• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

DNS Blacklist, New Package! Check it out.

pfSense Packages
56
153
127.6k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    Supermule Banned
    last edited by Oct 6, 2009, 3:33 PM

    Exactly. :)

    Keep it up! You are on the right track….IP's change. Domainnames do not as often....So it is a good argument.

    1 Reply Last reply Reply Quote 0
    • C
      cybrsrfr
      last edited by Oct 6, 2009, 3:47 PM

      The problem is the list. As I stated before it has to be created ethically. That is compiled from free lists where the owners give their permission.

      I will not commit something to pfSense that makes me an accessory to stealing. That is why I refused to commit the package with the previous list. If I did this I would expect to get my commit authority revoked.

      It is not impossible to find lists that are free for any use and supplement them, and improve them with your own domains you and others find while searching.

      1 Reply Last reply Reply Quote 0
      • X
        xa0z
        last edited by Oct 6, 2009, 3:51 PM

        That is exactly what I'm doing.  I'm not worried about the urlBlacklists database anymore.  I am just saying that I'm getting the database taken care of on my own, and it will be greatly categorizied.

        1 Reply Last reply Reply Quote 0
        • D
          Davc
          last edited by Oct 7, 2009, 1:27 AM

          I think this is a good project, if the DNS Blacklist is good and effectively use. Surely there will be people supported and willing to donate some subscription fee to maintain the Blacklist and the project itself in this Pfsense forum/members.

          I am no expert in here, but there are people who might (already) using OpenDNS to filter, as long as this project don't run the same track as the OpenDNS or able to offer more than OpenDNS. I think there are light on this projects.

          Good Work !!  ;)

          1 Reply Last reply Reply Quote 0
          • J
            jan.gestre
            last edited by Oct 7, 2009, 6:02 AM

            Hi Davc,

            I've tried DNS blacklist in one of my pfSense box but it broke the dns forwarder service, after installation the dnsmasq service stopped and can't be restarted even after repeated tries and reboot. I uninstalled the aforementioned package but I still can't start the dnsmasq service,I had to examine other working boxes to see what files have been added or changed by the DNS blacklist package, it added the dnsmasq.conf which I've deleted and my dnsmasq service finally started.

            Did I missed something?

            Regards,

            Jan

            1 Reply Last reply Reply Quote 0
            • C
              cybrsrfr
              last edited by Oct 7, 2009, 6:13 AM

              When you tried to start dnsmasq. If you would have looked at the Diagnostics: System logs: System and looked for errors inr regards to dnsmasq then you should be ablt to find a description why it refused to start.

              1 Reply Last reply Reply Quote 0
              • J
                jigpe
                last edited by Oct 7, 2009, 8:24 AM

                Good job :)

                I have Q.. How to block HTTPS? (except legit HTTPS)?

                jigp

                1 Reply Last reply Reply Quote 0
                • D
                  Davc
                  last edited by Oct 7, 2009, 4:48 PM

                  Mine is running fine.

                  1.2.3-RC2
                  built on Sat Jul 18 19:19:52 EDT 2009
                  FreeBSD 7.2-RELEASE-p2 i386

                  DNS Blacklist 0.2.4

                  Yes, after the installation of DNS Blacklist. I have to manual restart the services.

                  My Box run in Bridge mode, I guess yours are different in NAT mode.

                  Davc

                  1 Reply Last reply Reply Quote 0
                  • X
                    xa0z
                    last edited by Oct 7, 2009, 5:23 PM

                    After installing DNS Blacklist you shouldn't be required to restart dnsmasq as nothing is edited that pertains to dnsmasq at the time.  DNS Blacklist adds the dnsmasq.conf, and dnsmasq.blacklist.conf files into /usr/local/etc/.  When DNS Blacklist is enabled it adds a string into dnsmasq.conf to load the dnsmasq.blacklist.conf file, then restarts dnsmasq.  Any of the categories you select are entered within the dnsmasq.blacklist.conf file and that is what allows us to filter dns querys to the local server.

                    I am in no way out to seek any money from anyone for the blacklist database I'm putting together.  I can maintain a "main blacklist" but users would be free to add their own domains that aren't already listed.  Here soon I'll work on adding a custom Blacklist/Whitelist text area for you to enter your own on the fly.

