [ v3.1.0 ] [ 10/26/21 16:25:00 ]
          
          ===[  DNSBL Process  ]================================================
          
          Clearing all DNSBL Feeds
          
          TLD Analysis not required.
          Stopping Unbound Resolver
          Unbound stopped in 1 sec.
          Additional mounts (DNSBL python):
            No changes required.
          Starting Unbound Resolver... completed
          Restarting DNSBL Service (DNSBL python)
          DNSBL update [ 0 | PASSED  ]... completed [ 10/26/21 16:25:01 ]
          ------------------------------------------------------------------------
          
          ===[  GeoIP Process  ]============================================
          
          
          ===[  Aliastables / Rules  ]==========================================
          
          No changes to Firewall rules, skipping Filter Reload
          No Changes to Aliases, Skipping pfctl Update
          
           UPDATE PROCESS ENDED
          
          

          any one can help me?

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan @miquim
            last edited by

            @miquim said in pfBlockerNG-devel v3.1.0_0:

            any one can help me?

            Looks like this :

            703c3537-0198-44b4-a151-da4ca11a6bac-image.png

            isn't checked, right ?

            The message "Clearing all DNSBL Feeds" is showed under one condition :

            // When DNSBL is enabled and no Aliases are defined, or all Aliases are Disabled
            

            as in that case there is nothing to do.

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            M 1 Reply Last reply Reply Quote 0
            • M
              miquim @Gertjan
              last edited by

              @gertjan said in pfBlockerNG-devel v3.1.0_0:

              @miquim said in pfBlockerNG-devel v3.1.0_0:

              any one can help me?

              Looks like this :

              703c3537-0198-44b4-a151-da4ca11a6bac-image.png

              isn't checked, right ?

              The message "Clearing all DNSBL Feeds" is showed under one condition :

              // When DNSBL is enabled and no Aliases are defined, or all Aliases are Disabled
              

              as in that case there is nothing to do.

              no, it is enable, I make a fresh install of pfsense pfSense-CE-2.5.2-RELEASE-amd64, than install the pfBlockerNG-devel version 3.1.0.

              1a9b26c6-ee6e-4917-a305-4ed4c8bc4861-image.png
              5492d7a2-a226-4839-a431-8048c9277d7c-image.png

              and get same error

              dd8ded49-4d16-436e-b862-93b9c5e4d891-image.png

              M 1 Reply Last reply Reply Quote 0
              • M
                miquim @miquim
                last edited by

                @miquim said in pfBlockerNG-devel v3.1.0_0:

                @gertjan said in pfBlockerNG-devel v3.1.0_0:

                @miquim said in pfBlockerNG-devel v3.1.0_0:

                any one can help me?

                Looks like this :

                703c3537-0198-44b4-a151-da4ca11a6bac-image.png

                isn't checked, right ?

                The message "Clearing all DNSBL Feeds" is showed under one condition :

                // When DNSBL is enabled and no Aliases are defined, or all Aliases are Disabled
                

                as in that case there is nothing to do.

                no, it is enable, I make a fresh install of pfsense pfSense-CE-2.5.2-RELEASE-amd64, than install the pfBlockerNG-devel version 3.1.0.

                1a9b26c6-ee6e-4917-a305-4ed4c8bc4861-image.png
                5492d7a2-a226-4839-a431-8048c9277d7c-image.png

                and get same error

                dd8ded49-4d16-436e-b862-93b9c5e4d891-image.png

                i found the problem, I need to create this dnsbl group like this and it worked.
                660a965d-7030-4fa7-b23d-3683946216d7-image.png

                1 Reply Last reply Reply Quote 1
                • R
                  rjamesm
                  last edited by

                  Any word on safe search allowing duckduckgo? It appears it doesn't work.

                  1 Reply Last reply Reply Quote 1
                  • K
                    ksh
                    last edited by

                    Hi
                    I have some challanges with pfBlockerNG on version 22.05.
                    I have 2 pfSense were i have a custom IPv4 source defination.
                    On one of my pfSense it does not update the entire list on my other it does.
                    They are sync the settings to eachother so it has the same configuration.
                    Any idea why this might go bad?
                    It seems that pfSense 1 is just stuck on some cache or some "obsolete" list

                    pfSense 1 log
                    Alias table IP Counts

                    18754 total
                    16397 /var/db/aliastables/pfB_PRI1_v4.txt
                    1178 /var/db/aliastables/pfB_Allow_Hosting_Gateway_v4.txt
                    1178 /var/db/aliastables/pfB_Allow_Hosting_Customers_v4.txt
                    1 /var/db/aliastables/pfB_3CX_ServerPublic_v4.txt

                    pfSense 2 log
                    Alias table IP Counts

                    19042 total
                    16635 /var/db/aliastables/pfB_PRI1_v4.txt
                    1203 /var/db/aliastables/pfB_Allow_Hosting_Gateway_v4.txt
                    1203 /var/db/aliastables/pfB_Allow_Hosting_Customers_v4.txt
                    1 /var/db/aliastables/pfB_3CX_ServerPublic_v4.txt

