• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

pfBlockerNG-devel v3.1.0_19/10

pfBlockerNG
17
77
17.8k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    smolka_J
    last edited by Jan 21, 2023, 9:24 AM

    I have been getting quite a bit of download/update failures on 3.1.0_11 for any feed trying to update. Going into my previously working feeds lists, when I first enabled a few with pfBlockerng still disabled on the general tab after updating, settings saved fine with no errors. Re-enabled pfBlocker, forced reload, forced update and cron seeing the "Invalid URL. Terminating Download!" for each. Looking into the same DNSBL lists noting failures, attempting to save/edit/disable any while pfBlocker is enabled displays the errors below on both boxes, verified DNS hostnames and lists are all working otherwise except the same couple that were still down prior pending maintenance:

    DNSBL Source Definitions, Line 1: Invalid URL or Hostname not resolvable!
    DNSBL Source Definitions, Line 2: Invalid URL or Hostname not resolvable!
    DNSBL Source Definitions, Line 3: Invalid URL or Hostname not resolvable!
    DNSBL Source Definitions, Line 5: Invalid URL or Hostname not resolvable!
    DNSBL Source Definitions, Line 6: Invalid URL or Hostname not resolvable!
    DNSBL Source Definitions, Line 7: Invalid URL or Hostname not resolvable!
    DNSBL Source Definitions, Line 8: Invalid URL or Hostname not resolvable!
    DNSBL Source Definitions, Line 10: Invalid URL or Hostname not resolvable!
    DNSBL Source Definitions, Line 11: Invalid URL or Hostname not resolvable!
    DNSBL Source Definitions, Line 12: Invalid URL or Hostname not resolvable!
    DNSBL Source Definitions, Line 13: Invalid URL or Hostname not resolvable!
    DNSBL Source Definitions, Line 14: Invalid URL or Hostname not resolvable!
    DNSBL Source Definitions, Line 15: Invalid URL or Hostname not resolvable!
    DNSBL Source Definitions, Line 16: Invalid URL or Hostname not resolvable!
    DNSBL Source Definitions, Line 18: Invalid URL or Hostname not resolvable!
    DNSBL Source Definitions, Line 19: Invalid URL or Hostname not resolvable!

    B 1 Reply Last reply Jan 21, 2023, 2:32 PM Reply Quote 0
    • Y
      yorke @BBcan177
      last edited by Jan 21, 2023, 1:32 PM

      @bbcan177

      Yes did a clean fresh install of the PfblockerNG package 3 times with the keep settings uncheck
      but the error is still showing up , I notice under the Report unified Geoip is unk but under Alert Geoip/ASN list country,
      the packages i have installed are PfblockerNG, Suricata and Cron (memory usage 8% ), (MBUF Usage 3%), (State table size 0%) ( cpu usage 4%) (Swap space 0%) Service Status all green,
      did some test clear the Dns Resolver log under( system logs/system/dns resolver/) these 2 lines
      unbound 21493 [21493:0] notice: init module 0: python
      unbound 21493 [21493:0] info: [pfBlockerNG]: pfb_unbound.py script loaded
      reappear go to the dashboard the DNSBL turns yellow and gives the error
      |ERROR| [pfBlockerNG]: Failed to load python module 'maxminddb': No module named 'maxminddb'
      |ERROR| [pfBlockerNG]: Failed to load python module 'sqlite3': No module named '_sqlite3'

      B 1 Reply Last reply Jan 21, 2023, 2:32 PM Reply Quote 0
      • B
        BBcan177 Moderator @smolka_J
        last edited by Jan 21, 2023, 2:32 PM

        @smoke_a_j said in pfBlockerNG-devel v3.1.0_19/10:

        DNSBL Source Definitions, Line 1: Invalid URL or Hostname not resolvable!

        Either DNS isn't working on your box or something is blocking those urls.

        "Experience is something you don't get until just after you need it."

        Website: http://pfBlockerNG.com
        Twitter: @BBcan177  #pfBlockerNG
        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

        S 1 Reply Last reply Jan 22, 2023, 5:38 PM Reply Quote 0
        • B
          BBcan177 Moderator @yorke
          last edited by Jan 21, 2023, 2:32 PM

          @yorke I would backup you config and install a fresh copy of pfSense. Followed by a restore of the config.

