Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfblocker not downloading ASN list

    Scheduled Pinned Locked Moved General pfSense Questions
    18 Posts 6 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S
      stephenw10 Netgate Administrator
      last edited by

      Is it in the AppleASN alias file or in the actual table?

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @michmoor
        last edited by johnpoz

        @michmoor I think it tries to download from here api.bgpview.io

        Currently getting a 500 error from them

        They seem to be down.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        JonathanLeeJ M 2 Replies Last reply Reply Quote 2
        • JonathanLeeJ
          JonathanLee @johnpoz
          last edited by

          @johnpoz is this still down?? Does he have a secondary mirror option? Primary only??

          Make sure to upvote

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @JonathanLee
            last edited by johnpoz

            @JonathanLee the website directly seems to answer now - but horrible slow...

            And if try to use the api, still getting

            2024-02-29_020429.jpg

            And if you search just on the main page for something you get this

            page.jpg

            So yeah I would say its still down, there are other places to lookup such info.. For example https://asnlookup.com/asn/AS714/ or https://www.bigdatacloud.com/asn-lookup/714 or https://bgp.he.net/AS714#_prefixes or just something like this

            thisway.jpg

            But I am not aware of pfblocker having a backup location to use if that one doesn't answer or is sluggish, etc. I would assume they will be back shortly..

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 1
            • M
              michmoor LAYER 8 Rebel Alliance @johnpoz
              last edited by

              @johnpoz
              Nice catch John.
              I do wonder how large the database is and if downloading it onto local is possible. It’s an option for those who have large local storage. A diff is done say monthly between local and website and download the changes. Ehh just a thought not sure on what the policies are with the website.

              Firewall: NetGate,Palo Alto-VM,Juniper SRX
              Routing: Juniper, Arista, Cisco
              Switching: Juniper, Arista, Cisco
              Wireless: Unifi, Aruba IAP
              JNCIP,CCNP Enterprise

              J johnpozJ 2 Replies Last reply Reply Quote 0
              • J
                jrey @michmoor
                last edited by

                @michmoor
                Not an issue with the size, - the API only pulls the prefixes for the given ASN so there is no issue downloading an ASN in this regard.
                On their side, the ASN's are sync'd almost instantly when the ranges (prefixes) are changed upstream.

                Their "Mock Servers" are current responding as expected, but as noted the production servers are currently in a bad state.

                Dashboard is showing the failures here as I would expect in cases like this, and nothing bad happens, just continues to use the previous values.

                Screen Shot 2024-02-29 at 9.33.01 AM.png

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @michmoor
                  last edited by

                  @michmoor I was able to get to https://bgp.tools/as/714#prefixes

                  But man did it take a while..

                  And via api url still showing a 500 error..

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  M 1 Reply Last reply Reply Quote 0
                  • M
                    michmoor LAYER 8 Rebel Alliance @johnpoz
                    last edited by

                    @johnpoz
                    Appreciate the assist. Went to your link - https://bgp.tools/as/714#prefixes - I got the prefixes and did a bulk import for the alias.
                    Works without issue as a workaround to the issue with pfBlocker.

                    Firewall: NetGate,Palo Alto-VM,Juniper SRX
                    Routing: Juniper, Arista, Cisco
                    Switching: Juniper, Arista, Cisco
                    Wireless: Unifi, Aruba IAP
                    JNCIP,CCNP Enterprise

                    johnpozJ 1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator @michmoor
                      last edited by

                      @michmoor not sure I would call it an issue with pfblocker - seems more to me an issue with the site that pfblocker uses to get the info ;) But yeah for sure that is a work around until such time that site is fully operational again..

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      J M 2 Replies Last reply Reply Quote 0
                      • J
                        jrey @johnpoz
                        last edited by

                        @johnpoz said in pfblocker not downloading ASN list:

                        seems more to me an issue with the site that pfblocker uses to get the info

                        which is back running as of about 15 minutes ago, albeit still a little sluggish.

                        johnpozJ 1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator @jrey
                          last edited by

                          @jrey I think they are still having major problems..

                          I just got this trying to do a search for asn off their main page

                          Whoops, looks like something went wrong.

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          J 1 Reply Last reply Reply Quote 0
                          • J
                            jrey @johnpoz
                            last edited by

                            @johnpoz

                            didn't try that 😊 -
                            only tried the api calls and were/are responding (little slower than what I would call "normal" but a response at least) That's all pfblocker uses

                            https://api.bgpview.io/asn/714/prefixes

                            {"status":"ok","status_message":"Query was successful","data":{"ipv4_prefixes":[{"prefix":"17.0.0.0\/8","ip":"17.0.0.0","cidr":8,"roa_status":"None","name
                            
                            etc, etc 
                            
                            johnpozJ 1 Reply Last reply Reply Quote 0
                            • johnpozJ
                              johnpoz LAYER 8 Global Moderator @jrey
                              last edited by

                              @jrey said in pfblocker not downloading ASN list:

                              https://api.bgpview.io/asn/714/prefixes

                              yeah that did respond.. Good that they fix the api before the main site ;) But yeah it was a bit sluggish but then it did pop with all the data..

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.8, 24.11

                              fireodoF 1 Reply Last reply Reply Quote 0
                              • M
                                michmoor LAYER 8 Rebel Alliance @johnpoz
                                last edited by

                                @johnpoz said in pfblocker not downloading ASN list:

                                not sure I would call it an issue with pfblocker

                                yes you are right :)
                                I do appreciate the help

                                Firewall: NetGate,Palo Alto-VM,Juniper SRX
                                Routing: Juniper, Arista, Cisco
                                Switching: Juniper, Arista, Cisco
                                Wireless: Unifi, Aruba IAP
                                JNCIP,CCNP Enterprise

                                1 Reply Last reply Reply Quote 0
                                • fireodoF
                                  fireodo @johnpoz
                                  last edited by

                                  @johnpoz said in pfblocker not downloading ASN list:

                                  @jrey said in pfblocker not downloading ASN list:

                                  https://api.bgpview.io/asn/714/prefixes

                                  yeah that did respond.. Good that they fix the api before the main site ;) But yeah it was a bit sluggish but then it did pop with all the data..

                                  This morning there where again trouble with bgpview ...

                                   /usr/local/bin/curl -A "pfSense/pfblocker cURL download agent-ecd69ce851584cc71xxx" -sS1 https://api.bgpview.io/asn/53667/prefixes > /tmp/pfbtemp10_15438 
                                  .. Failed to download ASN
                                  restore bk file
                                  . completed ..
                                  

                                  (error repeated 5 times)
                                  Seems there are some work underway ... I guess ...

                                  Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                                  SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                                  pfsense 2.8.0 CE
                                  Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                                  J 1 Reply Last reply Reply Quote 0
                                  • J
                                    jrey @fireodo
                                    last edited by

                                    @fireodo

                                    All I can say is that at 01:20:13 Eastern it was working fine

                                    .. completed (Download Valid)
                                    removing bk file
                                    . completed ..

                                    and my next scheduled run isn't for a few hours.
                                    (yesterday log file showed a couple of ASN's failing,
                                    but for the most part ~95% of them they were fine.
                                    0 failures in the run earlier today.

                                    fireodoF 1 Reply Last reply Reply Quote 0
                                    • fireodoF
                                      fireodo @jrey
                                      last edited by

                                      @jrey said in pfblocker not downloading ASN list:

                                      All I can say is that at 01:20:13 Eastern it was working fine

                                      Ah, OK - thanks!

                                      Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                                      SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                                      pfsense 2.8.0 CE
                                      Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post
                                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.