Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to stop maxmind spam to pfsense alert?

    Scheduled Pinned Locked Moved pfBlockerNG
    11 Posts 5 Posters 1.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      MakOwner
      last edited by

      Is the answer to uninstall and point to a piehole?
      Ii don't mind being reminded but this is just ... and will someday cover up a serious alert I'm sure ...

      code_text

      pfBlockerNG MaxMind - MaxMind now requires a License Key! Review the IP tab: MaxMind settings for more information. @ 2024-02-08 10:15:29
      pfBlockerNG MaxMind - MaxMind now requires a License Key! Review the IP tab: MaxMind settings for more information. @ 2024-02-08 11:15:32
      pfBlockerNG MaxMind - MaxMind now requires a License Key! Review the IP tab: MaxMind settings for more information. @ 2024-02-08 12:15:26
      pfBlockerNG MaxMind - MaxMind now requires a License Key! Review the IP tab: MaxMind settings for more information. @ 2024-02-08 13:15:21
      pfBlockerNG MaxMind - MaxMind now requires a License Key! Review the IP tab: MaxMind settings for more information. @ 2024-02-08 14:15:27
      pfBlockerNG MaxMind - MaxMind now requires a License Key! Review the IP tab: MaxMind settings for more information. @ 2024-02-08 15:15:44
      pfBlockerNG MaxMind - MaxMind now requires a License Key! Review the IP tab: MaxMind settings for more information. @ 2024-02-08 16:15:35
      pfBlockerNG MaxMind - MaxMind now requires a License Key! Review the IP tab: MaxMind settings for more information. @ 2024-02-08 17:15:42
      pfBlockerNG MaxMind - MaxMind now requires a License Key! Review the IP tab: MaxMind settings for more information. @ 2024-02-08 18:15:42
      pfBlockerNG MaxMind - MaxMind now requires a License Key! Review the IP tab: MaxMind settings for more information. @ 2024-02-08 19:15:34
      pfBlockerNG MaxMind - MaxMind now requires a License Key! Review the IP tab: MaxMind settings for more information. @ 2024-02-08 20:15:29
      pfBlockerNG MaxMind - MaxMind now requires a License Key! Review the IP tab: MaxMind settings for more information. @ 2024-02-08 21:15:33
      pfBlockerNG MaxMind - MaxMind now requires a License Key! Review the IP tab: MaxMind settings for more information. @ 2024-02-08 22:15:35
      pfBlockerNG MaxMind - MaxMind now requires a License Key! Review the IP tab: MaxMind settings for more information. @ 2024-02-08 23:15:40
      pfBlockerNG MaxMind - MaxMind now requires a License Key! Review the IP tab: MaxMind settings for more information. @ 2024-02-09 00:15:42
      pfBlockerNG MaxMind - MaxMind now requires a License Key! Review the IP tab: MaxMind settings for more information. @ 2024-02-09 01:15:36
      pfBlockerNG MaxMind - MaxMind now requires a License Key! Review the IP tab: MaxMind settings for more information. @ 2024-02-09 02:15:40
      pfBlockerNG MaxMind - MaxMind now requires a License Key! Review the IP tab: MaxMind settings for more information. @ 2024-02-09 03:15:30
      pfBlockerNG MaxMind - MaxMind now requires a License Key! Review the IP tab: MaxMind settings for more information. @ 2024-02-09 04:15:38
      
      S 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @MakOwner
        last edited by

        @MakOwner You can change your update interval. AFAIK they only update the feed monthly anyway. And it won’t work without a license…and maybe https://forum.netgate.com/topic/186065/heads-up-new-suricata-7-0-3-package-is-coming-soon if I’m reading that correctly.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote 👍 helpful posts!

        1 Reply Last reply Reply Quote 0
        • Bob.DigB
          Bob.Dig LAYER 8
          last edited by

          Looks like we need another update for pfBlockerNG!

          1 Reply Last reply Reply Quote 0
          • NogBadTheBadN
            NogBadTheBad
            last edited by

            You could just sign up for a free license.

            Screenshot 2024-02-13 at 19.30.50.png

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            Bob.DigB 1 Reply Last reply Reply Quote 0
            • Bob.DigB
              Bob.Dig LAYER 8 @NogBadTheBad
              last edited by Bob.Dig

              @NogBadTheBad said in How to stop maxmind spam to pfsense alert?:

              You could just sign up for a free license.

              Na, take a look at what @SteveITS has "linked".

              NogBadTheBadN 1 Reply Last reply Reply Quote 0
              • NogBadTheBadN
                NogBadTheBad @Bob.Dig
                last edited by NogBadTheBad

                @Bob-Dig The link doesn't work.

                I'm running both and get no issues.

                Screenshot 2024-02-13 at 19.59.04.png

                Oh see what you mean now:-

                https://redmine.pfsense.org/issues/15240

                pfBlocker will just need to incorporate sending the accountID.

                Andy

                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                S 1 Reply Last reply Reply Quote 0
                • S
                  SteveITS Galactic Empire @NogBadTheBad
                  last edited by SteveITS

                  Sorry, Bill deleted the topic in favor of the release notes:
                  https://forum.netgate.com/topic/186071/suricata-package-v7-0-3-available-here-are-the-release-notes

                  "Special Notice: MaxMind recently changed their API for authentication when downloading updates for the GeoIP2 database. If you use the GeoIP2 option in Suricata, then you must execute a few specific actions to restore the GeoIP2 database download and update process.
                  ...
                  Enter your MaxMind Account ID in the new field provided above the previous License Key field."

                  I had tried a pfB update after I read that, and didn't have an issue though, so I was a bit confused...

                  Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                  When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                  Upvote 👍 helpful posts!

                  M 1 Reply Last reply Reply Quote 2
                  • M
                    MakOwner @SteveITS
                    last edited by

                    @SteveITS

                    I'm not using the IP related stuff, even tried hunting down as many settings as I could to disable updates but it just keeps spamming alerts. :/

                    Bob.DigB 1 Reply Last reply Reply Quote 0
                    • Bob.DigB
                      Bob.Dig LAYER 8 @MakOwner
                      last edited by

                      @MakOwner From what log-file is this exactly? I can't see it (for now).

                      johnpozJ 1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator @Bob.Dig
                        last edited by

                        When was this supposed to have changed... Looks like pfblocker updated just fine for me on the 6th of feb

                        And per maxmind I at least auth with the key on the 9th of feb..

                        maxmind.jpg

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                        S 1 Reply Last reply Reply Quote 0
                        • S
                          SteveITS Galactic Empire @johnpoz
                          last edited by

                          @johnpoz I believe the original (Suricata warning) post said January but wasn’t specific.

                          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                          Upvote 👍 helpful posts!

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.