Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfBlockerNG

    Scheduled Pinned Locked Moved pfBlockerNG
    1.2k Posts 211 Posters 1.9m Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      Slab
      last edited by

      Hi folks,

      I have a question re. utilizing a pfBlockerNG alias. Specifically, this text:

      
      When using 'Alias' rules, change (pfB_) to ( pfb_ ) in the beginning of rule description and use the 'Exact' spelling of
      the Alias (no trailing Whitespace)  Custom 'Alias' rules with 'pfB_ xxx' description will be removed by package if using
      Auto Rule Creation.
      
      

      I am assuming that I don't have to change anything with respect to the alias created by pfBlockerNG itself, but when creating a rule that utilizes the alias must the rule description field contain only the alias name (with the lower case 'B' substituted in the pfb_ prefix) or can it include additional text after the alias name? The "in the beginning of rule description" wording implies (to me) that other text can follow …but the "no trailing Whitespace" implies no other text should follow. I currently have additional text in the rule description field, and the dashboard widget shows green for the alias, but I just want to be sure.

      Thanks (and awesome package by the way!) ...

      1 Reply Last reply Reply Quote 0
      • BBcan177B
        BBcan177 Moderator
        last edited by

        @Slab:

        I currently have additional text in the rule description field, and the dashboard widget shows green for the alias, but I just want to be sure.

        Hi Slab,

        The Green arrow indicator, will show that there is a Rule associated with the pfBlockerNG Alias. If you add extra text to the Manual Rule Description, the Packet Count for this Manual Alias Rule in the widget might not work.

        "Experience is something you don't get until just after you need it."

        Website: http://pfBlockerNG.com
        Twitter: @BBcan177  #pfBlockerNG
        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

        1 Reply Last reply Reply Quote 0
        • S
          seqteq
          last edited by

          Hi, I updated from pfsense 2.2 to 2.2.1 and my pfBlockerng config got wiped. The package was uninstalled and reinstalled according to the logs

          all I had was 1 alias of 1 country, type native

          any ideas before I update the other 13 firewalls?

          Thank you for your time

          Mar 19 09:49:28 php: rc.bootup: Attempting to reinstall all packages
          Mar 19 09:49:28 php: rc.bootup: List of packages to reinstall: OpenVPN Client Export Utility, pfBlocker
          Mar 19 09:49:28 php: rc.bootup: Uninstalling package OpenVPN Client Export Utility
          Mar 19 09:49:40 php: rc.bootup: Finished uninstalling package OpenVPN Client Export Utility
          Mar 19 09:49:40 php: rc.bootup: Reinstalling package OpenVPN Client Export Utility
          Mar 19 09:49:40 php: rc.bootup: Beginning package installation for OpenVPN Client Export Utility .
          Mar 19 09:49:57 php: rc.bootup: Successfully installed package: OpenVPN Client Export Utility.
          Mar 19 09:49:57 php: rc.bootup: Finished installing package OpenVPN Client Export Utility
          Mar 19 09:49:57 php: rc.bootup: Uninstalling package pfBlocker
          Mar 19 09:49:57 php: rc.bootup: Finished uninstalling package pfBlocker
          Mar 19 09:49:57 php: rc.bootup: Reinstalling package pfBlocker
          Mar 19 09:49:58 php: rc.bootup: Finished installing package pfBlocker
          Mar 19 09:49:58 php: rc.bootup: Finished reinstalling all packages.

          1 Reply Last reply Reply Quote 0
          • BBcan177B
            BBcan177 Moderator
            last edited by

            Hi Seqteq,

            There is a checkbox in the General Tab called "Keep Settings" that needs to be enabled. On all new installations it has been defaulted to "On".

            Its strange that your posted log has "pfBlocker" when it should be "pfBlockerNG"

            "Experience is something you don't get until just after you need it."

            Website: http://pfBlockerNG.com
            Twitter: @BBcan177  #pfBlockerNG
            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

            1 Reply Last reply Reply Quote 0
            • D
              doktornotor Banned
              last edited by

              @seqteq:

              Hi, I updated from pfsense 2.2 to 2.2.1 and my pfBlockerng config got wiped. The package was uninstalled and reinstalled according to the logs

              pfBlocker package does not exist any more. No configuration from there will be carried over to pfBlockerNG. Restart from scratch.