          "Experience is something you don't get until just after you need it."

          Website: http://pfBlockerNG.com
          Twitter: @BBcan177  #pfBlockerNG
          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

          Y 1 Reply Last reply Jan 25, 2023, 4:38 AM Reply Quote 0
          • S
            smolka_J @BBcan177
            last edited by Jan 22, 2023, 5:38 PM

            @bbcan177 Gracias, at first I thought it was seeming similar to the inbound permit saving issue. Regardless of having most of these feeds already whitelisted, tracked it down to about 1500 some lines of regex I had came across and added a while back, most of which seemed to not be populating any alerts but invisibly blocking at random until matching the suffix/prefix portions of the code to match known alerting lines started populating the rest. I trimmed out 1300 lines to whats working, I then realized the entire 1500 lines I found were basically a reflection of the DNSBL TLD Group 1 & 2 lists. Went back to just my first 680 lines of regex and no more ghosted double filtering and running smooth

            B 1 Reply Last reply Jan 22, 2023, 5:40 PM Reply Quote 0
            • B
              BBcan177 Moderator @smolka_J
              last edited by Jan 22, 2023, 5:40 PM

              @smoke_a_j If you can pm or email that regex list, I can check it out to see if there is some code improvement required.

              "Experience is something you don't get until just after you need it."

              Website: http://pfBlockerNG.com
              Twitter: @BBcan177  #pfBlockerNG
              Reddit: https://www.reddit.com/r/pfBlockerNG/new/

              1 Reply Last reply Reply Quote 0
              • N
                nimrod @yorke
                last edited by Jan 23, 2023, 1:23 PM

                @yorke said in pfBlockerNG-devel v3.1.0_19/10:

                @bbcan177

                pfBlockerNG-devel 3.1.0_11 |ERROR| python module 'maxminddb
                Pfsense 2.6.0-RELEASE
                I upgraded pfBlockerNG-devel to 3.1.0_11 and got some issue before i upgraded everyting was work but now after the upgrade I am geting the errors listed below,
                2023-01-20 18:16:12,627|ERROR| [pfBlockerNG]: Failed to load python module 'maxminddb': No module named 'maxminddb'
                2023-01-20 18:16:12,627|ERROR| [pfBlockerNG]: Failed to load python module 'sqlite3': No module named '_sqlite3'

                I got the same error on pfSense v2.6.0 since the upgrade to pfBlockerNG v3.1.0_11. I have cleared the error in py_error.log. Lets see if it comes back.

                The report tab showns traffic being pass/block
                the dashboard for DNSBL the packets stay at 0 the counter do not move, but the ip counter works

                Same issue with IP Counter. It shows number of blocked IPs for a while, but when you refresh the page, counter goes to 0. This issue happens if you apply this patch via system patches package.

                🔒 Log in to view

                More details here.

                If you revert this change, counter starts working as it should and it doesnt reset to 0 after some time.

                1 Reply Last reply Reply Quote 0
                • D
                  Draco @BBcan177
                  last edited by Draco Jan 23, 2023, 11:46 PM Jan 23, 2023, 11:45 PM

                  @bbcan177 said in pfBlockerNG-devel v3.1.0_19/10:

                  Add "application/json" to list of allowed file download mime-types

                  I had hoped this might let pfBlocker directly download a JSON list like the one found at Microsoft Azure IPs. This is a file I manually download and then use pfSense's GUI CMD interface to upload for pfBlocker (I set the format to AUTO). Ran this on 3.1.0_11 just now.

                  It didn't work. So what JSON-related things were enabled with this change?

                  Thanks!

                  N B 2 Replies Last reply Jan 24, 2023, 3:41 PM Reply Quote 0
                  • N
                    nimrod @Draco
                    last edited by Jan 24, 2023, 3:41 PM

                    It happened again after after update.

                    🔒 Log in to view

                    This is the content of py_error.log

                    2023-01-24 16:36:57,206|ERROR| [pfBlockerNG]: Failed to load python module 'maxminddb': No module named 'maxminddb'
                    2023-01-24 16:36:57,206|ERROR| [pfBlockerNG]: Failed to load python module 'sqlite3': No module named '_sqlite3'
                    

                    Despite these errors, everything is working fine.

