Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlocker updater blocked by itself

    pfBlockerNG
    3
    4
    531
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Bob.DigB
      Bob.Dig LAYER 8
      last edited by Bob.Dig

      I think this has to go.
      Below are examples why lists couldn't be updated.
      I don't see the benefit but the problems.

      I get it that the firewall itself isn't bound to the rules created by pfblocker but this is madness.

       [ pfB_PRI4_v4 - AZORult_v4 ] Download Fail [ 07/17/23 04:46:44 ]
       [ 188.114.96.3 ] Firewall IP block found in: [ AZORult_v4 | 188.114.96.2/31 ] for HOST:azorult-tracker.net!
       [ 07/17/23 04:46:44 ]
        Restoring previously downloaded file contents... [ 07/17/23 04:46:45 ]
      
       [ pfB_UCEPROTECTNetwork_v4 - dnsblOne_v4 ] Download Fail [ 08/11/23 23:15:38 ]
       [ 41.208.71.58 ] Firewall IP block found in: [ pfB_Africa_v4 | 41.208.0.0/16 ] for HOST:wget-mirrors.uceprotect.net!
       [ 08/11/23 23:15:40 ]
        Restoring previously downloaded file contents... [ 08/11/23 23:15:40 ]
      

      I have an inbound block for Africa, not outbound...

      Also it looks like rsync isn't fully supported if at all.

       [ pfB_uceprotect_v4 - dnsbl1_v4 ] Download Fail [ 08/4/23 22:55:41 ]
        DNSBL, Firewall, and IDS (Legacy mode only) are not blocking download.
       [ 08/4/23 22:55:41 ]
      [PFB_FILTER - 2] Invalid URL (not allowed2) [ rsync-mirrors.uceprotect.net::RBLDNSD-ALL/dnsbl-1.uceprotect.net ] [ 08/5/23 10:10:22 ]
      
      GertjanG S 2 Replies Last reply Reply Quote 0
      • GertjanG
        Gertjan @Bob.Dig
        last edited by

        @Bob-Dig said in pfBlocker updater blocked by itself:

        I don't see the benefit but the problems.

        That one list/feed contains the IP of another list/feed ?
        That's not new.
        This :

        [ 188.114.96.3 ] Firewall IP block found in: [ AZORult_v4 | 188.114.96.2/31 ] for HOST:azorult-tracker.net
        

        and it backed out of the problem.
        That's good ? no ?
        Looks fine to me;

        Remember : the "quality" of the feeds, that's always a surprise.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        1 Reply Last reply Reply Quote 0
        • S
          SteveITS Galactic Empire @Bob.Dig
          last edited by

          @Bob-Dig said in pfBlocker updater blocked by itself:

          I have an inbound block for Africa, not outbound...

          I've seen deduplication do some unexpected things by removing blocks from aliases. Cant' say I've seen pfB reverse in and out. There are no floating rules being generated?

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote 👍 helpful posts!

          Bob.DigB 1 Reply Last reply Reply Quote 0
          • Bob.DigB
            Bob.Dig LAYER 8 @SteveITS
            last edited by

            @SteveITS said in pfBlocker updater blocked by itself:

            There are no floating rules being generated?

            I have some match rules in floating but to me it seems pfBlocker is checking on all blocked IPs and then is refusing updates from them, which is not good, especially for geoblocks.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.