Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfBlockerNG

    Scheduled Pinned Locked Moved pfBlockerNG
    1.2k Posts 210 Posters 1.8m Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • BBcan177B
      BBcan177 Moderator
      last edited by

      I posted some Lists here
          https://forum.pfsense.org/index.php?topic=86212.msg486648#msg486648

      Here are a couple more:
          http://www.infiltrated.net/blacklisted
          http://www.infiltrated.net/webattackers.txt

      I tried the Blocklist.de (ssh) and it worked fine on my test? Its strange that you had this error?
      as that would indicate that the URL was incorrect (localfile).

      [pfB_SSH_BlockList SSH_BlockList ] Local File Failure

      "Experience is something you don't get until just after you need it."

      Website: http://pfBlockerNG.com
      Twitter: @BBcan177  #pfBlockerNG
      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

      1 Reply Last reply Reply Quote 0
      • B
        Bummer
        last edited by

        Thank you so much for your help. I'm going to play with this some more tomorrow.

        Have a great evening!

        1 Reply Last reply Reply Quote 0
        • panzP
          panz
          last edited by

          One more question, about Suppress lists:

          I noticed that Bluetack Level 1 blocks Apple range of addresses: 17.0.0.0/8

          With that list working on pfblockerNG, my iPad can't get software auto updates.

          I think that, manual editing the Suppress Alias will not work, because the Help in the "Suppress" sections says:

          "A Blocked IP in a CIDR other than /24 will need to be Suppressed by an 'Permit Outbound' Firewall Rule"

          So, how do I pass those addresses?

          pfSense 2.3.2-RELEASE-p1 (amd64)
          motherboard: MSI C847MS-E33 Micro ATX (with Intel Celeron CPU 847 @ 1.10 GHz) ~ PSU: Corsair VS350 ~ RAM: Kingston KVR1333D3E9S 4096 MB 240-pin DIMM DDR3 SDRAM 1.5 volt ~ NIC: Intel EXPI9301CTBLK (LAN) ~ NIC: D-Link DFE-528TX (CAM) ~ Hard Disk: Western Digital WD10JFCX Red ~ Case: Cooler Master HAF XB ~ power consumption: 21 Watts.

          1 Reply Last reply Reply Quote 0
          • BBcan177B
            BBcan177 Moderator
            last edited by

            @panz:

            I think that, manual editing the Suppress Alias will not work, because the Help in the "Suppress" sections says:

            "A Blocked IP in a CIDR other than /24 will need to be Suppressed by an 'Permit Outbound' Firewall Rule"

            So, how do I pass those addresses?

            Just as it says  :)

            Create a new Alias called "Whitelist", in the custom Box at the bottom, enter any IPs that you want to allow Outbound. This will bypass the IP/Range that are in the Blocklists.

            Try to limit the IPs range as much as possible.

            Set the "Action" to "Permit Outbound"

            Define a "Rule Order" in the General Tab that will put the "Whitelist" above the Block/Reject Rules.

            (When you make future changes, you can click the "Update Custom List" at the bottom of the alias, and run a "Force Update" to get the new changes to be in effect.)

            "Experience is something you don't get until just after you need it."

            Website: http://pfBlockerNG.com
            Twitter: @BBcan177  #pfBlockerNG
            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

            1 Reply Last reply Reply Quote 0
            • B
              Bummer
              last edited by

              Hey BBScan177,

              I looked at the lists you suggested below. I've looked at them before but ignored them. Can you answer 2 questions?

              1. On pfBlockerNG it says you can comment out stuff using a # sign. The lists below use a semi colon. Will they still work?
              2. Lots of people use Google and Yahoo for spamming. I checked the MX record IPs for Google and they weren't listed on either list. Do you know if they ever get put on? The reason I ask is that a lot of people use Gmail.

              http://www.spamhaus.org/drop/edrop.txt
              http://www.spamhaus.org/drop/drop.txt

              This is great!

              1 Reply Last reply Reply Quote 0
              • BBcan177B
                BBcan177 Moderator
                last edited by

                @Bummer:

                Hey BBScan177,

                I looked at the lists you suggested below. I've looked at them before but ignored them. Can you answer 2 questions?

                1. On pfBlockerNG it says you can comment out stuff using a # sign. The lists below use a semi colon. Will they still work?
                2. Lots of people use Google and Yahoo for spamming. I checked the MX record IPs for Google and they weren't listed on either list. Do you know if they ever get put on? The reason I ask is that a lot of people use Gmail.

                http://www.spamhaus.org/drop/edrop.txt
                http://www.spamhaus.org/drop/drop.txt

                This is great!

                Lol.. ok for one… BBCan not BBScan ... (you owe me like +100 Karma for my identity crisis!)

                The lists that I recommended are all well established lists. You shouldn't have too much trouble with them.

                The parsing of the lists will skip any line that starts with a "#". The Spamhaus list parsing is not affected by that trailing ";".

                In the Custom Box entry of the Alias, you can enter an IP and follow that with a "#" to allow you to enter a description. This makes it easier to remember months later, why you put an IP in the Custom Box in the first place.

                The Spamhaus list will not affect Google/Yahoo. You can readup on the "Spamhaus" blocklists here…    https://www.spamhaus.org/drop/

                "Experience is something you don't get until just after you need it."