                    If you want to block all https, you need to put a block on dport:443, that isn't associated with DNS Blacklist.

                    1 Reply Last reply Reply Quote 0
                    • J
                      jigpe
                      last edited by Oct 8, 2009, 7:58 AM

                      | If you want to block all https, you need to put a block on dport:443, that isn't associated with DNS Blacklist.

                      • I dont want to block 443 from Firewall LAn.. Some users needs to access legitimate https sites…. Kindly show us the right way xa0z? Thanks

                      jigp |

                      1 Reply Last reply Reply Quote 0
                      • B
                        boblmartens
                        last edited by Oct 9, 2009, 3:21 PM

                        I can't really thank you enough for putting in the effort for this package. This is exactly what my place of employment has been looking for to push us off of using WatchGuard Fireboxes and moving to a custom-built firewall running pfSense.

                        Thanks, and if you need any help, let me know!

                        1 Reply Last reply Reply Quote 0
                        • M
                          mastablastaz
                          last edited by Oct 9, 2009, 4:01 PM

                          Is that package the same as using squid with 0 cache + squidGuard using the urlblacklist.com filter?

                          1 Reply Last reply Reply Quote 0
                          • X
                            xa0z
                            last edited by Oct 9, 2009, 5:26 PM

                            Not really, but the same concept mainly.  We're not using proxies, and are just making hostnames that you don't want allowed on your network to resolve to a specific IP rather than loading a proxy, etc.

                            So for instance, if you have  facebook.com  added to the category of denied hosts, then if anyone tried to resolve the forementioned host name then it would resolve to the IP I currently have set in the config, which is a Google IP.  So all requests would be for example like so…    http://www.facebook.com/games/mafiawars, would actually load http://www.google.com/games/mafiawars, which would fail, and alert you so.

                            I do have improvement ideas I'd like to implement in, but I won't be able to submit/commit them until mcrane is ready to do so and currently he has other projects he's working on.

                            1 Reply Last reply Reply Quote 0
                            • T
                              Tracktor
                              last edited by Oct 10, 2009, 11:54 AM

                              As I understand the LAN DNS must be the pfsense DNS forwarder in order to make this package work?

                              10X for your effort

                              1 Reply Last reply Reply Quote 0
                              • X
                                xa0z
                                last edited by Oct 10, 2009, 10:15 PM

                                Yes, in order to use this you MUST do 1 of two things…

                                1:  Make sure ALL clients on your LAN have the pfSense Gateway IP as their DNS IP.

                                2:  Set any and all connections that pass through on port 53, to bind back to the router IP on port 53.

                                1 Reply Last reply Reply Quote 0
                                • S
                                  Supermule Banned
                                  last edited by Oct 11, 2009, 2:45 PM

                                  Are there any sense in doing this, if other DNS Services (OpenDNS) will override the settings on this??

                                  1 Reply Last reply Reply Quote 0
                                  • X
                                    xa0z
                                    last edited by Oct 11, 2009, 5:41 PM

                                    In order for OpenDNS, and other DNS Services to work, you need to use their IP Address as your DNS Server IP.

                                    The concept of OpenDNS and DNSBlacklist is about the same except the changes made to DNSBlacklist are local (on the system)

                                    If you run DNS Blacklist, or other DNS Services like OpenDNS you can prevent people from loading other DNS Servers by forcing ALL outbound connections to port 53 to stop at the pfSense box.  This way no matter where they try to resolve host names, it will always use the DNS Server on the pfSense box, be that the DNS Forwarder of OpenDNS, etc.

                                    1 Reply Last reply Reply Quote 0
                                    • S
                                      Supermule Banned
                                      last edited by Oct 11, 2009, 5:48 PM

                                      How do you specific prevent people from doing that???

                                      How to in Pfsense???

                                      1 Reply Last reply Reply Quote 0
                                      • X
                                        xa0z
                                        last edited by Oct 11, 2009, 6:51 PM Oct 11, 2009, 6:02 PM

                                        Highlighted in RED.

                                        1 Reply Last reply Reply Quote 0
                                        • S
                                          Supermule Banned
                                          last edited by Oct 11, 2009, 6:45 PM

                                          I cant see anything….

                                          1 Reply Last reply Reply Quote 0
                                          29 out of 153
                                          • First post
                                            29/153
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.