              1 Reply Last reply Reply Quote 0
              • S
                seqteq
                last edited by

                @BBcan177:

                Hi Seqteq,

                There is a checkbox in the General Tab called "Keep Settings" that needs to be enabled. On all new installations it has been defaulted to "On".

                Its strange that your posted log has "pfBlocker" when it should be "pfBlockerNG"

                Ah, thanks I'll check that tomorrow.
                Just noticed the ng was missing in the log. I was definitely using ng in 2.2 and ng is definitely what got installed after the 2.2.1 update. iDunno. I adopted 2.2 for this appliance early, before the ng release, but that got replaced like the day after ng dropped.

                1 Reply Last reply Reply Quote 0
                • D
                  doktornotor Banned
                  last edited by

                  There's no way the package would reinstall in 1 second. Probably you have too many boxes to keep track of what actually was there.

                  1 Reply Last reply Reply Quote 0
                  • S
                    stanthewizard
                    last edited by

                    Hello

                    Got Something strange with PpBlockerNG on alerts tab

                    Fatal error: Call to undefined function subnetv6_expand() in /etc/inc/util.inc on line 714

                    Any idea what is going wrong ?

                    Thanks

                    1 Reply Last reply Reply Quote 0
                    • BBcan177B
                      BBcan177 Moderator
                      last edited by

                      pfBlockerNG v1.06  has been Merged by the Devs.

                      Changelog:

                      • Previously when deleting all IPs in the pfBlockerNGSuppress Alias, it would not
                        clear the widget Suppression Counter. This version fixes that issue as reported by user "Panz".

                      • Merged recent changes in pfSense diag_dns.php into pfblockerng_diag_dns.php to keep code base current.

                      • Change Release to "Stable" from previous "Beta" Status.

                      Notes -

                      The issue reported by "stanthewizard" above is partially due to a missing function in pfSense (subnetv6_expand). I expect that I will need to submit a new Pull Request to fix this issue. I provided him a workaround to fix his issue for now.

                      "Experience is something you don't get until just after you need it."

                      Website: http://pfBlockerNG.com
                      Twitter: @BBcan177  #pfBlockerNG
                      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                      1 Reply Last reply Reply Quote 0
                      • S
                        stanthewizard
                        last edited by

                        And I thank you for that again

                        1 Reply Last reply Reply Quote 0
                        • S
                          seqteq
                          last edited by

                          @doktornotor:

                          There's no way the package would reinstall in 1 second. Probably you have too many boxes to keep track of what actually was there.

                          That was it, it's been a busy year.

                          1 Reply Last reply Reply Quote 0
                          • V
                            varazir
                            last edited by

                            Hi, Thanks for a great pkg.

                            I'm having problem with port forwards and UPnP & NAT-PMP.

                            I use this settings for pfBlockerNG:
                            Marked all lists
                            Top 20 and Asia is blocked, both rest blocked inbound.
                            I have added custom lists from Bluetack ads/proxy/spyware and from Squidblacklist ads. All deny both
                            Set rule order pfSense pass/match | pfB_pass/match | pfB_block/reject

                            TIA

                            1 Reply Last reply Reply Quote 0
                            • D
                              doktornotor Banned
                              last edited by

                              @varazir:

                              I'm having problem with port forwards and UPnP & NAT-PMP.

                              You need to describe what is your problem…

                              @varazir:

                              I use this settings for pfBlockerNG:
                              Marked all lists
                              Top 20 and Asia is blocked, both rest blocked inbound.

                              What all lists? The country lists? So you blocked whole world inbound, or what? I don't understand your description at all. Plus, block is default on WAN. Are you actually running any service locally that you need to limit access to?

                              1 Reply Last reply Reply Quote 0
                              • V
                                varazir
                                last edited by

                                @doktornotor:

                                @varazir:

                                I'm having problem with port forwards and UPnP & NAT-PMP.

