• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

PfBlockerNG v2.1 w/TLD

pfBlockerNG
42
124
251.0k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • F
    f34rinc
    last edited by Jul 29, 2016, 2:51 PM

    Nice work BBcan177  :D  setup blocking of .ru as a test and it works.

    1 Reply Last reply Reply Quote 0
    • D
      DownloadDeviant
      last edited by Jul 29, 2016, 5:46 PM

      THANKS! Can't wait! Good stuff….great work...and thanks for helping us dumb dumbs  :P here and over at Reddit!

      PS - is there a quick n dirty way to test PFBNG to be sure you've generally set it up correctly? Like going to a website and not seeing ads, etc.?

      System: pfSense 2.4.3p1 - ZFS CPU: AMD Athlon 5350 (Kabini) MOBO: ASRock AM1H-ITX HD: 60GB SSD Patriot Inferno RAM: G.SKILL 8GB DDR3 2133 NIC: Intel I350-T2 PS: Lite-On 75W AC PACKAGES: Cron, NUT

      1 Reply Last reply Reply Quote 0
      • M
        mauroman33
        last edited by Jul 29, 2016, 9:12 PM

        Thank you so much for this fantastic work!!!

        1 Reply Last reply Reply Quote 0
        • B
          BBcan177 Moderator
          last edited by Jul 29, 2016, 10:27 PM

          @DownloadDeviant:

          THANKS! Can't wait! Good stuff….great work...and thanks for helping us dumb dumbs  :P here and over at Reddit!

          PS - is there a quick n dirty way to test PFBNG to be sure you've generally set it up correctly? Like going to a website and not seeing ads, etc.?

          Thanks… Are you on the latest 2.1.1_1 version?  Haven't heard much feedback yet, so not sure if many have installed it yet...

          Not sure what sites are the worst for ADs... but yahoo is probably up there....

          @mauroman33:

          Thank you so much for this fantastic work!!!

          Thanks!

          "Experience is something you don't get until just after you need it."

          Website: http://pfBlockerNG.com
          Twitter: @BBcan177  #pfBlockerNG
          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

          1 Reply Last reply Reply Quote 0
          • D
            DownloadDeviant
            last edited by Jul 30, 2016, 12:02 AM

            @BBcan177:

            Thanks… Are you on the latest 2.1.1_1 version?  Haven't heard much feedback yet, so not sure if many have installed it yet...

            Not sure what sites are the worst for ADs... but yahoo is probably up there....

            I'm still on 2.0.17. I've slowed down my updating a bit since I've had some snags and had to rebuild 3 times in the past 7 weeks. Two were my fault…lol I thought I had router plugged into the battery port on the UPS but didn't...storm hit...lost power...pf went corrupt. Sooooooooo, I'm a bit worn out on tampering right now. lol That said, I'll probably upgrade it this weekend.

            Yahoo it is then. I'm very new to pfBNG so I need to learn it and get comfortable. I don't want to get  too aggressive. I just want it to serve as a companion for my Firefox plugins and to help keep my girlfriend protected.

            System: pfSense 2.4.3p1 - ZFS CPU: AMD Athlon 5350 (Kabini) MOBO: ASRock AM1H-ITX HD: 60GB SSD Patriot Inferno RAM: G.SKILL 8GB DDR3 2133 NIC: Intel I350-T2 PS: Lite-On 75W AC PACKAGES: Cron, NUT

            1 Reply Last reply Reply Quote 0
            • S
              someuser123
              last edited by Jul 30, 2016, 12:21 AM

              pfBlockerNG-2.1.1_1 is working like charm, On 2.3.3-DEVELOPMENT (amd64) no issues.

              TLD Blacklist is really handy, Thanks BBcan177

              1 Reply Last reply Reply Quote 0
              • B
                BBcan177 Moderator
                last edited by Aug 22, 2016, 2:30 AM Jul 30, 2016, 4:52 AM

                Here are the links for Malware Corpus Tracker which can be used w/ pfBlockerNG DNSBL:

                Site:
                http://track.h3x.eu/about/400

                Available Feeds:
                https://tracker.h3x.eu/api/sites_1month.php
                https://tracker.h3x.eu/api/sites_1week.php
                https://tracker.h3x.eu/api/sites_1day.php
                https://tracker.h3x.eu/api/sites_1hour.php

                DO NOT Select all of these Feeds. You should pick only one Feed. For example: the "1Month" will include the "1Week/1Day/1Hour".

                [ Edit - change to https ]

                Twitter:
                https://twitter.com/h3x2b

                "Experience is something you don't get until just after you need it."