                Website: http://pfBlockerNG.com
                Twitter: @BBcan177  #pfBlockerNG
                Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                1 Reply Last reply Reply Quote 0
                • B
                  Bummer
                  last edited by

                  Okay BBCan177,

                  How do I issue karma points on this? I took speed reading when in high school. You can see how much good it did me! lol

                  Okay, I didn't comprehend what was written on phBlockerNG. Again, this must have to do with my speed reading!

                  1 Reply Last reply Reply Quote 0
                  • S
                    SkyHawk
                    last edited by

                    Is the CRON suppose to run hourly?  If so then why?

                    1 Reply Last reply Reply Quote 0
                    • D
                      doktornotor Banned
                      last edited by

                      @SkyHawk:

                      Is the CRON suppose to run hourly?  If so then why?

                      https://forum.pfsense.org/index.php?topic=86212.msg492936#msg492936

                      1 Reply Last reply Reply Quote 0
                      • B
                        BoMbY
                        last edited by

                        pfBlockerNG can't even import the DROP and EDROP lists from Spamhaus. Is there any way to use the old pfBlocker on pfSense 2.2 (package does not seem to be available)?

                        1 Reply Last reply Reply Quote 0
                        • BBcan177B
                          BBcan177 Moderator
                          last edited by

                          @SkyHawk:

                          Is the CRON suppose to run hourly?  If so then why?

                          I will add this to my list of Improvements as i indicated in a previous post..

                          @BBcan177:

                          I can however add an option in the future to edit the cron settings (min/hour/day etc)

                          "Experience is something you don't get until just after you need it."

                          Website: http://pfBlockerNG.com
                          Twitter: @BBcan177  #pfBlockerNG
                          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                          1 Reply Last reply Reply Quote 0
                          • BBcan177B
                            BBcan177 Moderator
                            last edited by

                            @BoMbY:

                            pfBlockerNG can't even import the DROP and EDROP lists from Spamhaus. Is there any way to use the old pfBlocker on pfSense 2.2 (package does not seem to be available)?

                            I think you have mis-configured something in your setup! As there is no issue with those lists. What errors or symptoms do you see in the logs?

                            "Experience is something you don't get until just after you need it."

                            Website: http://pfBlockerNG.com
                            Twitter: @BBcan177  #pfBlockerNG
                            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                            1 Reply Last reply Reply Quote 0
                            • D
                              doktornotor Banned
                              last edited by

                              @BBcan177:

                              I think you have mis-configured something in your setup! As there is no issue with those lists.

                              +1, zero issues with Spamhaus (e)drop.

                              1 Reply Last reply Reply Quote 0
                              • D
                                doktornotor Banned
                                last edited by

                                Lazy man's feature request: can you make the widget's aliases clickable? Like, show what's in the alias on hover (like when you hover in Firewall - Rules) and edit the alias when the row is double-clicked. :D

                                1 Reply Last reply Reply Quote 0
                                • M
                                  marcus556
                                  last edited by

                                  So I just tried to use TeamViewer and Pfblockerng is blocking it.  Not sure what list but don’t want to disable the whole list just for TeamViewer, so I went in and added www.teamviewer.com into the alias list and it still isn’t working.  I figured I added the wrong thing so I thought I would come here and ask if anyone knows how to add TeamViewer to the alias list and keep it from being blocked?

                                  1 Reply Last reply Reply Quote 0
                                  • D
                                    doktornotor Banned
                                    last edited by

                                    Generic hint: Only use such blocklists that fit your needs and that you are able to manage…

                                    1 Reply Last reply Reply Quote 0
                                    • S
                                      Supermule Banned
                                      last edited by

                                      Why not push the pass of teamviewer to the top of the list so it doesnt hit the block list before the passlist?? ;)

                                      1 Reply Last reply Reply Quote 0
                                      • M
                                        marcus556
                                        last edited by

                                        @Supermule:

                                        Why not push the pass of teamviewer to the top of the list so it doesnt hit the block list before the passlist?? ;)

                                        Where exactly do I go to do that?  I still very new with pfsense so please bare with me…

                                        1 Reply Last reply Reply Quote 0
                                        • BBcan177B
                                          BBcan177 Moderator
                                          last edited by

                                          @marcus556:

                                          So I just tried to use TeamViewer and Pfblockerng is blocking it.

                                          You need to look at the Alerts Tab and see which List is blocking it.
                                          I came across this issue before with TeamViewer and for that case, it was being blocked by a Country Block.. (One of the Top20)

                                          You also can't use an alias in the Custom Input settings. They have to be IP addresses.

                                          Try to ping www.teamviewer.com from your desktop and take a look for what is blocking it in the Alerts Tab.

                                          "Experience is something you don't get until just after you need it."

                                          Website: http://pfBlockerNG.com
                                          Twitter: @BBcan177  #pfBlockerNG
                                          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                                          1 Reply Last reply Reply Quote 0
                                          • M
                                            marcus556
                                            last edited by

                                            @doktornotor:

                                            Generic hint: Only use such blocklists that fit your needs and that you are able to manage…

                                            Its actually one of the Top 20 sites that is blocking it not one of the list I imported..

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.