Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlockerNG v3.2.0_9

    Scheduled Pinned Locked Moved pfBlockerNG
    17 Posts 9 Posters 4.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      TheNarc @BBcan177
      last edited by TheNarc

      @BBcan177 Thank you! Out of curiosity, will this update include support for AdBlock style feeds now needed for OISD and referenced here?

      Edit: Never mind, I found the PR and see that this update is specific to the MaxMind changes.

      1 Reply Last reply Reply Quote 2
      • M mcury referenced this topic on
      • keyserK
        keyser Rebel Alliance @BBcan177
        last edited by

        @BBcan177 Does that mean the -Devel track will start seeing new changes?

        Builtin syslog support for logging?
        Proper rotation of logfiles (so they dont get fully picked up again @ rotation by syslog-ng/telegraf and other logfile monitors?
        Perhaps full wildcard no AAAA filtering (top level or even intire “no AAAA”)

        Excellent package you are maintaining. Thank you for the great job you are doing

        -Keyser

        Love the no fuss of using the official appliances :-)

        UnoptanioU 1 Reply Last reply Reply Quote 1
        • UnoptanioU
          Unoptanio @keyser
          last edited by Unoptanio

          @keyser

          I received the communication via email from MaxMind.

          The change starts from May 1, 2024

          04fc57fb-87ec-427b-8149-b34eccc26bd5-image.png

          pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
          CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
          n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

          1 Reply Last reply Reply Quote 0
          • fireodoF
            fireodo
            last edited by

            Hi,

            until today 04.04.2024 no update to 3.2.0_9 available ... :-(

            Regards and thanks,
            fireodo

            Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
            SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
            pfsense 2.8.0 CE
            Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

            M 1 Reply Last reply Reply Quote 0
            • M
              mcury Rebel Alliance @fireodo
              last edited by

              @fireodo said in pfBlockerNG v3.2.0_9:

              Hi,

              until today 04.04.2024 no update to 3.2.0_9 available ... :-(

              Regards and thanks,
              fireodo

              3.2.0_8 just released for 23.09.1

              dead on arrival, nowhere to be found.

              BBcan177B fireodoF 2 Replies Last reply Reply Quote 1
              • BBcan177B
                BBcan177 Moderator @mcury
                last edited by

                @mcury yes for that pfSense version is _8

                "Experience is something you don't get until just after you need it."

                Website: http://pfBlockerNG.com
                Twitter: @BBcan177  #pfBlockerNG
                Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                1 Reply Last reply Reply Quote 3
                • MarinSNBM
                  MarinSNB
                  last edited by

                  Just updated to the _8 version and updated the Maxmind account number & license key (appreciate the heads up warning during initial reload progress logs and on the IP tab). Force reloaded IP/DNSBL afterwards and everything went smoothly. Thank you so much @BBcan177 for your efforts and hard work!

                  Netgate 6100 Max pfSense+
                  —>Unifi Aggregation/24 Pro PoE/24 PoE Enterprise switches
                  —> UCK2+
                  —> 3x U6E APs

                  1 Reply Last reply Reply Quote 0
                  • fireodoF
                    fireodo @mcury
                    last edited by

                    @mcury said in pfBlockerNG v3.2.0_9:

                    3.2.0_8 just released for 23.09.1

                    Updated the CE 2.7.2 to 3.2.0_8 too and everything fine.

                    Thanks again @BBcan177
                    regards, fireodo

                    Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                    SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                    pfsense 2.8.0 CE
                    Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                    UnoptanioU 1 Reply Last reply Reply Quote 0
                    • UnoptanioU
                      Unoptanio @fireodo
                      last edited by

                      @fireodo
                      pfSense 2.7.2. CE:

                      Before update:

                      fd2ae07c-44e7-449e-89dd-2bde0c825130-image.png

                      After Update to pfBlockerNG v3.2.0_8

                      635de178-76d2-4fd6-a8e9-be7f9fa20764-image.png

                      pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
                      CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
                      n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

                      fireodoF 1 Reply Last reply Reply Quote 0
                      • fireodoF
                        fireodo @Unoptanio
                        last edited by

                        @Unoptanio said in pfBlockerNG v3.2.0_9:

                        After Update to pfBlockerNG v3.2.0_8

                        Yes here you have to put your Maxmind Account ID (six numbers in my case). Look in your Maxmind account and you will find there your account ID.
                        Or do you want to ask something else?

                        Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                        SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                        pfsense 2.8.0 CE
                        Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                        UnoptanioU 2 Replies Last reply Reply Quote 1
                        • UnoptanioU
                          Unoptanio @fireodo
                          last edited by

                          @fireodo
                          OK done.
                          I entered the account id. Also in my case 6 digit number

                          pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
                          CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
                          n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

                          1 Reply Last reply Reply Quote 1
                          • UnoptanioU
                            Unoptanio @fireodo
                            last edited by

                            @fireodo

                            Excuse me,
                            Can you tell me why some sites are blocked by viewing this screen with the reason and other sites are blocked by displaying a totally black page with a dot in the center?

