Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS Blacklist, New Package! Check it out.

    Scheduled Pinned Locked Moved pfSense Packages
    153 Posts 56 Posters 135.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jideel
      last edited by

      There's also an error at boot :
      DNS Blacklist : Fatal error : cannot redeclare pkg_is_service_running() previously declared in /usr/local/pkg/cron.inc:37 in /usr/local/pkg/dnsblacklist.inc on line 35.
      I removed the cron package, and now it says the same message for another package (ip-blocklist).
      Can it interfere with other packages, and how to fix this message ?

      1 Reply Last reply Reply Quote 0
      • T
        tommyboy180
        last edited by

        The ip-blocklist package messes with the dns blacklist package. Sorry Mcrane!

        I am working on a fix right now.

        -Tom Schaefer
        SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

        Please support pfBlocker | File Browser | Strikeback

        1 Reply Last reply Reply Quote 0
        • T
          tommyboy180
          last edited by

          Fixed!

          -Tom Schaefer
          SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

          Please support pfBlocker | File Browser | Strikeback

          1 Reply Last reply Reply Quote 0
          • S
            shadowteller
            last edited by

            So question….

            I am using a brand new clean install on pfSense 1.2.3.  I install this as the only package.

            The Problem I am seeing is that every site gets redirected to the google.com page.  Has anyone ran into this issue and if so what is the fix?

            Regards

            1 Reply Last reply Reply Quote 0
            • T
              tommyboy180
              last edited by

              DNS blacklist domains are kind of out dated.
              Here's how you can update your lists
              1. Download latest from http://cri.univ-tlse1.fr/blacklists/index_en.php - download the blacklists.tar.gz
              2. Untar the archive
              3. Copy contents directly to /usr/local/www/packages/dnsblacklist/blacklists
              4. overwrite when prompted.
              5. In your browser re-save the DNS Blocklist settings to commit the new updates.

              -Tom Schaefer
              SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

              Please support pfBlocker | File Browser | Strikeback

              1 Reply Last reply Reply Quote 0
              • X
                Xthink
                last edited by

                Is this package available for the snapshot builds?

                1 Reply Last reply Reply Quote 0
                • V
                  vsberto
                  last edited by

                  Strange i can open youtube.com as allways…
                  I installed package
                  Updated blacklist's
                  And activated DNS Blocklist in pfSense services and checked categories i need...
                  And it doesent block anything

                  1 Reply Last reply Reply Quote 0
                  • T
                    tommyboy180
                    last edited by

                    @vsberto:

                    Strange i can open youtube.com as allways…
                    I installed package
                    Updated blacklist's
                    And activated DNS Blocklist in pfSense services and checked categories i need...
                    And it doesent block anything

                    Which category is supposed to block YouTube?

                    -Tom Schaefer
                    SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

                    Please support pfBlocker | File Browser | Strikeback

                    1 Reply Last reply Reply Quote 0
                    • V
                      vburshteyn
                      last edited by

                      Hi folks, i am new to pfsense so please excuse what might be a stupid question.

                      I installed and got this package working but i have two questions:

                      1. is there a way to change where the blocked page gets redirected to?
                      2. is there a way to have certain ip's bypass this app?

                      Thanks,

                      1 Reply Last reply Reply Quote 0
                      • M
                        machado
                        last edited by

                        This is a greate package from pfsense. I loving pFsense  ;D ;D ;D ;D

                        1 Reply Last reply Reply Quote 0
                        • M
                          mgc6288
                          last edited by

                          Hello, I was instructed that DNS Blacklist would be a good addition to pfsense.  Right now I have added "OPT1" specifically for my son's computer which is directly plugged in.  He has the outstanding Country Block on his interface blocking the outbound however I'd also like to block certain categories, i.e. Adult content.  I can use OpenDNS' settings however eventually he'll figure out how to temporarily switch them and so having something within pfsense would be ideal.  Back to DNS Blacklist, is this list actively updated or obsolete?  Can I address this package to only effect certain interfaces or is every interface effected by the selections made?  Thanks.

                          1 Reply Last reply Reply Quote 0
                          • T
                            tommyboy180
                            last edited by

                            @mgc6288:

                            Hello, I was instructed that DNS Blacklist would be a good addition to pfsense.  Right now I have added "OPT1" specifically for my son's computer which is directly plugged in.  He has the outstanding Country Block on his interface blocking the outbound however I'd also like to block certain categories, i.e. Adult content.  I can use OpenDNS' settings however eventually he'll figure out how to temporarily switch them and so having something within pfsense would be ideal.  Back to DNS Blacklist, is this list actively updated or obsolete?  Can I address this package to only effect certain interfaces or is every interface effected by the selections made?  Thanks.

                            The lists are actively updated but not in the package. In the previous post I show you how to update your lists directly from the source.
                            Every interface using local DNS is affected by the package. You can bypass by specifying another DNS server on your systems just the same way you can bypass OpenDNS.

