Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlocker remove Shalla and UT1

    Scheduled Pinned Locked Moved pfBlockerNG
    12 Posts 4 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mak73
      last edited by mak73

      Well it hangs here. I tried with Big porn list, and waited, and waited .... and at the end it does not block all sites, so i installed OISD NWFW list, and than i could block a lot of them.
      https://oisd.nl/setup/pfblockerng

      Social Media does not block Facebook, i blocked it in TLD with wildcard option enabled.

      And Shalla? Why is there, i don't know.
      Without UT1 works everything works better. I love pfBlocker.

      M M GertjanG 3 Replies Last reply Reply Quote 0
      • M
        michmoor LAYER 8 Rebel Alliance @mak73
        last edited by

        @mak73 UT1 filtering is....Ok. Its free and community driven so the list is only as good as who contributes to it. A commercial solution will always be superior. That said Shalla is of course gone for a few years but the pfblocker maintainer will need to update the package to remove it. I know there are Redmines for this effort.
        Secondly, if you are looking for URL filtering via UT1 and assuming this is a business deployment i highly recommend using something else - UT1 ain't it.

        Firewall: NetGate,Palo Alto-VM,Juniper SRX
        Routing: Juniper, Arista, Cisco
        Switching: Juniper, Arista, Cisco
        Wireless: Unifi, Aruba IAP
        JNCIP,CCNP Enterprise

        1 Reply Last reply Reply Quote 1
        • M
          mak73 @mak73
          last edited by

          @mak73 well, i am ok with all what pfblocker provides. And i know that if i want to use something other, app blocker or similar, than i have to pay AdGuard or similar. THX

          1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan @mak73
            last edited by

            @mak73 said in pfBlocker remove Shalla and UT1:

            I tried with Big porn list, and waited, and waited

            Easy solution Don't use that one - it's way to big.
            Files - lists - are downloaded by pfBlockerng ... and pfBlockerng is nothing more or less then PHP scripts. The PHP interpreter can't use "all RAM", its memory size is (very) limited.

            The default PHP memory is ok when you have a pfSense with 32 Gbytes of RAM.

            My 4100 has 4 Gbytes, and PHP has reserved for its own use :

            bb590853-0386-4f79-aedb-7a1f3baea4ec-image.png

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            M 2 Replies Last reply Reply Quote 1
            • M
              mak73 @Gertjan
              last edited by

              @Gertjan THX, i gave up on those two list (UT1 and Shalla)s. I just found blocking lists, and bind it.
              The others are working, with 8 GB RAM.

              1 Reply Last reply Reply Quote 0
              • M
                mak73 @Gertjan
                last edited by

                @Gertjan I found this one now:
                https://forum.netgate.com/topic/179185/php-memory-allocation-error-in-pfblockerng-dnsbl/7

                GertjanG 1 Reply Last reply Reply Quote 0
                • GertjanG
                  Gertjan @mak73
                  last edited by

                  @mak73 said in pfBlocker remove Shalla and UT1:

                  @Gertjan I found this one now:
                  https://forum.netgate.com/topic/179185/php-memory-allocation-error-in-pfblockerng-dnsbl/7

                  Oh, yeah, the question pops up often.
                  Raising the memory is a workaround, and then the next problem pops up which is also PHP related : If you need to sort out, list, merge, filter, and file create, use whatever you want, but do NOT take PHP to do it.
                  Guess what : pfBlockerng is written mostly with PHP.
                  So, with much memory, PHP will finish the task. It will take 'ages', and all this time the processor spikes to 100 %, which isn't a good thing for the basic firewall router's main occupation : doing firewall and routing.

                  No "help me" PM's please. Use the forum, the community will thank you.
                  Edit : and where are the logs ??

                  M 1 Reply Last reply Reply Quote 1
                  • M
                    mak73 @Gertjan
                    last edited by

                    @Gertjan No, i didn't make it, and i will not. I am also sceptical about it.
                    I will just not use thoes lists, or just a slammler ones.

                    Thank you

                    1 Reply Last reply Reply Quote 0
                    • S
                      smolka_J @Gertjan
                      last edited by

                      @Gertjan With enough RAM and a little tweaking, I have both Shallalist + Porn and UT1 + Adult running and loading just fine and both are the largest out of all other feed I have. After the maintainer had to step away from Shallalist and site went down, I saved the last live copy of Shallalist from Wayback Machine web archives, then updated a handful of the category's lists I use filling my shallalist.tar.gz file up to 41MB then uploaded it to my pfSense boxes as a static file to the /var/db/pfblockerng/ directory and edited my /conf/config.xml file to point to the static file for the Shallalist feed download. On my "parental control" pfSense VMs with 12gb RAM, Shallalist with Porn and others activated currently blocks 3,648,492 domains/IPs as well as UT1 with Adult and others activated is blocking 4,286,200 domains/IPs with both large lists loading fine together in pfBlockerNG. Trying to use my same tweaked shallalist.tar.gz file with SquidGuard now that was an entirely different story, SquidGuard wasn't able to handle such large of lists too well at all after a certain size list was reached and choked itself.

                      M 1 Reply Last reply Reply Quote 1
                      • M
                        mak73 @smolka_J
                        last edited by

                        @smolka_J No tweaking , i don't like that.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.