Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfBlockerNG v2.0 w/DNSBL

    Scheduled Pinned Locked Moved pfBlockerNG
    1.1k Posts 192 Posters 1.7m Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      AspiringNSATroglodyte
      last edited by

      The issue is that I have selected the option that creates a floating rule to the VIP DNSBL IP but there is no floating rule visible in the GUI. In the past this rule was always created.

      This is on a vanilla pfsense install.

      According to the service status widget, the DNSBL service is running.

      1 Reply Last reply Reply Quote 0
      • BBcan177B
        BBcan177 Moderator
        last edited by

        Did you select the Interface(s) for the Permit Rule?

        "Experience is something you don't get until just after you need it."

        Website: http://pfBlockerNG.com
        Twitter: @BBcan177  #pfBlockerNG
        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

        1 Reply Last reply Reply Quote 0
        • A
          AspiringNSATroglodyte
          last edited by

          @BBcan177:

          Did you select the Interface(s) for the Permit Rule?

          Can you expound on this? Where exactly is this option?

          1 Reply Last reply Reply Quote 0
          • BBcan177B
            BBcan177 Moderator
            last edited by

            @AspiringNSATroglodyte:

            @BBcan177:

            Did you select the Interface(s) for the Permit Rule?

            Can you expound on this? Where exactly is this option?

            DNSBL Tab: DNSBL Firewall Rule: Interface menu options

            "Experience is something you don't get until just after you need it."

            Website: http://pfBlockerNG.com
            Twitter: @BBcan177  #pfBlockerNG
            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

            1 Reply Last reply Reply Quote 0
            • C
              chain
              last edited by

              @BBcan177:

              @chain:

              Is there a way to add this to pfBlockerNG or Aliases, this list of domains

              Hi Chain, that list can be parsed without issues… If that was from a URL, just add the URL to a DNSBL alias ... You could also paste that into a custom list and the package will parse it...

              i did that, but I notices that it don't show up in the list of site to block, that the link below for the site

              http://pastebin.com/050GLwG8

              Its a good site for block windows 7-10 spying on people

              1 Reply Last reply Reply Quote 0
              • BBcan177B
                BBcan177 Moderator
                last edited by

                @chain:

                @BBcan177:

                @chain:

                Is there a way to add this to pfBlockerNG or Aliases, this list of domains

                Hi Chain, that list can be parsed without issues… If that was from a URL, just add the URL to a DNSBL alias ... You could also paste that into a custom list and the package will parse it...

                i did that, but I notices that it don't show up in the list of site to block, that the link below for the site

                http://pastebin.com/050GLwG8

                Its a good site for block windows 7-10 spying on people

                Click the "Raw" button, and you should be able to pull that list with DNSBL, as it removes the HTML formatting…

                http://pastebin.com/raw/050GLwG8

                "Experience is something you don't get until just after you need it."

                Website: http://pfBlockerNG.com
                Twitter: @BBcan177  #pfBlockerNG
                Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                1 Reply Last reply Reply Quote 0
                • BBcan177B
                  BBcan177 Moderator
                  last edited by

                  @AspiringNSATroglodyte:

                  I've attached some pictures to hopefully shed some light on the issue. As I've said, I have configured pfblockerng and DNSBL succesfully many times in the past without issue.

                  Can you run this command and send me the output:

                  grep -B10 -A12 "pfB_DNSBL_Allow_access_to_VIP" /conf/config.xml
                  

                  "Experience is something you don't get until just after you need it."

                  Website: http://pfBlockerNG.com
                  Twitter: @BBcan177  #pfBlockerNG
                  Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                  1 Reply Last reply Reply Quote 0
                  • A
                    AspiringNSATroglodyte
                    last edited by

                    @BBcan177:

                    @AspiringNSATroglodyte:

                    I've attached some pictures to hopefully shed some light on the issue. As I've said, I have configured pfblockerng and DNSBL succesfully many times in the past without issue.

                    Can you run this command and send me the output:

                    grep -B10 -A12 "pfB_DNSBL_Allow_access_to_VIP" /conf/config.xml
                    

                    PM sent

                    1 Reply Last reply Reply Quote 0
                    • BBcan177B
                      BBcan177 Moderator
                      last edited by

                      Sent you a reply.

                      "Experience is something you don't get until just after you need it."

                      Website: http://pfBlockerNG.com
                      Twitter: @BBcan177  #pfBlockerNG
                      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                      1 Reply Last reply Reply Quote 0
                      • A
                        alex3712
                        last edited by

                        Hello BBcan177 thanks for a great package, update for 2.2.6 will or only for 2.3.x?

                        1 Reply Last reply Reply Quote 0
                        • BBcan177B
                          BBcan177 Moderator
                          last edited by

                          @alex3712:

                          Hello BBcan177 thanks for a great package, update for 2.2.6 will or only for 2.3.x?

                          You can upgrade from 2.2.x to 2.3.x and pfBlockerNG will upgrade without issue…

                          "Experience is something you don't get until just after you need it."

                          Website: http://pfBlockerNG.com
                          Twitter: @BBcan177  #pfBlockerNG
                          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                          1 Reply Last reply Reply Quote 0
                          • J
                            Jamerson
                            last edited by

                            Thank you for this BBcan177.
                            I am using it for over a year now everything working really fine.
                            I want to filter the adult website using this package is this even possible or have to install a proxy ?

                            1 Reply Last reply Reply Quote 0
                            • BBcan177B
                              BBcan177 Moderator
                              last edited by

                              @Jamerson:

                              Thank you for this BBcan177.
                              I am using it for over a year now everything working really fine.
                              I want to filter the adult website using this package is this even possible or have to install a proxy ?