                            -Tom Schaefer
                            SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

                            Please support pfBlocker | File Browser | Strikeback

                            1 Reply Last reply Reply Quote 0
                            • M
                              mgc6288
                              last edited by

                              @tommyboy180:

                              The lists are actively updated but not in the package. In the previous post I show you how to update your lists directly from the source.
                              Every interface using local DNS is affected by the package. You can bypass by specifying another DNS server on your systems just the same way you can bypass OpenDNS.

                              UPDATE: I figured it out!  I guess for now, if I want to use OpenDNS' settings what I can do is go to Services –> DHCP Server --> OPT1 --> and fill in the OpenDNS settings in the DNS Servers block.  With DNS Forwarder checked all he gets is his default gateway as the DNS server which masks it that much better.

                              1 Reply Last reply Reply Quote 0
                              • X
                                XIII
                                last edited by

                                What you need so that he cant bypass your DNS servers/settings is a rule that allows DNS access to your firewall and OpenDNS and than below that a rule that denies access to all DNS servers, this way one can get DNS from the firewall or pfsense but not anywhere else therefor you can block them from going to sites you dont want. If you dont do these rules, one can just change the dns servers that the computer uses.

                                -Chris Stutzman
                                Sys0:2.0.1: AMD Sempron 140 @2.7 1024M RAM 100GHD
                                Sys1:2.0.1: Intel P4 @2.66 1024M RAM 40GHD
                                freedns.afraid.org - Free DNS dynamic DNS subdomain and domain hosting.
                                Check out the pfSense Wiki

                                1 Reply Last reply Reply Quote 0
                                • M
                                  mgc6288
                                  last edited by

                                  @XIII:

                                  What you need so that he cant bypass your DNS servers/settings is a rule that allows DNS access to your firewall and OpenDNS and than below that a rule that denies access to all DNS servers, this way one can get DNS from the firewall or pfsense but not anywhere else therefor you can block them from going to sites you dont want. If you dont do these rules, one can just change the dns servers that the computer uses.

                                  A very good idea as when he figures out how to configure static he'll be able to type in the ISP dns manually.  I'd like for the OPT1 (son's) interface to only use the OpenDNS one.

                                  Would that be in the Firewall –> Rules --> OPT1 interface?  Example?  Thanks...

                                  1 Reply Last reply Reply Quote 0
                                  • X
                                    XIII
                                    last edited by

                                    Yes, attached is a pic of my DNS server rules, remember rules at the top override those at the bottom.
                                    Edit: Also I have an alias for DNS Servers which is the firewall and OpenDNS' DNS servers.

                                    If you need more help, start a new thread so as not to hijack this one.

                                    dnsrules.png
                                    dnsrules.png_thumb

                                    -Chris Stutzman
                                    Sys0:2.0.1: AMD Sempron 140 @2.7 1024M RAM 100GHD
                                    Sys1:2.0.1: Intel P4 @2.66 1024M RAM 40GHD
                                    freedns.afraid.org - Free DNS dynamic DNS subdomain and domain hosting.
                                    Check out the pfSense Wiki

                                    1 Reply Last reply Reply Quote 0
                                    • M
                                      mgc6288
                                      last edited by

                                      @XIII:

                                      Yes, attached is a pic of my DNS server rules, remember rules at the top override those at the bottom.
                                      Edit: Also I have an alias for DNS Servers which is the firewall and OpenDNS' DNS servers.

                                      If you need more help, start a new thread so as not to hijack this one.

                                      Excuse me, continued here.

                                      1 Reply Last reply Reply Quote 0
                                      • M
                                        machado
                                        last edited by

                                        @xa0z:

                                        Here is a little teaser for you guys…  I still need to work on how we read/edit the blacklist.  I was doing it with PHP but it uses too much RAM, so now we're doing it in sh which runs a lot quicker.  Just need a little more time, so please be patient.

                                        How to add manual entries?

                                        1 Reply Last reply Reply Quote 0
                                        • F
                                          frostpaw
                                          last edited by

                                          I used DNS blacklist about a year ago before I started using the snapshot version.  I thought it was a great package and I'd really like to see it available for use with the snapshots.

                                          Is there anyone currently looking into making the DNS blacklist  package available for snapshots?  Or is there some other package people are using instead of DNS blacklist now?

                                          1 Reply Last reply Reply Quote 0
                                          • J
                                            jambek2003
                                            last edited by

                                            I've got a nice white 404 Error-page when clicking DNS Blacklist referring to http://pfsense:82/packages/dnsblacklist/dnsblacklist.php

                                            Tried first Squid allong with SquidGuard but was to much of a hassle to get it working. Was blocking websites so I had to manually Whitelist them. Ended up uninstalling Squid en SquidGuard, rebooting and installing DNS Blacklist. I Reinstalled Package version 0.2.4 but no luck! How and Why?!

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.