Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlockerNG-devel v3.1.0_19/10

    Scheduled Pinned Locked Moved pfBlockerNG
    77 Posts 17 Posters 23.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      pfT @BBcan177
      last edited by

      @bbcan177 said in pfBlockerNG-devel v3.1.0_19/10:

      @pft said in pfBlockerNG-devel v3.1.0_19/10:

      Not entirely sure what's going on there, but i'm happy to live with it

      Probably due to deduplication

      bbcan177,

      Thanks.

      That's exactly what it was. Coincidentally, I had just finished checking exactly that before seeing your post. I learn something every day.

      I feel I have taken this thread completely off topic. Sorry for that.

      I'll crawl back into my hole and stop bothering both you and the community. I feel quite abashed at the moment.

      BBcan177B 1 Reply Last reply Reply Quote 0
      • BBcan177B
        BBcan177 Moderator @pfT
        last edited by

        @pft read my tagline below....:)

        "Experience is something you don't get until just after you need it."

        Website: http://pfBlockerNG.com
        Twitter: @BBcan177  #pfBlockerNG
        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

        1 Reply Last reply Reply Quote 2
        • T
          Tigo @BBcan177
          last edited by

          @bbcan177

          Unfortunately, ver _20 is not showing up for me on pfsense 23.01 - it's still reading ver _16. I have tried updating the repository from shell, and it's reporting that repositories are up to date.

          Is there an command that I can run from shell to force the upgrade for it? I also have the portBSD repsositories enabled as well.

          Thanks,

          T 1 Reply Last reply Reply Quote 0
          • Y
            yorke
            last edited by

            @bbcan177

            pfBlockerNG-devel 3.1.0_11 |ERROR| python module 'maxminddb
            Pfsense 2.6.0-RELEASE
            I upgraded pfBlockerNG-devel to 3.1.0_11 and got some issue before i upgraded everyting was work but now after the upgrade I am geting the errors listed below,
            2023-01-20 18:16:12,627|ERROR| [pfBlockerNG]: Failed to load python module 'maxminddb': No module named 'maxminddb'
            2023-01-20 18:16:12,627|ERROR| [pfBlockerNG]: Failed to load python module 'sqlite3': No module named '_sqlite3'
            MaxMind GeoIP download the file and GeoLite2-Country.mmdb is in /usr/local/share/GeoIP
            Under Report tab Alert country code are listed under GeoIP/ASN.
            The report tab showns traffic being pass/block
            the dashboard for DNSBL the packets stay at 0 the counter do not move, but the ip counter works
            I Referenced these post https://forum.netgate.com/topic/176668/geoip-showing-unk
            https://forum.netgate.com/topic/176991/geoip-shows-country-as-unknown
            to try and fix it.
            their are no other errors but the ones below.

            BBcan177B N 2 Replies Last reply Reply Quote 0
            • BBcan177B
              BBcan177 Moderator @yorke
              last edited by

              @yorke did you try to reinstall the package? Reboot?

              "Experience is something you don't get until just after you need it."

              Website: http://pfBlockerNG.com
              Twitter: @BBcan177  #pfBlockerNG
              Reddit: https://www.reddit.com/r/pfBlockerNG/new/

              Y 1 Reply Last reply Reply Quote 0
              • T
                Tigo @Tigo
                last edited by

                @tigo

                I had also uninstalled it. Rebooted. Checked the branch updates, - and it’s still v_16. Installed it again - configured - rebooted and yet no v_20.

                Perhaps it hasn’t been approved - pushed out yet?

                1 Reply Last reply Reply Quote 0
                • S
                  smolka_J
                  last edited by

                  I have been getting quite a bit of download/update failures on 3.1.0_11 for any feed trying to update. Going into my previously working feeds lists, when I first enabled a few with pfBlockerng still disabled on the general tab after updating, settings saved fine with no errors. Re-enabled pfBlocker, forced reload, forced update and cron seeing the "Invalid URL. Terminating Download!" for each. Looking into the same DNSBL lists noting failures, attempting to save/edit/disable any while pfBlocker is enabled displays the errors below on both boxes, verified DNS hostnames and lists are all working otherwise except the same couple that were still down prior pending maintenance:

