Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    TDL option in pfBlockerNG makes reload run for ever

    Scheduled Pinned Locked Moved Plus 23.01 Development Snapshots (Retired)
    5 Posts 4 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • motivioM
      motivio
      last edited by motivio

      When I have Wildcard Blocking (TLD) on in pfBlockerNG and run a reload I get it never gets finished.
      It just hangs there with high CPU load on "grep -vF -f /tmp/dnsbl_tld_remove /tmp/pfbtemp3_71192".
      With the 22.05 version this was never a problem.

      ....
      Assembling DNSBL database...... completed [ 01/12/23 18:29:05 ]
      Adding DNSBL Unbound mode (Resolver adv. setting)
      TLD:
      Blocking full TLD/Sub-Domain(s)... |cm|ml|fit|live|beauty|top|su|gq|monster|surf|party|click|link|gdn|study|men| completed
      TLD analysis....xxxxxxxxxxx completed [ 01/12/23 18:30:10 ]

      ** TLD Domain count exceeded. [ 400000 ] All subsequent Domains listed as-is **

      TLD finalize.
      ....

      PID USERNAME PRI NICE SIZE RES STATE C TIME WCPU COMMAND
      41008 root 133 0 479M 434M CPU1 1 14:31 96.78% grep -vF -f /tmp/dnsbl_tld_remove /tmp/pfbtemp3_71192

      J 1 Reply Last reply Reply Quote 4
      • J
        joedan @motivio
        last edited by joedan

        @motivio

        Can also confirm I experienced this on 23.01.r.20230202.0019 / pfBlockerNG-devel 3.2.0.

        This was prior to upgrading to the final RC version 23.01.r.20230202.1645

        It eventually finished just took hours instead of the usual 1-2 mins.

        7fad8b1e-6847-43b6-91e9-3c010c1d8347-image.png

        J 1 Reply Last reply Reply Quote 0
        • E emikaadeo referenced this topic on
        • E emikaadeo referenced this topic on
        • E
          emikaadeo
          last edited by emikaadeo

          Maybe @BBcan177 will have a time to look into this.
          I will upgrade 22.05-RELEASE (amd64) to 23.01-RC today and see if this will show up on my box.

          1 Reply Last reply Reply Quote 0
          • J
            joedan @joedan
            last edited by

            @joedan

            I am now unsure if the TLD finalize actually worked as I don't recall the DNSBL count being so high in the widget. I could swear it used to be the final number (445047) and not the original (999933) - but I am not 100% sure.

            c54396c6-ee36-4e00-a07c-f6009d66c25e-image.png
            b2c07d9c-b48e-435d-9a70-54fca9d3116a-image.png

            S 1 Reply Last reply Reply Quote 0
            • S
              SteveITS Galactic Empire @joedan
              last edited by

              See https://forum.netgate.com/topic/177504/v-3-2-0-with-pfsense-23-01-rc-20230202/9
              "If you can easily reproduce this, try the following patch in the system patches package"

              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
              Upvote 👍 helpful posts!

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.