Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfBlockerNG

    Scheduled Pinned Locked Moved pfBlockerNG
    1.2k Posts 210 Posters 1.8m Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • BBcan177B
      BBcan177 Moderator
      last edited by

      You will need to re-configure, as it doesn't share the same settings.

      I would recommend that you create aliases with more than one list. No real need to have a rule per list.

      If you want to stay with "Alias" rules, you can modify the existing rules from pfblocker, and change the "alias table" setting and change the description to :

      pfb_  then the name of the aliastable
          (more details in the alias settings tab)

      "Experience is something you don't get until just after you need it."

      Website: http://pfBlockerNG.com
      Twitter: @BBcan177  #pfBlockerNG
      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

      1 Reply Last reply Reply Quote 0
      • panzP
        panz
        last edited by

        I created an Alias for each list because, with one "big" list, pfblocker crashed with pfSense's message "PF was wedged/busy and has been reset".

        So, I'm going to follow this procedure:

        1. delete any previous firewall rule created by pfblocker;

        2. delete any Alias also created by pfblocker;

        3. enter the setting again in the new package pfblockerNG.

        pfSense 2.3.2-RELEASE-p1 (amd64)
        motherboard: MSI C847MS-E33 Micro ATX (with Intel Celeron CPU 847 @ 1.10 GHz) ~ PSU: Corsair VS350 ~ RAM: Kingston KVR1333D3E9S 4096 MB 240-pin DIMM DDR3 SDRAM 1.5 volt ~ NIC: Intel EXPI9301CTBLK (LAN) ~ NIC: D-Link DFE-528TX (CAM) ~ Hard Disk: Western Digital WD10JFCX Red ~ Case: Cooler Master HAF XB ~ power consumption: 21 Watts.

        1 Reply Last reply Reply Quote 0
        • BBcan177B
          BBcan177 Moderator
          last edited by

          @panz:

          I created an Alias for each list because, with one "big" list, pfblocker crashed with pfSense's message "PF was wedged/busy and has been reset".

          Enable "De-duplication" in the General Tab. You will see the total size of the Block lists shrink substantially.

          "Experience is something you don't get until just after you need it."

          Website: http://pfBlockerNG.com
          Twitter: @BBcan177  #pfBlockerNG
          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

          1 Reply Last reply Reply Quote 0
          • B
            Bummer
            last edited by

            Hey guys,

            I set up a few lists from BlockList.de and have it set to run via cron. I'm getting the errors below. What am I doing wrong?

            CRON  PROCESS  START [ 02/21/15 13:00:00 ]
              Updates Found
              Updates Found
            UPDATE PROCESS START

            [ pfB_Africa_v4 ] exists, Reloading File

            [ pfB_Africa_v6 ] exists, Reloading File

            [ pfB_Top_v4 ] exists, Reloading File
            [ pfB_Top_v6 ] exists, Reloading File

            [ White Listed IPs_custom ] exists, Reloading File

            [  http://lists.blocklist.de/lists/ssh.txt ]
            ** TERMINATED - Header contains Blank/International/Special or Spaces

            [ SSH-BlockList_custom ] Loading Custom File
            –--------------------------------------------------------
            Original  Masterfile Outfile    [ Post Duplication count ] 
            –--------------------------------------------------------
            952        952        952        [ Passed ]                 
            –--------------------------------------------------------

            [ http://lists.blocklist.de/lists/ssh.txt ]
            ** TERMINATED - Header contains Blank/International/Special or Spaces
            \ Email-BlockList_custom ] exists, Reloading File

            ===[  Aliastables / Rules  ]================================

            No Changes to Firewall Rules, Skipping Filter Reload
            Updating: pfB_SSHBlockList
            no changes.
            UPDATE PROCESS ENDED

            1 Reply Last reply Reply Quote 0
            • BBcan177B
              BBcan177 Moderator
              last edited by

              Make sure you set the "Header" in the IPv4 tab for each list. The log usually has all the details to diagnose issues.

              ** TERMINATED - Header contains Blank/International/Special or Spaces

              Also - try to use. "https" when possible.

              EDIT:

              You can't use "-" in the Header field…

              "Experience is something you don't get until just after you need it."

              Website: http://pfBlockerNG.com
              Twitter: @BBcan177  #pfBlockerNG
              Reddit: https://www.reddit.com/r/pfBlockerNG/new/

              1 Reply Last reply Reply Quote 0
              • B
                Bummer
                last edited by

                Okay, BBScan177,

                OKay, call me stupid. Okay, very stupid. How do I set the header for each list? When making the list is says to make a unique header. I saw the area and put the same thing in the "header" area as I did for the "List Description" and "List Name". So now that I know that's not correct, what do I do?