                                You need to describe what is your problem…

                                @varazir:

                                I use this settings for pfBlockerNG:
                                Marked all lists
                                Top 20 and Asia is blocked, both rest blocked inbound.

                                What all lists? The country lists? So you blocked whole world inbound, or what? I don't understand your description at all. Plus, block is default on WAN. Are you actually running any service locally that you need to limit access to?

                                Never mind, me who has got all wrong :( Changed to outbound only and now it's working

                                1 Reply Last reply Reply Quote 0
                                • V
                                  varazir
                                  last edited by

                                  I heard there was host blocking option on it's way?

                                  1 Reply Last reply Reply Quote 0
                                  • ?
                                    A Former User
                                    last edited by

                                    I just wanted to drop a thank you for a great package. Runs excellent with all the bells running. Error log is empty.
                                    Thanks again guys. BBcan177 nice job. Your work is appreciated. ;D

                                    ps: just finished reading this post in its entirety and what did you guys "NOT" cover. The post is a manual in its own right. Your patience shows. ::)

                                    1 Reply Last reply Reply Quote 0
                                    • BBcan177B
                                      BBcan177 Moderator
                                      last edited by

                                      Here is another Threat Source for pfBlockerNG :

                                      This feed is provided by :  bambenekconsulting.com

                                      These lists cover the following type of Threats:

                                      • Banjori

                                      • Bebloh/URLZone

                                      • Cryptolocker

                                      • Cryptowall

                                      • Dyre

                                      • Geodo

                                      • Hesperbot

                                      • Matsnu

                                      • Necurs

                                      • P2P GOZ

                                      • PT GOZ / New GOZ

                                      • Pushdo

                                      • Qakbot

                                      • Ramnit

                                      • Symmi

                                      • Tinba / TinyBanker

                                      Here is a list of all the Feeds available:  All Feeds

                                      I would recommend using the two main IP lists which encompass all of the individual Lists:

                                      c2 IP Feed                Master Feed of known, active and non-sinkholed C&Cs IP addresses.

                                      c2 All Indicator Feed  Master Feed of known, active and non-sinkholed C&Cs indicators

                                      Use the "html" Format to download these Lists. Download frequency of atleast once per day.

                                      ** Please read their License and please donate to the charity they run called the "Tumaini Foundation".

                                      If you see Alerts to any of these Lists, please take additional measures to clean up any infections as these IPs are very malicious. So please put these lists into its own Alias.

                                      "Experience is something you don't get until just after you need it."

                                      Website: http://pfBlockerNG.com
                                      Twitter: @BBcan177  #pfBlockerNG
                                      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                                      1 Reply Last reply Reply Quote 0
                                      • panzP
                                        panz
                                        last edited by

                                        «You don't have permission to access /feeds/c2-ipmasterlist.txt on this server.»

                                        pfSense 2.3.2-RELEASE-p1 (amd64)
                                        motherboard: MSI C847MS-E33 Micro ATX (with Intel Celeron CPU 847 @ 1.10 GHz) ~ PSU: Corsair VS350 ~ RAM: Kingston KVR1333D3E9S 4096 MB 240-pin DIMM DDR3 SDRAM 1.5 volt ~ NIC: Intel EXPI9301CTBLK (LAN) ~ NIC: D-Link DFE-528TX (CAM) ~ Hard Disk: Western Digital WD10JFCX Red ~ Case: Cooler Master HAF XB ~ power consumption: 21 Watts.

                                        1 Reply Last reply Reply Quote 0
                                        • D
                                          doktornotor Banned
                                          last edited by

                                          Hmm, apparently people hammered the poor guys. :D

                                          1 Reply Last reply Reply Quote 0
                                          • BBcan177B
                                            BBcan177 Moderator
                                            last edited by

                                            It seems to be fixed now. Post back if you continue to have any issues.

                                            "Experience is something you don't get until just after you need it."

                                            Website: http://pfBlockerNG.com
                                            Twitter: @BBcan177  #pfBlockerNG
                                            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.