Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfBlockerNG

    Scheduled Pinned Locked Moved pfBlockerNG
    1.2k Posts 210 Posters 1.9m Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      doktornotor Banned
      last edited by

      There's no way the package would reinstall in 1 second. Probably you have too many boxes to keep track of what actually was there.

      1 Reply Last reply Reply Quote 0
      • S
        stanthewizard
        last edited by

        Hello

        Got Something strange with PpBlockerNG on alerts tab

        Fatal error: Call to undefined function subnetv6_expand() in /etc/inc/util.inc on line 714

        Any idea what is going wrong ?

        Thanks

        1 Reply Last reply Reply Quote 0
        • BBcan177B
          BBcan177 Moderator
          last edited by

          pfBlockerNG v1.06  has been Merged by the Devs.

          Changelog:

          • Previously when deleting all IPs in the pfBlockerNGSuppress Alias, it would not
            clear the widget Suppression Counter. This version fixes that issue as reported by user "Panz".

          • Merged recent changes in pfSense diag_dns.php into pfblockerng_diag_dns.php to keep code base current.

          • Change Release to "Stable" from previous "Beta" Status.

          Notes -

          The issue reported by "stanthewizard" above is partially due to a missing function in pfSense (subnetv6_expand). I expect that I will need to submit a new Pull Request to fix this issue. I provided him a workaround to fix his issue for now.

          "Experience is something you don't get until just after you need it."

          Website: http://pfBlockerNG.com
          Twitter: @BBcan177  #pfBlockerNG
          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

          1 Reply Last reply Reply Quote 0
          • S
            stanthewizard
            last edited by

            And I thank you for that again

            1 Reply Last reply Reply Quote 0
            • S
              seqteq
              last edited by

              @doktornotor:

              There's no way the package would reinstall in 1 second. Probably you have too many boxes to keep track of what actually was there.

              That was it, it's been a busy year.

              1 Reply Last reply Reply Quote 0
              • V
                varazir
                last edited by

                Hi, Thanks for a great pkg.

                I'm having problem with port forwards and UPnP & NAT-PMP.

                I use this settings for pfBlockerNG:
                Marked all lists
                Top 20 and Asia is blocked, both rest blocked inbound.
                I have added custom lists from Bluetack ads/proxy/spyware and from Squidblacklist ads. All deny both
                Set rule order pfSense pass/match | pfB_pass/match | pfB_block/reject

                TIA

                1 Reply Last reply Reply Quote 0
                • D
                  doktornotor Banned
                  last edited by

                  @varazir:

                  I'm having problem with port forwards and UPnP & NAT-PMP.

                  You need to describe what is your problem…

                  @varazir:

                  I use this settings for pfBlockerNG:
                  Marked all lists
                  Top 20 and Asia is blocked, both rest blocked inbound.

                  What all lists? The country lists? So you blocked whole world inbound, or what? I don't understand your description at all. Plus, block is default on WAN. Are you actually running any service locally that you need to limit access to?

                  1 Reply Last reply Reply Quote 0
                  • V
                    varazir
                    last edited by

                    @doktornotor:

                    @varazir:

                    I'm having problem with port forwards and UPnP & NAT-PMP.

                    You need to describe what is your problem…

                    @varazir:

                    I use this settings for pfBlockerNG:
                    Marked all lists
                    Top 20 and Asia is blocked, both rest blocked inbound.

                    What all lists? The country lists? So you blocked whole world inbound, or what? I don't understand your description at all. Plus, block is default on WAN. Are you actually running any service locally that you need to limit access to?

                    Never mind, me who has got all wrong :( Changed to outbound only and now it's working

                    1 Reply Last reply Reply Quote 0
                    • V
                      varazir
                      last edited by

                      I heard there was host blocking option on it's way?