                Sorry, I feel stupid.

                Thanks!

                1 Reply Last reply Reply Quote 0
                • BBcan177B
                  BBcan177 Moderator
                  last edited by

                  I usually setup an Alias for "Malicious", "Ads", "IBlock", "Mail" etc (group common lists into one alias) and for each list enter a unique name for each list/header. If the List source has multiple lists, then use a prefix like so:

                  blocklistde_ssh
                      blocklistde_spam

                  "Experience is something you don't get until just after you need it."

                  Website: http://pfBlockerNG.com
                  Twitter: @BBcan177  #pfBlockerNG
                  Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                  1 Reply Last reply Reply Quote 0
                  • B
                    Bummer
                    last edited by

                    I am missing something? Attached here is a partial screen cap of what I have set up.

                    bbacan177.png
                    bbacan177.png_thumb

                    1 Reply Last reply Reply Quote 0
                    • BBcan177B
                      BBcan177 Moderator
                      last edited by

                      Unfortunately you can't use "-" in the header name. I also added that to a previous post above.

                      "Experience is something you don't get until just after you need it."

                      Website: http://pfBlockerNG.com
                      Twitter: @BBcan177  #pfBlockerNG
                      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                      1 Reply Last reply Reply Quote 0
                      • B
                        Bummer
                        last edited by

                        I"ve read so much on these posts my head spins! I try to go back and look at something that I wanted to research and can't find it.

                        Thank you very much for letting me know. I appreciate it.

                        Time to make the changes!

                        1 Reply Last reply Reply Quote 0
                        • B
                          Bummer
                          last edited by

                          Well, most of it worked! But, there is an error below. It doesn't say much for the SSH block list.

                          I'm sorry, I hope this isn't something stupid again. I'm very excited with the new pfBlockerNG and want to use it to it's fullest! See the attached screen cap.

                          pfblockerNG.png
                          pfblockerNG.png_thumb

                          1 Reply Last reply Reply Quote 0
                          • BBcan177B
                            BBcan177 Moderator
                            last edited by

                            Can you copy that url and test it in the browser?

                            Some site have rate-limiting if you download too many times. When you test it in the browser, and if you get a rate limiting error, disable that list for 24hrs and then re-enable it.

                            Blocklist.de also has all those categories in a single download file if you want to try that one.

                            "Experience is something you don't get until just after you need it."

                            Website: http://pfBlockerNG.com
                            Twitter: @BBcan177  #pfBlockerNG
                            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                            1 Reply Last reply Reply Quote 0
                            • B
                              Bummer
                              last edited by

                              Yes, I was able to copy and paste the url in to my browser and it came up. I did the "All" as you suggested. I'll see if it updates.

                              What other lists are good to add? I've looked around and it can get confusing. I've seen lists from BlueTack and I-Blocklist. Are they redundant or any good?

                              The spammers and hackers can sure make things painful.

                              1 Reply Last reply Reply Quote 0
                              • B
                                Bummer
                                last edited by

                                It looks like it updated okay! I'm excited, thank you very much!

                                Please let me know if there are other lists you consider good and/or use!

                                1 Reply Last reply Reply Quote 0
                                • BBcan177B
                                  BBcan177 Moderator
                                  last edited by

                                  I posted some Lists here
                                      https://forum.pfsense.org/index.php?topic=86212.msg486648#msg486648

                                  Here are a couple more:
                                      http://www.infiltrated.net/blacklisted
                                      http://www.infiltrated.net/webattackers.txt

                                  I tried the Blocklist.de (ssh) and it worked fine on my test? Its strange that you had this error?
                                  as that would indicate that the URL was incorrect (localfile).

                                  [pfB_SSH_BlockList SSH_BlockList ] Local File Failure

                                  "Experience is something you don't get until just after you need it."

                                  Website: http://pfBlockerNG.com
                                  Twitter: @BBcan177  #pfBlockerNG
                                  Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                                  1 Reply Last reply Reply Quote 0
                                  • B
                                    Bummer
                                    last edited by

                                    Thank you so much for your help. I'm going to play with this some more tomorrow.

                                    Have a great evening!

                                    1 Reply Last reply Reply Quote 0
                                    • panzP
                                      panz
                                      last edited by

                                      One more question, about Suppress lists:

                                      I noticed that Bluetack Level 1 blocks Apple range of addresses: 17.0.0.0/8

                                      With that list working on pfblockerNG, my iPad can't get software auto updates.