                    C 1 Reply Last reply Jan 24, 2023, 3:59 PM Reply Quote 0
                    • C
                      cmcdonald Netgate Developer @nimrod
                      last edited by cmcdonald Jan 24, 2023, 4:00 PM Jan 24, 2023, 3:59 PM

                      @nimrod

                      What is the output of:

                      pkg info py* unbound

                      Need help fast? https://www.netgate.com/support

                      R 1 Reply Last reply Jan 24, 2023, 4:05 PM Reply Quote 0
                      • R
                        renegade @cmcdonald
                        last edited by Jan 24, 2023, 4:05 PM

                        @cmcdonald
                        Same problem on my side.

                        [22.05-RELEASE][admin@firewall.home]/root: pkg info py* unbound
                        pkg: No match.

                        C 1 Reply Last reply Jan 24, 2023, 4:10 PM Reply Quote 0
                        • C
                          cmcdonald Netgate Developer @renegade
                          last edited by Jan 24, 2023, 4:10 PM

                          @renegade

                          Sorry, try this:

                          pkg info "py*" unbound

                          Need help fast? https://www.netgate.com/support

                          N 1 Reply Last reply Jan 24, 2023, 4:15 PM Reply Quote 0
                          • N
                            nimrod @cmcdonald
                            last edited by Jan 24, 2023, 4:15 PM

                            @cmcdonald said in pfBlockerNG-devel v3.1.0_19/10:

                            @renegade

                            Sorry, try this:

                            pkg info "py*" unbound

                            Here it is:

                            [2.6.0-RELEASE][admin@pfSense.home.arpa]/root: pkg info "py*" unbound
                            py38-ply-3.11
                            py38-setuptools-57.0.0
                            py39-maxminddb-2.0.3
                            py39-setuptools-57.0.0
                            py39-sqlite3-3.9.9_7
                            python38-3.8.12_1
                            python39-3.9.9
                            unbound-1.13.2
                            
                            
                            C 2 Replies Last reply Jan 24, 2023, 4:18 PM Reply Quote 0
                            • C
                              cmcdonald Netgate Developer @nimrod
                              last edited by Jan 24, 2023, 4:18 PM

                              @nimrod Thanks. I see the problem. Testing a fix. Standby

                              Need help fast? https://www.netgate.com/support

                              1 Reply Last reply Reply Quote 2
                              • C
                                cmcdonald Netgate Developer @nimrod
                                last edited by Jan 24, 2023, 4:20 PM

                                @nimrod can you also share pkg info unbound ?

                                Need help fast? https://www.netgate.com/support

                                N 1 Reply Last reply Jan 24, 2023, 4:23 PM Reply Quote 0
                                • N
                                  nimrod @cmcdonald
                                  last edited by Jan 24, 2023, 4:23 PM

                                  @cmcdonald said in pfBlockerNG-devel v3.1.0_19/10:

                                  @nimrod can you also share pkg info unbound ?

                                  Of course. Here it is:

                                  [2.6.0-RELEASE][admin@pfSense.home.arpa]/root: pkg info unbound
                                  unbound-1.13.2
                                  Name           : unbound
                                  Version        : 1.13.2
                                  Installed on   : Mon Jan 31 21:24:27 2022 CET
                                  Origin         : dns/unbound
                                  Architecture   : FreeBSD:12:amd64
                                  Prefix         : /usr/local
                                  Categories     : dns
                                  Licenses       : BSD3CLAUSE
                                  Maintainer     : jaap@NLnetLabs.nl
                                  WWW            : https://www.nlnetlabs.nl/projects/unbound
                                  Comment        : Validating, recursive, and caching DNS resolver
                                  Options        :
                                  	DEP-RSA1024    : off
                                  	DNSCRYPT       : off
                                  	DNSTAP         : off
                                  	DOCS           : off
                                  	DOH            : on
                                  	ECDSA          : on
                                  	EVAPI          : off
                                  	FILTER_AAAA    : off
                                  	GOST           : on
                                  	HIREDIS        : off
                                  	LIBEVENT       : on
                                  	MUNIN_PLUGIN   : off
                                  	PYTHON         : on
                                  	SUBNET         : off
                                  	TFOCL          : off
                                  	TFOSE          : off
                                  	THREADS        : on
                                  Shared Libs required:
                                  	libexpat.so.1
                                  	libnghttp2.so.14
                                  	libpython3.8.so.1.0
                                  	libevent-2.1.so.7
                                  Shared Libs provided:
                                  	libunbound.so.8
                                  Annotations    :
                                  	FreeBSD_version: 1203500
                                  	build_timestamp: 2022-01-12T15:27:10+0000
                                  	built_by       : poudriere-git-3.3.99.20211130
                                  	cpe            : cpe:2.3:a:nlnetlabs:unbound:1.13.2:::::freebsd12:x64
                                  	port_checkout_unclean: no
                                  	port_git_hash  : 8df9544dcbab
                                  	ports_top_checkout_unclean: yes
                                  	ports_top_git_hash: 7046b65c0d41
                                  	repo_type      : binary
                                  	repository     : pfSense
                                  Flat size      : 7.99MiB
                                  Description    :
                                  Unbound is designed as a set of modular components, so that also
                                  DNSSEC (secure DNS) validation and stub-resolvers (that do not run as
                                  a server, but are linked into an application) are easily possible.
                                  
