Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Feed name crossed out in alerts.

    Scheduled Pinned Locked Moved pfBlockerNG
    6 Posts 3 Posters 47 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Z Offline
      Zaketis
      last edited by

      Hey Everyone,
      Looking for clarification on what exactly this is telling me.
      Screenshot 2025-10-23 094318.png

      See this on the alerts page.
      I see this for connections that were allowed Aswell as ones that were blocked

      Thanks,

      1 Reply Last reply Reply Quote 0
      • U Offline
        Uglybrian
        last edited by

        I have come to find that it means the list is no longer being used. In DNSBL if i was to change from Adaway to Steven Black Ads. The old Adaway hits would have a line through them like you have.

        Z 1 Reply Last reply Reply Quote 0
        • Z Offline
          Zaketis @Uglybrian
          last edited by

          @Uglybrian
          In this example that's not the case.
          The ET_Block list is still in use and continuing to block traffic as expected.

          Now if I download the list. I cannot find the IP or Range of IPs.
          So maybe it is showing that this IP/range used to be on this list but based on the latest version it's not so falls under this new list instead??

          BBcan177B 1 Reply Last reply Reply Quote 0
          • BBcan177B Offline
            BBcan177 Moderator @Zaketis
            last edited by

            @Zaketis

            The event that you see if saying that it was originally block via ET feed. Then later on its now being blocked via GeoIP feed.

            When deduplication is enabled, it will remove all duplicates. And as feeds continue to be downloaded, IPs can change by cidr ranges as you see in this example. Also Aggregation can have an affect on CIDR ranges.

            "Experience is something you don't get until just after you need it."

            Website: http://pfBlockerNG.com
            Twitter: @BBcan177  #pfBlockerNG
            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

            Z 1 Reply Last reply Reply Quote 0
            • Z Offline
              Zaketis @BBcan177
              last edited by

              @BBcan177

              Thanks for the confirmation.

              Another quick sanity check.
              The event that i screenshot was a permit event.
              The ET_Block list is associated with a deny rule.

              De-duplication won't affect permit rules correct?
              Deny rule is configured as Alias Deny
              Permit rule uses geo IP and is set to Alias Permit.

              BBcan177B 1 Reply Last reply Reply Quote 0
              • BBcan177B Offline
                BBcan177 Moderator @Zaketis
                last edited by

                @Zaketis dedup is only Deny Feeds which would also include and GeoIP lists. Aggregation works in separate silos for each type ie: permit or deny etc...

                "Experience is something you don't get until just after you need it."

                Website: http://pfBlockerNG.com
                Twitter: @BBcan177  #pfBlockerNG
                Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.