                                      I think that, manual editing the Suppress Alias will not work, because the Help in the "Suppress" sections says:

                                      "A Blocked IP in a CIDR other than /24 will need to be Suppressed by an 'Permit Outbound' Firewall Rule"

                                      So, how do I pass those addresses?

                                      pfSense 2.3.2-RELEASE-p1 (amd64)
                                      motherboard: MSI C847MS-E33 Micro ATX (with Intel Celeron CPU 847 @ 1.10 GHz) ~ PSU: Corsair VS350 ~ RAM: Kingston KVR1333D3E9S 4096 MB 240-pin DIMM DDR3 SDRAM 1.5 volt ~ NIC: Intel EXPI9301CTBLK (LAN) ~ NIC: D-Link DFE-528TX (CAM) ~ Hard Disk: Western Digital WD10JFCX Red ~ Case: Cooler Master HAF XB ~ power consumption: 21 Watts.

                                      1 Reply Last reply Reply Quote 0
                                      • BBcan177B
                                        BBcan177 Moderator
                                        last edited by

                                        @panz:

                                        I think that, manual editing the Suppress Alias will not work, because the Help in the "Suppress" sections says:

                                        "A Blocked IP in a CIDR other than /24 will need to be Suppressed by an 'Permit Outbound' Firewall Rule"

                                        So, how do I pass those addresses?

                                        Just as it says  :)

                                        Create a new Alias called "Whitelist", in the custom Box at the bottom, enter any IPs that you want to allow Outbound. This will bypass the IP/Range that are in the Blocklists.

                                        Try to limit the IPs range as much as possible.

                                        Set the "Action" to "Permit Outbound"

                                        Define a "Rule Order" in the General Tab that will put the "Whitelist" above the Block/Reject Rules.

                                        (When you make future changes, you can click the "Update Custom List" at the bottom of the alias, and run a "Force Update" to get the new changes to be in effect.)

                                        "Experience is something you don't get until just after you need it."

                                        Website: http://pfBlockerNG.com
                                        Twitter: @BBcan177  #pfBlockerNG
                                        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                                        1 Reply Last reply Reply Quote 0
                                        • B
                                          Bummer
                                          last edited by

                                          Hey BBScan177,

                                          I looked at the lists you suggested below. I've looked at them before but ignored them. Can you answer 2 questions?

                                          1. On pfBlockerNG it says you can comment out stuff using a # sign. The lists below use a semi colon. Will they still work?
                                          2. Lots of people use Google and Yahoo for spamming. I checked the MX record IPs for Google and they weren't listed on either list. Do you know if they ever get put on? The reason I ask is that a lot of people use Gmail.

                                          http://www.spamhaus.org/drop/edrop.txt
                                          http://www.spamhaus.org/drop/drop.txt

                                          This is great!

                                          1 Reply Last reply Reply Quote 0
                                          • BBcan177B
                                            BBcan177 Moderator
                                            last edited by

                                            @Bummer:

                                            Hey BBScan177,

                                            I looked at the lists you suggested below. I've looked at them before but ignored them. Can you answer 2 questions?

                                            1. On pfBlockerNG it says you can comment out stuff using a # sign. The lists below use a semi colon. Will they still work?
                                            2. Lots of people use Google and Yahoo for spamming. I checked the MX record IPs for Google and they weren't listed on either list. Do you know if they ever get put on? The reason I ask is that a lot of people use Gmail.

                                            http://www.spamhaus.org/drop/edrop.txt
                                            http://www.spamhaus.org/drop/drop.txt

                                            This is great!

                                            Lol.. ok for one… BBCan not BBScan ... (you owe me like +100 Karma for my identity crisis!)

                                            The lists that I recommended are all well established lists. You shouldn't have too much trouble with them.

                                            The parsing of the lists will skip any line that starts with a "#". The Spamhaus list parsing is not affected by that trailing ";".

                                            In the Custom Box entry of the Alias, you can enter an IP and follow that with a "#" to allow you to enter a description. This makes it easier to remember months later, why you put an IP in the Custom Box in the first place.

                                            The Spamhaus list will not affect Google/Yahoo. You can readup on the "Spamhaus" blocklists here…    https://www.spamhaus.org/drop/

                                            "Experience is something you don't get until just after you need it."

                                            Website: http://pfBlockerNG.com
                                            Twitter: @BBcan177  #pfBlockerNG
                                            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.