Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfBlockerNG

    Scheduled Pinned Locked Moved pfBlockerNG
    1.2k Posts 210 Posters 1.8m Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      Mr. Jingles
      last edited by

      @doktornotor:

      The suppress alias is visible in normal pfS aliases list (pfBlockerNGSuppress). Also, works only for /24 and /32.
      Any of the Alias list actions are for manually created rules only. No auto rules will be created for these.

      Thanks for clarifying this, Dok  ;D

      Why doesn't it create the rules automatically? On the todo-list?

      6 and a half billion people know that they are stupid, agressive, lower life forms.

      1 Reply Last reply Reply Quote 0
      • D
        doktornotor Banned
        last edited by

        No, definitely not on todo list, it's a feature. If you want auto rules to pass traffic, use the list action Permit {Inbound,Outbound,Both}.

        1 Reply Last reply Reply Quote 0
        • S
          SkyHawk
          last edited by

          I have searched the forums for a couple of hours, forced update, forced cron, reload reload, and even rebooted - still have this error.  Does anyone know how I might be able to resolve this?

          Thanks

          Sanity Check (Not Including IPv6)  ** These two Counts should Match! **
          –----------
          Masterfile Count    [ 100076 ]
          Deny folder Count  [ 100061 ]

          1 Reply Last reply Reply Quote 0
          • BBcan177B
            BBcan177 Moderator
            last edited by

            Hi SkyHawk,

            Try to Disable "Keep Setting" and Disable "pfBlockerNG", then hit "Save"… This will do a full clear of all the files.  Re-apply "Keep" and Re-Enable pfBNG, followed by a "Force Update" and see if that clears the discrepancy...

            "Experience is something you don't get until just after you need it."

            Website: http://pfBlockerNG.com
            Twitter: @BBcan177  #pfBlockerNG
            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

            1 Reply Last reply Reply Quote 0
            • BBcan177B
              BBcan177 Moderator
              last edited by

              Hi Mr. Jingles,

              When you click on the "+" Icon to suppress an IP, it will clear that IP from the pfSense Alias Table that originally contained the IP. It then adds that IP to a pfSense Alias called "pfBlockerNGSuppress". When the lists are downloaded, any IP in this Alias will be suppressed. So it does not generate a Firewall Rule.

              You can only suppress a /32 or a /24 Block… So if in the Alerts tab, you see the Alert was blocked by a /19 for example, you will need to put the IP that you want to allow into a "Permit Outbound" Alias (Custom Box entry). The order of the Rules is important, so that you will require this Permit Outbound Rule to be above the Block rules. You can change the order of the Rules in the "Rules Order" Setting in the "General Tab"

              "Experience is something you don't get until just after you need it."

              Website: http://pfBlockerNG.com
              Twitter: @BBcan177  #pfBlockerNG
              Reddit: https://www.reddit.com/r/pfBlockerNG/new/

              1 Reply Last reply Reply Quote 0
              • S
                SkyHawk
                last edited by

                @BBcan177:

                Hi SkyHawk,

                Try to Disable "Keep Setting" and Disable "pfBlockerNG", then hit "Save"… This will do a full clear of all the files.  Re-apply "Keep" and Re-Enable pfBNG, followed by a "Force Update" and see if that clears the discrepancy...

                Thank you BBcan177 this needs to be on a sticky or something.  I did as you suggested; then after Re-apply "Keep" and Re-Enable pfBNG I hit "Save" followed by a "Force Update" and poof - the error was resolved.

                1 Reply Last reply Reply Quote 0
                • K
                  Kytran
                  last edited by

                  Thank you, BBCan177!
                  I try install pfBlockerNG in my firewall and config block some range IP.
                  I force update but it's not update anything and cannot download some range list.
                  It just show result:
                  "  No Updates required.
                  CRON  PROCESS  ENDED
                  UPDATE PROCESS ENDED"
                  and
                  "===[  Aliastables / Rules  ]================================

                  No Changes to Firewall Rules, Skipping Filter Reload

                  No Changes to Aliases, Skipping pfctl Update "
                  So, Could you tell some way to pfBlockerNG can update, please!
                  Thanks.

                  1 Reply Last reply Reply Quote 0
                  • BBcan177B
                    BBcan177 Moderator
                    last edited by

                    Hi Kytran,

                    In the Alias settings, did you configure the "Update Frequency"? Which Lists are you trying to use? Did the lists download initially?

                    Cron will execute each hour, the package will check each alias to see if the "Update Frequency" setting is within the current hour, and if so it will perform an update. The message "No Updates required" means none of the defined Aliases require to be updated at this particular Hour interval.

                    "Experience is something you don't get until just after you need it."

                    Website: http://pfBlockerNG.com
                    Twitter: @BBcan177  #pfBlockerNG
                    Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                    1 Reply Last reply Reply Quote 0
                    • K
                      Kytran
                      last edited by

                      Hi BBcan177,
                      I chose some country to block, but not config list action yet, I change config and it's can update list alias.
                      Thanks!

                      1 Reply Last reply Reply Quote 0
                      • M
                        Mr. Jingles
                        last edited by

                        BB  :-* :-* :-* :-* :-*

                        I will respond later with some useless text, but this one is not useless ( ;D ): I am amazed by your package, to me, while playing with it, it seems you've thought of some many things, and it is so fast. Your package to me is like the attached pic (and you know how I feel about these women.. ;D ;D ;D ).

                        Ciao BB,

                        BB001.jpg
                        BB001.jpg_thumb

                        6 and a half billion people know that they are stupid, agressive, lower life forms.

                        1 Reply Last reply Reply Quote 0
                        • G
                          GoldServe
                          last edited by

                          Is there a known issue generating a custom list with an ip block of /8?