                      1 Reply Last reply Reply Quote 0
                      • ?
                        A Former User
                        last edited by

                        I just wanted to drop a thank you for a great package. Runs excellent with all the bells running. Error log is empty.
                        Thanks again guys. BBcan177 nice job. Your work is appreciated. ;D

                        ps: just finished reading this post in its entirety and what did you guys "NOT" cover. The post is a manual in its own right. Your patience shows. ::)

                        1 Reply Last reply Reply Quote 0
                        • BBcan177B
                          BBcan177 Moderator
                          last edited by

                          Here is another Threat Source for pfBlockerNG :

                          This feed is provided by :  bambenekconsulting.com

                          These lists cover the following type of Threats:

                          • Banjori

                          • Bebloh/URLZone

                          • Cryptolocker

                          • Cryptowall

                          • Dyre

                          • Geodo

                          • Hesperbot

                          • Matsnu

                          • Necurs

                          • P2P GOZ

                          • PT GOZ / New GOZ

                          • Pushdo

                          • Qakbot

                          • Ramnit

                          • Symmi

                          • Tinba / TinyBanker

                          Here is a list of all the Feeds available:  All Feeds

                          I would recommend using the two main IP lists which encompass all of the individual Lists:

                          c2 IP Feed                Master Feed of known, active and non-sinkholed C&Cs IP addresses.

                          c2 All Indicator Feed  Master Feed of known, active and non-sinkholed C&Cs indicators

                          Use the "html" Format to download these Lists. Download frequency of atleast once per day.

                          ** Please read their License and please donate to the charity they run called the "Tumaini Foundation".

                          If you see Alerts to any of these Lists, please take additional measures to clean up any infections as these IPs are very malicious. So please put these lists into its own Alias.

                          "Experience is something you don't get until just after you need it."

                          Website: http://pfBlockerNG.com
                          Twitter: @BBcan177  #pfBlockerNG
                          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                          1 Reply Last reply Reply Quote 0
                          • panzP
                            panz
                            last edited by

                            «You don't have permission to access /feeds/c2-ipmasterlist.txt on this server.»

                            pfSense 2.3.2-RELEASE-p1 (amd64)
                            motherboard: MSI C847MS-E33 Micro ATX (with Intel Celeron CPU 847 @ 1.10 GHz) ~ PSU: Corsair VS350 ~ RAM: Kingston KVR1333D3E9S 4096 MB 240-pin DIMM DDR3 SDRAM 1.5 volt ~ NIC: Intel EXPI9301CTBLK (LAN) ~ NIC: D-Link DFE-528TX (CAM) ~ Hard Disk: Western Digital WD10JFCX Red ~ Case: Cooler Master HAF XB ~ power consumption: 21 Watts.

                            1 Reply Last reply Reply Quote 0
                            • D
                              doktornotor Banned
                              last edited by

                              Hmm, apparently people hammered the poor guys. :D

                              1 Reply Last reply Reply Quote 0
                              • BBcan177B
                                BBcan177 Moderator
                                last edited by

                                It seems to be fixed now. Post back if you continue to have any issues.

                                "Experience is something you don't get until just after you need it."

                                Website: http://pfBlockerNG.com
                                Twitter: @BBcan177  #pfBlockerNG
                                Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                                1 Reply Last reply Reply Quote 0
                                • BBcan177B
                                  BBcan177 Moderator
                                  last edited by

                                  If your interested to read up on Bambenek Consultings work:

                                  "The New Scourge of Ransomware: A Study of CryptoLocker and Its Friends"

                                  Published on Mar 19, 2015
                                      By Lance James and John Bambenek
                                      https://www.youtube.com/watch?v=X994Rdt-36o

                                  Meat of the video starts at around the 9-10min mark.

                                  "Experience is something you don't get until just after you need it."

                                  Website: http://pfBlockerNG.com
                                  Twitter: @BBcan177  #pfBlockerNG
                                  Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                                  1 Reply Last reply Reply Quote 0
                                  • T
                                    taryezveb
                                    last edited by

                                    @BBcan177:

                                    Here is another Threat Source for pfBlockerNG :

                                    This feed is provided by :  bambenekconsulting.com

                                    These lists cover the following type of Threats:

                                    • Banjori

                                    • Bebloh/URLZone

                                    • Cryptolocker

                                    • Cryptowall

                                    • Dyre

                                    • Geodo

                                    • Hesperbot

                                    • Matsnu

                                    • Necurs

                                    • P2P GOZ

                                    • PT GOZ / New GOZ

                                    • Pushdo

                                    • Qakbot

                                    • Ramnit

                                    • Symmi

                                    • Tinba / TinyBanker

                                    Here is a list of all the Feeds available:  All Feeds

                                    I would recommend using the two main IP lists which encompass all of the individual Lists:

                                    c2 IP Feed                Master Feed of known, active and non-sinkholed C&Cs IP addresses.