                              Just have to add the domains that you want to block into a DNSBL Alias…

                              "Experience is something you don't get until just after you need it."

                              Website: http://pfBlockerNG.com
                              Twitter: @BBcan177  #pfBlockerNG
                              Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                              1 Reply Last reply Reply Quote 0
                              • BBcan177B
                                BBcan177 Moderator
                                last edited by

                                pfBlockerNG v2.0.15 -    Pull Request #140 was merged:

                                See the following for details:
                                    https://github.com/pfsense/FreeBSD-ports/pull/140

                                UPDATE:

                                Please wait for pfBlockerNG v2.0.16 due to the following unescaped variable issue:
                                    https://github.com/pfsense/FreeBSD-ports/pull/143/files

                                "Experience is something you don't get until just after you need it."

                                Website: http://pfBlockerNG.com
                                Twitter: @BBcan177  #pfBlockerNG
                                Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                                1 Reply Last reply Reply Quote 0
                                • ivorI
                                  ivor
                                  last edited by

                                  @BBcan177:

                                  pfBlockerNG v2.0.15 -    Pull Request #140 was merged:

                                  See the following for details:
                                      https://github.com/pfsense/FreeBSD-ports/pull/140

                                  UPDATE:

                                  Please wait for pfBlockerNG v2.0.16 due to the following unescaped variable issue:
                                      https://github.com/pfsense/FreeBSD-ports/pull/143/files

                                  Great job. Just resolved the issue with dnsbl service not starting.

                                  Need help fast? Our support is available 24/7 https://www.netgate.com/support/

                                  1 Reply Last reply Reply Quote 0
                                  • N
                                    nathulal
                                    last edited by

                                    Using pfBlockerNG v2.0.16 I have DNSBL EasyPrivacy turned on from before. It was working fine. After updating to v2.0.16 twitter.com is getting blocked. Was not getting blocked before. I tried to add twitter.com to DNSBL->Custom Domain Suppression (Whitelist) but that doesnt unblock it. If I set the EasyPrivacy feed to Off, twitter.com loads successfully.

                                    1 Reply Last reply Reply Quote 0
                                    • BBcan177B
                                      BBcan177 Moderator
                                      last edited by

                                      @nathulal:

                                      Using pfBlockerNG v2.0.16 I have DNSBL EasyPrivacy turned on from before. It was working fine. After updating to v2.0.16 twitter.com is getting blocked. Was not getting blocked before. I tried to add twitter.com to DNSBL->Custom Domain Suppression (Whitelist) but that doesnt unblock it. If I set the EasyPrivacy feed to Off, twitter.com loads successfully.

                                      You can suppress directly from the Alerts Tab, which will remove the Domain immediately… if you add the domain manually to the Whitelist, you need to select the "update custom list" checkbox, and run a "Force Reload - DNSBL" for it to take effect...

                                      "Experience is something you don't get until just after you need it."

                                      Website: http://pfBlockerNG.com
                                      Twitter: @BBcan177  #pfBlockerNG
                                      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                                      1 Reply Last reply Reply Quote 0
                                      • N
                                        nathulal
                                        last edited by

                                        @BBcan177:

                                        You can suppress directly from the Alerts Tab, which will remove the Domain immediately… if you add the domain manually to the Whitelist, you need to select the "update custom list" checkbox, and run a "Force Reload - DNSBL" for it to take effect...

                                        Ahh thanks for clearing that up. All good now.

                                        1 Reply Last reply Reply Quote 0
                                        • BBcan177B
                                          BBcan177 Moderator
                                          last edited by

                                          @nathulal:

                                          @BBcan177:

                                          You can suppress directly from the Alerts Tab, which will remove the Domain immediately… if you add the domain manually to the Whitelist, you need to select the "update custom list" checkbox, and run a "Force Reload - DNSBL" for it to take effect...

                                          Ahh thanks for clearing that up. All good now.

                                          Ahh crap… I have to make another change to the code as it shouldn't have picked up that Domain name :)  Sorry guys... I will post a PR to get this fixed ASAP...

                                          "Experience is something you don't get until just after you need it."

                                          Website: http://pfBlockerNG.com
                                          Twitter: @BBcan177  #pfBlockerNG
                                          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                                          1 Reply Last reply Reply Quote 0
                                          • BBcan177B
                                            BBcan177 Moderator
                                            last edited by

                                            pfBlockerNG v2.0.17 :
                                                https://github.com/pfsense/FreeBSD-ports/pull/144

                                            This will fix the issue with the EasyPrivacy Feed (As noted above)

                                            I suspect that EasyList will also change file formats at some point, but I will make those changes at that time.

                                            Until the PR is merged, either disable EasyPrivacy, or fetch the file from my Github repo:

                                            –> File below is only for pfSense v2.3.x <–

                                            fetch -o /usr/local/pkg/pfblockerng/pfblockerng.inc "https://raw.githubusercontent.com/BBcan177/FreeBSD-
                                            ports/88fc815594c48f9d99c2f7feb9649a3586a3ca27/net/pfSense-pkg-pfBlockerNG/files/usr/local/pkg/pfblockerng/pfblockerng.inc"
                                            

                                            and run a "Force Reload - DNSBL"

                                            "Experience is something you don't get until just after you need it."

                                            Website: http://pfBlockerNG.com
                                            Twitter: @BBcan177  #pfBlockerNG
                                            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.