                          I tried 17.0.0.0/8 for all of Apple's servers but when I look at the table, I only see 17.0.0.0

                          When I tried 17.0.0.0/10, I see exactly 17.0.0.0/10 in the table.

                          1 Reply Last reply Reply Quote 0
                          • BBcan177B
                            BBcan177 Moderator
                            last edited by

                            Hi GoldServe, there is a small bug that I have fixed. I am putting together some other changes/features for version 1.07 and this will be included.

                            I will send you a PM shortly with a fix until v1.07 is released.

                            "Experience is something you don't get until just after you need it."

                            Website: http://pfBlockerNG.com
                            Twitter: @BBcan177  #pfBlockerNG
                            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                            1 Reply Last reply Reply Quote 0
                            • G
                              GoldServe
                              last edited by

                              Thanks! I tried the patch and all is working…

                              1 Reply Last reply Reply Quote 0
                              • M
                                Mr. Jingles
                                last edited by

                                Hi BB  :D

                                I get this error constantly every day:

                                
                                [ pfB_PRI3 Juniper ] Download FAIL [ 04/14/15 18:00:27 ]
                                
                                

                                The list does exist, 'though:

                                https://www.juniper.net/security/auto/spam

                                It is set to html (by default).

                                Would your Royalty have any idea?

                                Thank you  ;D

                                6 and a half billion people know that they are stupid, agressive, lower life forms.

                                1 Reply Last reply Reply Quote 0
                                • BBcan177B
                                  BBcan177 Moderator
                                  last edited by

                                  Hi Mr. Jingles,

                                  Take a look at the pfblockerng.log  and/or the error.log … Both of these log files are accessible in the Log Browser Tab. It should give you clues as to why its failed.

                                  "Experience is something you don't get until just after you need it."

                                  Website: http://pfBlockerNG.com
                                  Twitter: @BBcan177  #pfBlockerNG
                                  Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                                  1 Reply Last reply Reply Quote 0
                                  • H
                                    Hakim
                                    last edited by

                                    Hi,

                                    Since I upgrade from 2.2 to 2.2.2, I cannot change my NAT rules (well I can change them, but they do not apply).

                                    In fact, I also change pfBlocker to pfBlockerNG.

                                    And if I stop pfBlockerNG then my NAT changes are applied, I can make further NAT changes and they apply correctly.
                                    As soon as I start pfBlockerNG, existing NAT settings are correctly applied, but I cannot change them (until I stop pfBlockerNG).

                                    My global settings include :

                                    <inbound_interface>opt1,wan</inbound_interface>
                                    <inbound_deny_action>block</inbound_deny_action>
                                    <outbound_interface>lan,opt2</outbound_interface>
                                    <outbound_deny_action>reject</outbound_deny_action>
                                    
                                    

                                    And I have 1 IPv4 Alias :

                                     <pfblockernglistsv4><config><action>Deny_Both</action>
                                    		<cron>04hours</cron>
                                    		<dow>1</dow>
                                    		<aliaslog>enabled</aliaslog>
                                    		 <custom><custom_update>disabled</custom_update></custom></config></pfblockernglistsv4> 
                                    
                                    

                                    Any idea about what could be wrong ?

                                    Thanks,
                                    Hakim

                                    1 Reply Last reply Reply Quote 0
                                    • D
                                      doktornotor Banned
                                      last edited by

                                      @Hakim:

                                      Since I upgrade from 2.2 to 2.2.2, I cannot change my NAT rules (well I can change them, but they do not apply).

                                      As noted right above your comments, logs exist for a reason… ;)

                                      1 Reply Last reply Reply Quote 0
                                      • M
                                        Mr. Jingles
                                        last edited by

                                        @BBcan177:

                                        Hi Mr. Jingles,

                                        Take a look at the pfblockerng.log  and/or the error.log … Both of these log files are accessible in the Log Browser Tab. It should give you clues as to why its failed.

                                        Thanks BB  ;D

                                        I got that previous quote from error.log, wasn't awake enough to realize there was also info contained in another log:

                                        [ Juniper ]          Downloading New File
                                        looking up www.juniper.net
                                        connecting to www.juniper.net:443
                                        SSL options: 81004bff
                                        Peer verification enabled
                                        Using CA cert file: /usr/local/etc/ssl/cert.pem
                                        Certificate verification failed for /C=IE/O=Baltimore/OU=CyberTrust/CN=Baltimore CyberTrust Root
                                        34381026664:error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed:/usr/pfSensesrc/src/secure/lib/libssl/../../../crypto/openssl/ssl/s3_clnt.c:1162:
                                        fetch: https://www.juniper.net/security/auto/spam: Authentication error

                                        [ pfB_PRI3 Juniper ] Download FAIL [ 04/18/15 7:00:29 ]

                                        6 and a half billion people know that they are stupid, agressive, lower life forms.

                                        1 Reply Last reply Reply Quote 0
                                        • H
                                          Hakim
                                          last edited by

                                          As noted right above your comments, logs exist for a reason…

                                          No doubt about it, but in this case, no clue in the logs (in fact nothing is logged - on pfBlockerNG side when I made a change in the firewall / NAT UI settings).

                                          On the System/General log I only have :
                                          check_reload_status: Reloading filter
                                          check_reload_status: Syncing firewall

                                          1 Reply Last reply Reply Quote 0
                                          • D
                                            doktornotor Banned
                                            last edited by

                                            pfBNG has nothing to do with NAT. You simply most likely have some broken alias coming from the pfBNG lists you did set up that breaks the firewall rules altogether. Again, there are logs for a reason.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.