                  DNSBL Source Definitions, Line 1: Invalid URL or Hostname not resolvable!
                  DNSBL Source Definitions, Line 2: Invalid URL or Hostname not resolvable!
                  DNSBL Source Definitions, Line 3: Invalid URL or Hostname not resolvable!
                  DNSBL Source Definitions, Line 5: Invalid URL or Hostname not resolvable!
                  DNSBL Source Definitions, Line 6: Invalid URL or Hostname not resolvable!
                  DNSBL Source Definitions, Line 7: Invalid URL or Hostname not resolvable!
                  DNSBL Source Definitions, Line 8: Invalid URL or Hostname not resolvable!
                  DNSBL Source Definitions, Line 10: Invalid URL or Hostname not resolvable!
                  DNSBL Source Definitions, Line 11: Invalid URL or Hostname not resolvable!
                  DNSBL Source Definitions, Line 12: Invalid URL or Hostname not resolvable!
                  DNSBL Source Definitions, Line 13: Invalid URL or Hostname not resolvable!
                  DNSBL Source Definitions, Line 14: Invalid URL or Hostname not resolvable!
                  DNSBL Source Definitions, Line 15: Invalid URL or Hostname not resolvable!
                  DNSBL Source Definitions, Line 16: Invalid URL or Hostname not resolvable!
                  DNSBL Source Definitions, Line 18: Invalid URL or Hostname not resolvable!
                  DNSBL Source Definitions, Line 19: Invalid URL or Hostname not resolvable!

                  BBcan177B 1 Reply Last reply Reply Quote 0
                  • Y
                    yorke @BBcan177
                    last edited by

                    @bbcan177

                    Yes did a clean fresh install of the PfblockerNG package 3 times with the keep settings uncheck
                    but the error is still showing up , I notice under the Report unified Geoip is unk but under Alert Geoip/ASN list country,
                    the packages i have installed are PfblockerNG, Suricata and Cron (memory usage 8% ), (MBUF Usage 3%), (State table size 0%) ( cpu usage 4%) (Swap space 0%) Service Status all green,
                    did some test clear the Dns Resolver log under( system logs/system/dns resolver/) these 2 lines
                    unbound 21493 [21493:0] notice: init module 0: python
                    unbound 21493 [21493:0] info: [pfBlockerNG]: pfb_unbound.py script loaded
                    reappear go to the dashboard the DNSBL turns yellow and gives the error
                    |ERROR| [pfBlockerNG]: Failed to load python module 'maxminddb': No module named 'maxminddb'
                    |ERROR| [pfBlockerNG]: Failed to load python module 'sqlite3': No module named '_sqlite3'

                    BBcan177B 1 Reply Last reply Reply Quote 0
                    • BBcan177B
                      BBcan177 Moderator @smolka_J
                      last edited by

                      @smoke_a_j said in pfBlockerNG-devel v3.1.0_19/10:

                      DNSBL Source Definitions, Line 1: Invalid URL or Hostname not resolvable!

                      Either DNS isn't working on your box or something is blocking those urls.

                      "Experience is something you don't get until just after you need it."

                      Website: http://pfBlockerNG.com
                      Twitter: @BBcan177  #pfBlockerNG
                      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                      S 1 Reply Last reply Reply Quote 0
                      • BBcan177B
                        BBcan177 Moderator @yorke
                        last edited by

                        @yorke I would backup you config and install a fresh copy of pfSense. Followed by a restore of the config.

                        "Experience is something you don't get until just after you need it."

                        Website: http://pfBlockerNG.com
                        Twitter: @BBcan177  #pfBlockerNG
                        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                        Y 1 Reply Last reply Reply Quote 0
                        • S
                          smolka_J @BBcan177
                          last edited by

                          @bbcan177 Gracias, at first I thought it was seeming similar to the inbound permit saving issue. Regardless of having most of these feeds already whitelisted, tracked it down to about 1500 some lines of regex I had came across and added a while back, most of which seemed to not be populating any alerts but invisibly blocking at random until matching the suffix/prefix portions of the code to match known alerting lines started populating the rest. I trimmed out 1300 lines to whats working, I then realized the entire 1500 lines I found were basically a reflection of the DNSBL TLD Group 1 & 2 lists. Went back to just my first 680 lines of regex and no more ghosted double filtering and running smooth

                          BBcan177B 1 Reply Last reply Reply Quote 0
                          • BBcan177B
                            BBcan177 Moderator @smolka_J
                            last edited by

                            @smoke_a_j If you can pm or email that regex list, I can check it out to see if there is some code improvement required.

                            "Experience is something you don't get until just after you need it."