                Website: http://pfBlockerNG.com
                Twitter: @BBcan177  #pfBlockerNG
                Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                1 Reply Last reply Reply Quote 0
                • N
                  ntct
                  last edited by Jul 30, 2016, 6:10 AM Jul 30, 2016, 6:06 AM

                  Hi BBcan177,

                  I can't update h3x feed from available feeds list in pfBlockerNG v2.1.

                  It show below.

                  [ h3x ]			 Downloading update .. 200 OK
                   Remote timestamp missing 
                   No Domains Found
                  

                  And I can't let TLD Exclusion List working. Can you give a example or check it works?

                  1 Reply Last reply Reply Quote 0
                  • R
                    RonpfS
                    last edited by Jul 30, 2016, 9:26 AM

                    @ntct:

                    Hi BBcan177,

                    I can't update h3x feed from available feeds list in pfBlockerNG v2.1.

                    It show below.

                    [ h3x ]			 Downloading update .. 200 OK
                     Remote timestamp missing 
                     No Domains Found
                    

                    Same here

                    @ntct:

                    And I can't let TLD Exclusion List working. Can you give a example or check it works?

                    Did you do a Force Reload after changing the list ?

                    2.4.5-RELEASE-p1 (amd64)
                    Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                    Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                    1 Reply Last reply Reply Quote 0
                    • H
                      hulleyrob
                      last edited by Jul 30, 2016, 11:34 AM

                      [ 1month ]		 Downloading update .. 200 OK
                        Remote timestamp missing 
                       No Domains Found
                      
                      [ 1week ]		 Downloading update [ 07/30/16 12:31:20 ] .. 200 OK
                        Remote timestamp missing 
                       No Domains Found
                      
                      [ 1day ]		 Downloading update .. 200 OK
                        Remote timestamp missing 
                       No Domains Found
                      
                      [ 1hour ]		 Downloading update .. 200 OK
                        Remote timestamp missing 
                       No Domains Found
                      

                      Me three, anyone post how exactly you get these list working?

                      1 Reply Last reply Reply Quote 0
                      • B
                        BBcan177 Moderator
                        last edited by Jul 30, 2016, 12:40 PM

                        Here is a patch to fix the H3X Feed…  Sorry about that  ...

                        @BBcan177:

                        Here are the links for Malware Corpus Tracker which can be used w/ pfBlockerNG DNSBL:

                        UPDATE:

                        Guess the internal QA testing didn't work too well when I tested this Feed.
                        Please follow these instructions below to patch the code to get the following feed to parse:

                        Edit     /usr/local/pkg/pfblockerng/pfblockerng.inc

                        Goto Line 3368 which contains the following:

                        $h3x_feed = TRUE;
                        

                        Reference:
                        https://github.com/pfsense/FreeBSD-ports/blob/devel/net/pfSense-pkg-pfBlockerNG/files/usr/local/pkg/pfblockerng/pfblockerng.inc#L3368

                        and add the following line after line 3368:

                        $liteparser = TRUE;
                        

                        Then follow that with a    "Force Update"

                        "Experience is something you don't get until just after you need it."

                        Website: http://pfBlockerNG.com
                        Twitter: @BBcan177  #pfBlockerNG
                        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                        1 Reply Last reply Reply Quote 0
                        • B
                          BBcan177 Moderator
                          last edited by Jul 30, 2016, 12:42 PM

                          @ntct:

                          And I can't let TLD Exclusion List working. Can you give a example or check it works?

                          Can you provide more detail about what you're trying to accomplish?

                          "Experience is something you don't get until just after you need it."

                          Website: http://pfBlockerNG.com
                          Twitter: @BBcan177  #pfBlockerNG
                          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                          1 Reply Last reply Reply Quote 0
                          • H
                            hulleyrob
                            last edited by Jul 30, 2016, 12:42 PM

                            Works for me.

                            For the lazy:

                            vi +3368 /usr/local/pkg/pfblockerng/pfblockerng.inc
                            

                            to go straight to the line.

                            Thanks BBcan

                            1 Reply Last reply Reply Quote 0
                            • B
                              BBcan177 Moderator
                              last edited by Jul 30, 2016, 8:37 PM

                              I have posted a PR #164 to fix the H3x parser issue noted above.
                              ‎https://github.com/pfsense/FreeBSD-ports/pull/164‎

                              Once this is merged the pkg will be at version 2.1.1_2.

                              If you manually edited the file noted above, or not, you do not need to make any further changes with this version.

                              "Experience is something you don't get until just after you need it."