                                  Goals:
                                      * A validating recursive DNS resolver.
                                      * Code diversity in the DNS resolver monoculture.
                                      * Drop-in replacement for BIND apart from config.
                                      * DNSSEC support.
                                      * Fully RFC compliant.
                                      * High performance, even with validation enabled.
                                      * Used as: stub resolver, full caching name server, resolver library.
                                      * Elegant design of validator, resolver, cache modules.
                                            o provide the ability to pick and choose modules.
                                      * Robust.
                                      * In C, open source: The BSD license.
                                      * Smallest as possible component that does the job.
                                      * Stub-zones can be configured (local data or AS112 zones).
                                  
                                  Non-goals:
                                      * An authoritative name server.
                                      * Too many Features.
                                  
                                  WWW: https://www.nlnetlabs.nl/projects/unbound
                                  
                                  
                                  C 1 Reply Last reply Jan 24, 2023, 4:54 PM Reply Quote 1
                                  • C
                                    cmcdonald Netgate Developer @nimrod
                                    last edited by Jan 24, 2023, 4:54 PM

                                    @nimrod Can you now try reinstalling pfBlockerNG-devel on 22.05/2.6, and repeat the above command pkg info "py*" unbound

                                    Need help fast? https://www.netgate.com/support

                                    N 1 Reply Last reply Jan 24, 2023, 5:00 PM Reply Quote 0
                                    • N
                                      nimrod @cmcdonald
                                      last edited by Jan 24, 2023, 5:00 PM

                                      @cmcdonald said in pfBlockerNG-devel v3.1.0_19/10:

                                      @nimrod Can you now try reinstalling pfBlockerNG-devel on 22.05/2.6, and repeat the above command pkg info "py*" unbound

                                      I reinstalled it and here is the output:

                                      [2.6.0-RELEASE][admin@pfSense.home.arpa]/root: pkg info "py*" unbound
                                      py38-maxminddb-2.0.3
                                      py38-ply-3.11
                                      py38-setuptools-57.0.0
                                      py38-sqlite3-3.8.12_7
                                      py39-maxminddb-2.0.3
                                      py39-setuptools-57.0.0
                                      py39-sqlite3-3.9.9_7
                                      python38-3.8.12_1
                                      python39-3.9.9
                                      unbound-1.13.2
                                      
                                      
                                      C 1 Reply Last reply Jan 24, 2023, 5:01 PM Reply Quote 0
                                      • C
                                        cmcdonald Netgate Developer @nimrod
                                        last edited by Jan 24, 2023, 5:01 PM

                                        @nimrod That should be correct now. Clear the unbound errors and try again.

                                        Need help fast? https://www.netgate.com/support

                                        N B 2 Replies Last reply Jan 24, 2023, 5:07 PM Reply Quote 2
                                        • N
                                          nimrod @cmcdonald
                                          last edited by Jan 24, 2023, 5:07 PM

                                          @cmcdonald said in pfBlockerNG-devel v3.1.0_19/10:

                                          @nimrod That should be correct now. Clear the unbound errors and try again.

                                          Yup. That fixed it. Thank you sir.

                                          🔒 Log in to view

                                          1 Reply Last reply Reply Quote 1
                                          40 out of 77
                                          • First post
                                            40/77
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.