                                    c2 All Indicator Feed  Master Feed of known, active and non-sinkholed C&Cs indicators

                                    Use the "html" Format to download these Lists. Download frequency of atleast once per day.

                                    ** Please read their License and please donate to the charity they run called the "Tumaini Foundation".

                                    If you see Alerts to any of these Lists, please take additional measures to clean up any infections as these IPs are very malicious. So please put these lists into its own Alias.

                                    Thanks for this and your work on pfBlockerNG; a welcomed upgrade to
                                    pfBlocker.

                                    Just started using pflockerNG and have a suggestion. When clicking on
                                    the 'Cancel' button instead of reloading the page, it should take you
                                    back to the previous page. For example, when editing/adding an
                                    alias/list would take you back to the main alias/list page.

                                    Maybe others like the current function. Just seems that when canceling
                                    should go to the previous page, a reload does not convey that whatever
                                    was done was canceled.

                                    Thank You

                                    1 Reply Last reply Reply Quote 0
                                    • C
                                      ConfusedUser
                                      last edited by

                                      Hi All,

                                      The filter function for the alerts doesn't seem to be working properly (pfSense 2.2.1, pfBlockerNG 1.06).
                                      For example right now when I have a look at my alerts only within the last 2 hours I have 5 entries with destination port 25.
                                      In the total list (500 entries, around 2 days) there are around 100 entries with destination port 25.

                                      When I set a filter for destination port = 25 it displays only three items (out of the approximate 100) and when I change the filter to ^25$ then only one entry (the most recent one) is displayed.
                                      Any idea what I can try to be able to correctly filter by destination port?

                                      1 Reply Last reply Reply Quote 0
                                      • BBcan177B
                                        BBcan177 Moderator
                                        last edited by

                                        @taryezveb:

                                        When clicking on the 'Cancel' button instead of reloading the page, it should take you
                                        back to the previous page.

                                        In my setup, this is what it does, so not sure why it doesn't do that for you? The code for this is in pfSense base code, (pkg_edit.php). What theme are you using?

                                        "Experience is something you don't get until just after you need it."

                                        Website: http://pfBlockerNG.com
                                        Twitter: @BBcan177  #pfBlockerNG
                                        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                                        1 Reply Last reply Reply Quote 0
                                        • BBcan177B
                                          BBcan177 Moderator
                                          last edited by

                                          @ConfusedUser:

                                          When I set a filter for destination port = 25 it displays only three items (out of the approximate 100) and when I change the filter to ^25$ then only one entry (the most recent one) is displayed.
                                          Any idea what I can try to be able to correctly filter by destination port?

                                          Hi ConfuesedUser, what did you input in the "Deny Entries" in the Alert Settings at the top of the Alerts Page? It will only report this number of Alerts (With/without Filtering). My tests show everything to be ok with all of the Filtering options?

                                          "Experience is something you don't get until just after you need it."

                                          Website: http://pfBlockerNG.com
                                          Twitter: @BBcan177  #pfBlockerNG
                                          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                                          1 Reply Last reply Reply Quote 0
                                          • T
                                            taryezveb
                                            last edited by

                                            @BBcan177:

                                            In my setup, this is what it does, so not sure why it doesn't do that
                                            for you? The code for this is in pfSense base code, (pkg_edit.php). What
                                            theme are you using?

                                            Using the pfsense_ng theme, reverted to the pfsense theme. Still get the
                                            same in chromium and firefox; after logging out closing the window and
                                            opening a new window and logging back in. In case that would make a
                                            difference.

                                            Thank You

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.