Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    adult content

    Scheduled Pinned Locked Moved pfBlockerNG
    24 Posts 5 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      rcoleman-netgate Netgate @reynold
      last edited by

      @reynold You're probably hitting a different resource limit.

      Check System > Advanced and click on "Firewall & NAT" and look at your "Firewall Maximum Table Entries" value. Mine is set to 2000000

      Ryan
      Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
      Requesting firmware for your Netgate device? https://go.netgate.com
      Switching: Mikrotik, Netgear, Extreme
      Wireless: Aruba, Ubiquiti

      R 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @reynold
        last edited by

        @reynold You can download the file from pfBlocker’s feed page. I know it takes over 1 GB disk space for pfSense to extract, but I don’t know the actual disk or RAM usage.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote 👍 helpful posts!

        1 Reply Last reply Reply Quote 0
        • R
          reynold @rcoleman-netgate
          last edited by

          @rcoleman-netgate
          Mine is set also to 2000000

          R 1 Reply Last reply Reply Quote 0
          • R
            reynold @reynold
            last edited by

            I'm using steven black lists.
            It seems working.
            But I'm not able to block pornhub.
            Could you help me?
            I have already tried with custom blacklist but it did not work

            provelsP 1 Reply Last reply Reply Quote 0
            • provelsP
              provels @reynold
              last edited by provels

              @reynold
              FWIW, I use the UT1 adult list and that doesn't block Pornhub either, so it's not the answer. But if you want to try it, I would disable your other lists, start with the UT1 adult list and see how memory looks, then start adding other UT1 categories and other you want and note the effects on memory, That said I run UT1, the old Shallalist and quite a few others and my memory shows only 7% of 16GB.

              Peder

              MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
              BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

              R 1 Reply Last reply Reply Quote 0
              • R
                reynold @provels
                last edited by

                @provels ok. I will try.
                But is there a way to block pornhub?
                Why is that not blocked?

                R S 2 Replies Last reply Reply Quote 0
                • R
                  rcoleman-netgate Netgate @reynold
                  last edited by

                  @reynold said in adult content:

                  But is there a way to block pornhub?

                  Block ASNs.

                  https://www.peeringdb.com/asn/55222 that is the parent company's ASN. Aylo, née MindGeek.

                  Ryan
                  Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                  Requesting firmware for your Netgate device? https://go.netgate.com
                  Switching: Mikrotik, Netgear, Extreme
                  Wireless: Aruba, Ubiquiti

                  R 1 Reply Last reply Reply Quote 0
                  • S
                    SteveITS Galactic Empire @reynold
                    last edited by

                    @reynold said in adult content:

                    block pornhub

                    Alternately, create hostname overrides for pornhub.com, www.pornhub.com, etc. pointing to 127.0.0.1 or some nonexistent IP.

                    Test with dig or nslookup.

                    Keep in mind any DNS based blocking assumes DNS over HTTPS is not being used. Here is a writeup of how to block DoH, in the pfSense PDF:
                    https://github.com/jpgpi250/piholemanual

                    Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                    When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                    Upvote 👍 helpful posts!

                    M 1 Reply Last reply Reply Quote 0
                    • M
                      mcury @SteveITS
                      last edited by mcury

                      These lists are pretty good:

                      https://github.com/StevenBlack/hosts

                      d24fcc0f-b67a-4e4b-81e0-80ce8bf9f3cc-image.png

                      You can select only porn if you want.

                      dead on arrival, nowhere to be found.

                      R 1 Reply Last reply Reply Quote 0
                      • R
                        reynold @mcury
                        last edited by

                        @mcury
                        I'm using that lists but i can not block pornhub

                        M provelsP 2 Replies Last reply Reply Quote 0
                        • M
                          mcury @reynold
                          last edited by

                          @reynold said in adult content:

                          I'm using that lists but i can not block pornhub

                          hm, that is weird because I can see pornhub in that list..

                          Are you sure sure that the hosts in your network are using Pfsense's DNS server?
                          Nothing using DOT or DOH to bypass the DNS server?

                          dead on arrival, nowhere to be found.

                          R 1 Reply Last reply Reply Quote 0
                          • R
                            reynold @rcoleman-netgate
                            last edited by

                            @rcoleman-netgate
                            It can be a solution but ASN blocking isn't dangerous?.
                            Unless its an ASN wholly owned by the public entity (facebook,google,nextlix) I could blackholing lots of sites

                            R 1 Reply Last reply Reply Quote 0
                            • R
                              reynold @mcury
                              last edited by

                              @mcury
                              I'm sure
                              I'm trying myself from lan
                              I can block many porn sites but pornhub seems to be impossible
                              Nslookup shows thar pornhub.com is correctly resolved.
                              If i try to resolve youporn it gives me 10.10.10.1 and that's ok. In fact it's blocked

                              M 1 Reply Last reply Reply Quote 0
                              • R
                                rcoleman-netgate Netgate @reynold
                                last edited by

                                @reynold In this case... Aylo's ONLY business is PornHub. Blocking their ASN should be "safe"

                                Ryan
                                Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                                Requesting firmware for your Netgate device? https://go.netgate.com
                                Switching: Mikrotik, Netgear, Extreme
                                Wireless: Aruba, Ubiquiti

                                1 Reply Last reply Reply Quote 0
                                • M
                                  mcury @reynold
                                  last edited by

                                  @reynold said in adult content:

                                  I can block many porn sites but pornhub seems to be impossible

                                  If you are on Windows, try this: ipconfig /flushdns and test again, just to make sure that cache is not the problem.

                                  If the problem persists after that, you could create a custom list to include along with the others you already have.
                                  As far as I remember, you can create that list in a .txt file and put somewhere.
                                  The downside of this is that you would probably need to enable TLD which increases the memory usage by a lot..

                                  dead on arrival, nowhere to be found.

                                  R 1 Reply Last reply Reply Quote 0
                                  • R
                                    reynold @mcury
                                    last edited by

                                    @mcury cache is not the problem and i enabled tld already.
                                    I do not know how to create custom txt list and where to puts

                                    M 1 Reply Last reply Reply Quote 0
                                    • M
                                      mcury @reynold
                                      last edited by

                                      @reynold

                                      It seems that you don't need to create a .txt file, try like this:
                                      https://forum.netgate.com/post/834813

                                      dead on arrival, nowhere to be found.

                                      R 1 Reply Last reply Reply Quote 0
                                      • R
                                        reynold @mcury
                                        last edited by

                                        @mcury
                                        I can not find that GUI, i think it's an older version

                                        R M 2 Replies Last reply Reply Quote 0
                                        • R
                                          rcoleman-netgate Netgate @reynold
                                          last edited by

                                          @reynold said in adult content:

                                          I can not find that GUI, i think it's an older version

                                          if you are running an older release of pfBlocker you should update to current.

                                          Ryan
                                          Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                                          Requesting firmware for your Netgate device? https://go.netgate.com
                                          Switching: Mikrotik, Netgear, Extreme
                                          Wireless: Aruba, Ubiquiti

                                          R 1 Reply Last reply Reply Quote 0
                                          • M
                                            mcury @reynold
                                            last edited by

                                            @reynold said in adult content:

                                            I can not find that GUI, i think it's an older version

                                            1c7a3b8b-5fd3-4fbd-b30f-c3fd6afc3c87-image.png

                                            1da120e4-2663-4c84-993d-0dd21189b8ec-image.png

                                            10fecc40-372a-4b3a-88f3-30f92aaa5604-image.png

                                            Remember to set Action to Unbound and run update in pfB.

                                            dead on arrival, nowhere to be found.

                                            R 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.