                            Can the black screen with the dot in the center be customized?

                            21b4519e-4f03-4618-ad7c-3e5c4dbbadcf-image.png

                            78aa884d-b469-4d09-ba5a-d1290c5df97d-image.png

                            pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
                            CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
                            n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

                            fireodoF GertjanG 2 Replies Last reply Reply Quote 0
                            • fireodoF
                              fireodo @Unoptanio
                              last edited by fireodo

                              @Unoptanio said in pfBlockerNG v3.2.0_9:

                              Can you tell me why some sites are blocked by viewing this screen with the reason and other sites are blocked by displaying a totally black page with a dot in the center?

                              Here is the explanation offered by BBcan177 some years ago:
                              "This is only displayed when a full Domain is blocked and not for an ADvert on a page! You can also create your own page to display any customizations. "

                              When a ADvert is blocked you see only that 1x1 pixel image.

                              Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                              SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                              pfsense 2.8.0 CE
                              Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                              1 Reply Last reply Reply Quote 0
                              • GertjanG
                                Gertjan @Unoptanio
                                last edited by

                                @Unoptanio said in pfBlockerNG v3.2.0_9:

                                Can the black screen with the dot in the center be customized?

                                Long story short : you can not and you will not break TLS == https.

                                In the good old days, it was ok if a site http://www.some-site.tld redirected the visitor to http://www.another-site.tld. It was great, and everybody trusted everybody and we were all happy.

                                Later on, for obvious reasons, https was introduced. For example : this site, the forum :

                                Your visiting https://forum.netgate.com/...... and your browser received a certificate from that server that says :

                                5691040b-826b-4789-bf84-db3aff4b9ea2-image.png

                                so all is well.

                                Now, back to pfBlockerng.
                                If a browser want to visit http://www.google.com and the host name google.com is listed in a DNSBL, pfBlockerng and you've selected "DNSBL Webserver" then pfBlockerng, by the bias of the resolver, will send to the browser the pfSense pfBlockerng web server IP to show you that the page was blocked.
                                Nice.
                                But wait ...... does your pfBlockerng has the certificate that says it is "google.com" ?
                                Do you think you can get one ? Do you own google.com ?
                                Noop to all this.
                                So, these days, modern browsers won't show the black pfBlockerng page (the one you've showed) at all. Just a big huge ugly error page.
                                The solution is :

                                eacb5ad2-3561-42d0-8888-ffb1a4f916e4-image.png

                                so the pfBlockerng won't show any informative pages anymore.
                                After all : you can't and don't want to break TLS = https.

                                If you have users on your network that actually visit crappy host names and still us http (port 80) then pfBlockerng is actually useful.
                                But also means you've a huge security issue : you've people on your network (LAN !!) using ancient technology. Things will go bad fast, have a talk with them, and if needed, throw them of your network.
                                Or block port 80 TCP all together.

                                No "help me" PM's please. Use the forum, the community will thank you.
                                Edit : and where are the logs ??

                                UnoptanioU 1 Reply Last reply Reply Quote 1
                                • UnoptanioU
                                  Unoptanio @Gertjan
                                  last edited by Unoptanio

                                  @Gertjan

                                  my config:
                                  22f0563f-1930-4c09-99cd-c0637fe018b9-image.png

                                  Do I change everything to: Null Block (logging) ?

                                  I'm trying...

                                  when I do SAVE it doesn't save the changes in the combo lists and shows me DNSBL webserver/VIP (global)
                                  43df13aa-b3b0-4a70-86c0-2849b2a0445d-image.png

                                  going inside the tab it seems to have saved.
                                  180e5334-5755-4f1f-a363-b212dd55f6f1-image.png

                                  pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
                                  CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
                                  n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

                                  1 Reply Last reply Reply Quote 0
                                  • S
                                    SteveITS Galactic Empire @BBcan177
                                    last edited by

                                    @BBcan177 As per https://forum.netgate.com/topic/179060/pfblockerng-sync-not-working/54 (and https://redmine.pfsense.org/issues/14189) the account ID doesn't sync to the HA backup without adding the one line fix "pfblockerng_sync_on_changes();" to pfblockerng.php (and waiting for cron to run).

                                    Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                    When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                                    Upvote 👍 helpful posts!

                                    1 Reply Last reply Reply Quote 1
                                    • S SteveITS referenced this topic on
                                    • BBcan177B BBcan177 unpinned this topic on
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.