                    GertjanG 1 Reply Last reply Reply Quote 0
                    • GertjanG
                      Gertjan @ksh
                      last edited by Gertjan

                      @ksh

                      Do a Force reload, and look at what the log, at the bottom of the page, produces.
                      Even when I asked a

                      8c459bc3-a537-4a27-a56e-2f5ad7bd3246-image.png

                      the files didn't get reloaded again :

                      ...
                      ====================[ DNSBL Last Updated List Summary ]==============
                      
                      Oct 3	00:00	DNSBL_174618
                      Dec 5	00:00	UT1_gambling
                      Dec 5	00:00	UT1_games
                      Dec 5	00:00	UT1_phishing
                      Dec 5	00:00	UT1_warez
                      Dec 5	00:00	StevenBlack_ADs
                      ===============================================================
                      ...
                      

                      Note : where I live, its December 7.
                      So, it might be possible that files on your two pfSense are not 100 % identical.
                      This behaviour is normal. List don't get reloaded every hours or so as this (xx thousands of pfBlockerng-devel are running out there) would destroy the web servers that hosts these files.

                      Btw : I've demanded to update my one and only DNSBL list Weekly, as these lists do not get updated massively every hour or day and I don't bother missing one or two.

                      3959bffc-400b-4776-a1f0-f44808105c40-image.png

                      No "help me" PM's please. Use the forum, the community will thank you.
                      Edit : and where are the logs ??

                      K 1 Reply Last reply Reply Quote 0
                      • K
                        ksh @Gertjan
                        last edited by

                        @gertjan
                        My custom list needs to be adjusted more than once an hour :)

                        Bottom of the log file:
                        ====================[ DNSBL Last Updated List Summary ]==============

                        Nov 29 00:00 StevenBlack_ADs

                        Database Sanity check [ PASSED ]

                        Masterfile/Deny folder uniq check
                        Deny folder/Masterfile uniq check

                        Sync check (Pass=No IPs reported)

                        Alias table IP Counts

                        18754 total
                        16397 /var/db/aliastables/pfB_PRI1_v4.txt
                        1178 /var/db/aliastables/pfB_Allow_Hosting_Gateway_v4.txt
                        1178 /var/db/aliastables/pfB_Allow_Hosting_Customers_v4.txt
                        1 /var/db/aliastables/pfB_3CX_ServerPublic_v4.txt

                        pfSense Table Stats

                        table-entries hard limit 400000
                        Table Usage Count 159353

                        UPDATE PROCESS ENDED [ 12/7/22 13:03:18 ]

                        GertjanG 1 Reply Last reply Reply Quote 0
                        • GertjanG
                          Gertjan @ksh
                          last edited by Gertjan

                          @ksh

                          You didn't show what I've showed you.
                          The part with the dates and hour.

                          I've tricked my pfblockerng-devel by forcing it to download the lists again.
                          I've deleted all the files in /var/db/pfblockerng/dnsblorig/
                          Then I did a force reload.
                          It showed :

                          ====================[ DNSBL Last Updated List Summary ]==============
                          
                          Dec 7	13:37	UT1_gambling
                          Dec 7	13:37	UT1_games
                          Dec 7	13:37	UT1_phishing
                          Dec 7	13:37	UT1_warez
                          Dec 7	13:37	StevenBlack_ADs
                          ===============================================================
                          

                          Done ;)

                          No "help me" PM's please. Use the forum, the community will thank you.
                          Edit : and where are the logs ??

                          K 1 Reply Last reply Reply Quote 0
                          • K
                            ksh @Gertjan
                            last edited by

                            @gertjan
                            So this one?
                            ====================[ IPv4/6 Last Updated List Summary ]==============

                            Nov 10 03:53 Spamhaus_eDrop_v4
                            Nov 29 05:18 Spamhaus_Drop_v4
                            Nov 29 06:30 ET_Block_v4
                            Nov 29 23:16 ET_Comp_v4
                            Nov 30 06:00 Talos_BL_v4
                            Nov 30 12:50 ISC_Block_v4
                            Nov 30 13:18 CINS_army_v4
                            Nov 30 14:00 Abuse_SSLBL_v4
                            Nov 30 14:00 Abuse_Feodo_C2_v4
                            Nov 30 14:00 CompusoftCustomers_v4
                            Dec 7 13:03 3CX_ServerPublic_custom_v4

                            GertjanG 1 Reply Last reply Reply Quote 0
                            • GertjanG
                              Gertjan @ksh
                              last edited by

                              @ksh

                              Yep.
                              Rookie mode : Delete them all - and sync pfblocker
                              Better be safe then sorry : copy them on a safe place and then delete them all, and sync pfblocker

                              Btw : Dec 7 13:03 3CX_ServerPublic_custom_v4 (your own list ?) seems recent enough.