                            Website: http://pfBlockerNG.com
                            Twitter: @BBcan177  #pfBlockerNG
                            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                            1 Reply Last reply Reply Quote 0
                            • N
                              nimrod @yorke
                              last edited by

                              @yorke said in pfBlockerNG-devel v3.1.0_19/10:

                              @bbcan177

                              pfBlockerNG-devel 3.1.0_11 |ERROR| python module 'maxminddb
                              Pfsense 2.6.0-RELEASE
                              I upgraded pfBlockerNG-devel to 3.1.0_11 and got some issue before i upgraded everyting was work but now after the upgrade I am geting the errors listed below,
                              2023-01-20 18:16:12,627|ERROR| [pfBlockerNG]: Failed to load python module 'maxminddb': No module named 'maxminddb'
                              2023-01-20 18:16:12,627|ERROR| [pfBlockerNG]: Failed to load python module 'sqlite3': No module named '_sqlite3'

                              I got the same error on pfSense v2.6.0 since the upgrade to pfBlockerNG v3.1.0_11. I have cleared the error in py_error.log. Lets see if it comes back.

                              The report tab showns traffic being pass/block
                              the dashboard for DNSBL the packets stay at 0 the counter do not move, but the ip counter works

                              Same issue with IP Counter. It shows number of blocked IPs for a while, but when you refresh the page, counter goes to 0. This issue happens if you apply this patch via system patches package.

                              ba6d96ea-1a8f-448b-be68-285c6e8d6a4d-image.png

                              More details here.

                              If you revert this change, counter starts working as it should and it doesnt reset to 0 after some time.

                              1 Reply Last reply Reply Quote 0
                              • D
                                Draco @BBcan177
                                last edited by Draco

                                @bbcan177 said in pfBlockerNG-devel v3.1.0_19/10:

                                Add "application/json" to list of allowed file download mime-types

                                I had hoped this might let pfBlocker directly download a JSON list like the one found at Microsoft Azure IPs. This is a file I manually download and then use pfSense's GUI CMD interface to upload for pfBlocker (I set the format to AUTO). Ran this on 3.1.0_11 just now.

                                It didn't work. So what JSON-related things were enabled with this change?

                                Thanks!

                                N BBcan177B 2 Replies Last reply Reply Quote 0
                                • N
                                  nimrod @Draco
                                  last edited by

                                  It happened again after after update.

                                  39063a17-dfca-4dcd-a76c-2419e8b11441-image.png

                                  This is the content of py_error.log

                                  2023-01-24 16:36:57,206|ERROR| [pfBlockerNG]: Failed to load python module 'maxminddb': No module named 'maxminddb'
                                  2023-01-24 16:36:57,206|ERROR| [pfBlockerNG]: Failed to load python module 'sqlite3': No module named '_sqlite3'
                                  

                                  Despite these errors, everything is working fine.

                                  cmcdonaldC 1 Reply Last reply Reply Quote 0
                                  • cmcdonaldC
                                    cmcdonald Netgate Developer @nimrod
                                    last edited by cmcdonald

                                    @nimrod

                                    What is the output of:

                                    pkg info py* unbound

                                    Need help fast? https://www.netgate.com/support

                                    R 1 Reply Last reply Reply Quote 0
                                    • R
                                      renegade @cmcdonald
                                      last edited by

                                      @cmcdonald
                                      Same problem on my side.

                                      [22.05-RELEASE][admin@firewall.home]/root: pkg info py* unbound
                                      pkg: No match.

                                      cmcdonaldC 1 Reply Last reply Reply Quote 0
                                      • cmcdonaldC
                                        cmcdonald Netgate Developer @renegade
                                        last edited by

                                        @renegade

                                        Sorry, try this:

                                        pkg info "py*" unbound

                                        Need help fast? https://www.netgate.com/support

                                        N 1 Reply Last reply Reply Quote 0
                                        • N
                                          nimrod @cmcdonald
                                          last edited by

                                          @cmcdonald said in pfBlockerNG-devel v3.1.0_19/10:

                                          @renegade

                                          Sorry, try this:

                                          pkg info "py*" unbound

                                          Here it is:

                                          [2.6.0-RELEASE][admin@pfSense.home.arpa]/root: pkg info "py*" unbound
                                          py38-ply-3.11
                                          py38-setuptools-57.0.0
                                          py39-maxminddb-2.0.3
                                          py39-setuptools-57.0.0
                                          py39-sqlite3-3.9.9_7
                                          python38-3.8.12_1
                                          python39-3.9.9
                                          unbound-1.13.2
                                          
                                          
                                          cmcdonaldC 2 Replies Last reply Reply Quote 0
                                          • cmcdonaldC
                                            cmcdonald Netgate Developer @nimrod
                                            last edited by

                                            @nimrod Thanks. I see the problem. Testing a fix. Standby

                                            Need help fast? https://www.netgate.com/support

                                            1 Reply Last reply Reply Quote 2
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.