                              Website: http://pfBlockerNG.com
                              Twitter: @BBcan177  #pfBlockerNG
                              Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                              1 Reply Last reply Reply Quote 0
                              • O
                                oddworld19
                                last edited by Jul 31, 2016, 12:14 AM Jul 30, 2016, 11:31 PM

                                …...and I'm buying another 8 gigs RAM tonight (from 8G to 16G) now that unbound is VIRT 12.3G and I've swapped 6G.

                                Worth it though.

                                Supermicro SYS-5018A-FTN4 (Atom c2758)
                                pfSense 2.3.2

                                1 Reply Last reply Reply Quote 0
                                • A
                                  Andrew453
                                  last edited by Jul 31, 2016, 9:32 AM

                                  Hi BBcan177

                                  Thanks for implementing this.  Would you be able to explain a bit more what the role of the /usr/local/pkg/pfblockerng/dnsbl_tld file is please?

                                  I was expecting it to contain a pure list of TLDs which pfblockerng can then use to work out whether any given domain is a second level domain or higher.  But it seems itself to contain some second level domains?

                                  That said, when I've looked that the /var/unbound/pfb_dnsbl.conf on my set up that pfblockerng has created, it does contain exactly what I would expect to see (i.e. full blocking of the entire domain for second level domains, but only specific blocking for higher level domains).  So it does seem to be doing exactly what I'd like it to, but I'm not sure how the dnsbl_tld file is working to do that.

                                  Thanks.

                                  1 Reply Last reply Reply Quote 0
                                  • Q
                                    Qinn
                                    last edited by Jul 31, 2016, 9:44 AM

                                    Hi BBcan177,

                                    Is there any good install/setup/configure instruction (video or guide) for the last version op pfblockerNG, that you could/would recommend?

                                    Thanks for your advice, cheers Qinn

                                    Hardeware: Intel(R) Celeron(R) J4125 CPU @ 2.00GHz 102 GB mSATA SSD (ZFS)
                                    Firmware: Latest-stable-pfSense CE (amd64)
                                    Packages: pfBlockerNG devel-beta (beta tester) - Avahi - Notes - Ntopng - PIMD/udpbroadcastrelay - Service Watchdog - System Patches

                                    1 Reply Last reply Reply Quote 0
                                    • B
                                      BBcan177 Moderator
                                      last edited by Jul 31, 2016, 9:53 AM

                                      @Andrew453:

                                      I was expecting it to contain a pure list of TLDs which pfblockerng can then use to work out whether any given domain is a second level domain or higher.  But it seems itself to contain some second level domains?

                                      Hi Andrew453,

                                      If I only used the TLD, it would be a simple process of looking at any listed Domain and seeing if it had only a second-level Domain (SLD) then block the entire Domain. However, there are suffixes like "uk.com" which is what I would call the TLD that is used to determine if there is one more level. So all of the TLDs (suffixes) in that file are known TLDs which is used in the determination process. Most of the file was taken from the "Public Suffix Registry".

                                      "Experience is something you don't get until just after you need it."

                                      Website: http://pfBlockerNG.com
                                      Twitter: @BBcan177  #pfBlockerNG
                                      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                                      1 Reply Last reply Reply Quote 0
                                      • B
                                        BBcan177 Moderator
                                        last edited by Jul 31, 2016, 9:55 AM

                                        @Qinn:

                                        Hi BBcan177,

                                        Is there any good install/setup/configure instruction (video or guide) for the last version op pfblockerNG, that you could/would recommend?

                                        Thanks for your advice, cheers Qinn

                                        There is a pfSense Hangout that I did which can be used for an overview of the pkg functionality. However, apart from the three main pfBlockerNG threads in this forum, there isn't any other documentation.

                                        "Experience is something you don't get until just after you need it."

                                        Website: http://pfBlockerNG.com
                                        Twitter: @BBcan177  #pfBlockerNG
                                        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                                        1 Reply Last reply Reply Quote 0
                                        • Q
                                          Qinn
                                          last edited by Jul 31, 2016, 10:01 AM

                                          Thanks for the quick reply. Darn  :( I found this one can you can agree to this one?

                                          https://www.youtube.com/watch?v=YLhDOaH0q5U

                                          Hardeware: Intel(R) Celeron(R) J4125 CPU @ 2.00GHz 102 GB mSATA SSD (ZFS)
                                          Firmware: Latest-stable-pfSense CE (amd64)
                                          Packages: pfBlockerNG devel-beta (beta tester) - Avahi - Notes - Ntopng - PIMD/udpbroadcastrelay - Service Watchdog - System Patches

                                          1 Reply Last reply Reply Quote 0
                                          20 out of 124
                                          • First post
                                            20/124
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.