                              Other lists : if they didn't changed, they won't get downloaded (I guess ?!)

                              No "help me" PM's please. Use the forum, the community will thank you.
                              Edit : and where are the logs ??

                              K 1 Reply Last reply Reply Quote 0
                              • K
                                ksh @Gertjan
                                last edited by ksh

                                @gertjan
                                I removed the list. And added it again. This works.
                                But if i go and add an IP to the list an run the job it doesn't get updated :/

                                There should be 1278 and 1276 in /var/db/aliastables/pfB_Allow_Hosting_Customers_v4.txt

                                I can also see that it seems like it doesn't get updated from when i create it to i update it.
                                But my 3CX_ServerPublic_custom_v4 seems to be updated everytime. This is an Alias Native. and not a list.

                                ====================[ IPv4/6 Last Updated List Summary ]==============

                                Nov 10 03:53 Spamhaus_eDrop_v4
                                Nov 29 05:18 Spamhaus_Drop_v4
                                Nov 29 06:30 ET_Block_v4
                                Nov 29 23:16 ET_Comp_v4
                                Nov 30 06:00 Talos_BL_v4
                                Nov 30 12:50 ISC_Block_v4
                                Nov 30 13:18 CINS_army_v4
                                Nov 30 14:00 Abuse_SSLBL_v4
                                Nov 30 14:00 Abuse_Feodo_C2_v4
                                Dec 7 21:21 CustomersGateway_v4
                                Dec 7 21:23 CompusoftCustomers_v4
                                Dec 7 21:35 3CX_ServerPublic_custom_v4

                                ====================[ DNSBL Last Updated List Summary ]==============

                                Nov 29 00:00 StevenBlack_ADs

                                Database Sanity check [ PASSED ]

                                Masterfile/Deny folder uniq check
                                Deny folder/Masterfile uniq check

                                Sync check (Pass=No IPs reported)

                                Alias table IP Counts

                                20550 total
                                17997 /var/db/aliastables/pfB_PRI1_v4.txt
                                1276 /var/db/aliastables/pfB_Allow_Hosting_Gateway_v4.txt
                                1276 /var/db/aliastables/pfB_Allow_Hosting_Customers_v4.txt
                                1 /var/db/aliastables/pfB_3CX_ServerPublic_v4.txt

                                pfSense Table Stats

                                table-entries hard limit 400000
                                Table Usage Count 161000

                                UPDATE PROCESS ENDED [ 12/7/22 21:35:30 ]

                                GertjanG 1 Reply Last reply Reply Quote 0
                                • GertjanG
                                  Gertjan @ksh
                                  last edited by

                                  @ksh said in pfBlockerNG-devel v3.1.0_0:

                                  But if i go and add an IP to the list an run the job it doesn't get updated :/

                                  You posted (now) 11 hours ago. It's 08h00 AM here.

                                  The last time that your file was downloaded, was :

                                  @ksh said in pfBlockerNG-devel v3.1.0_0:

                                  Dec 7 21:35 3CX_ServerPublic_custom_v4

                                  That's also some 11 hours ago.
                                  That file seems pretty up to date to me.

                                  If you set pfBlockerng to do house hold tasks every hour :

                                  2a571df8-0a8b-40fa-bae5-89f25f4a8120-image.png

                                  and set your list ( I showed a DNSBL list here ) to be downloaded every hour :

                                  5f293093-c307-447e-a897-92c36e65e29d-image.png

                                  then this file will ... should (?!) get downloaded every hour.

                                  In your case, as you host this file yourself, that's ok, you' hitting your infrastructure.
                                  I strongly advice you not to do this for any other feed/list that is on a host that you do not own.

                                  No "help me" PM's please. Use the forum, the community will thank you.
                                  Edit : and where are the logs ??

                                  K 1 Reply Last reply Reply Quote 0
                                  • K
                                    ksh @Gertjan
                                    last edited by

                                    @gertjan
                                    I have figured it out now.
                                    I was running the reload command and not the cron command.
                                    When i run the cron command it updates the list in the firewall.
                                    And you are right I shouldn't spam other list. A workround for now is that i make my own custom list that contains the IP addresses from the other list and update the backend list once a day.
                                    Thanks for the help

                                    1 Reply Last reply Reply Quote 0
                                    • BBcan177B BBcan177 unpinned this topic on
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.