• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Unable to get DNSBL to work using pfBlockerNG

Scheduled Pinned Locked Moved pfBlockerNG
17 Posts 4 Posters 6.7k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K Offline
    kiekar
    last edited by Mar 2, 2017, 8:41 PM

    Hello and thank you for your support. I made some screen shots of the logs but unfortunately I think it's still not working. For one thing I still see o packets on the widget.

    When you browse to the VIP you should see 1x1px GIF.

    I only see a blank screen on the edge and EI browser and a black screen on chrome when I enter in the browser 10.10.10.1.

    I'm not quite sure what to make from the logs below.
    .

    DNSBL-Alert.jpg
    DNSBL-Alert.jpg_thumb
    DNSB-Logs.jpg
    DNSB-Logs.jpg_thumb

    1 Reply Last reply Reply Quote 0
    • R Offline
      RonpfS
      last edited by Mar 2, 2017, 8:52 PM

      The Alerts Tab will only show one blocked access for repeated blocks.
      DNSBL.log will log all accesses.

      You have to make sure that you lan devices use pfSense resolver for DNS resolution. Check the DNS configuration on the LAN devices.

      To test, go to Firewall / pfBlockerNG / Log Browser / DNSBL files and test with some domain names that are listed in there.

      2.4.5-RELEASE-p1 (amd64)
      Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
      Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

      1 Reply Last reply Reply Quote 0
      • K Offline
        kiekar
        last edited by Mar 2, 2017, 9:16 PM

        I selected from the adaway.txt file: www.smartadserver.com and entered it in the browser where by the site loaded.

        Could the issue stem from me using PIA (Private Internet Access). I'm using DHCP static mappings.

        Static-Mappings.jpg
        Static-Mappings.jpg_thumb
        DNS-Resolver.jpg
        DNS-Resolver.jpg_thumb

        1 Reply Last reply Reply Quote 0
        • R Offline
          RonpfS
          last edited by Mar 2, 2017, 9:27 PM

          So this Device does NOT use pfSense DNS Resolver for address resolution.
          Leave the field empty as suggested

          "Note: leave blank to use the system default DNS servers - this interface's IP if DNS Forwarder or Resolver is enabled, otherwise the servers configured on the General page. "

          2.4.5-RELEASE-p1 (amd64)
          Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
          Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

          1 Reply Last reply Reply Quote 0
          • K Offline
            kiekar
            last edited by Mar 2, 2017, 9:59 PM

            Looks like it's working now I see more alerts now and the counter for the widget is increasing. The only anoyence is I have my antiviruis popping up. I do have one concern thow is may have a DNS leak now since I'm not using there DNS servers. I will need to do some tests

            Can I have easylist and DNSBL working together?

            DNSBL-Alert2.jpg
            DNSBL-Alert2.jpg_thumb
            Antivirus.jpg
            Antivirus.jpg_thumb

            1 Reply Last reply Reply Quote 0
            • R Offline
              RonpfS
              last edited by Mar 2, 2017, 10:02 PM

              @kiekar:

              Can I have easylist and DNSBL working together?

              Yes you can.

              2.4.5-RELEASE-p1 (amd64)
              Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
              Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

              1 Reply Last reply Reply Quote 0
              • K Offline
                kiekar
                last edited by Mar 2, 2017, 10:05 PM

                Ok will try easylist. Once again thanks for your support, much appreciated.

                1 Reply Last reply Reply Quote 0
                • R Offline
                  RonpfS
                  last edited by Mar 2, 2017, 10:18 PM

                  @kiekar:

                  I do have one concern thow is may have a DNS leak now since I'm not using there DNS servers. I will need to do some tests

                  If you tests show DNS leaks, try configuring DNS resolver in Forwarding mode.

                  2.4.5-RELEASE-p1 (amd64)
                  Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                  Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                  1 Reply Last reply Reply Quote 0
                  • K Offline
                    kiekar
                    last edited by Mar 4, 2017, 3:01 AM

                    Well I'm Back,

                    Unfortunately I'm unable to get both DNSBL and PIA working togeather. As soon as I remove the DNS Server IP address from the DHCP Static mapping page, I get a DNS Leak when testing but the DNSBL is working perfectly. I tried enabling forwarding mode on DNS Resolver and  adding the PIA DNS Server IP addresses to the DNS server settings at System / General Setup page but again still had the DNS leak when testing. Any other ideas would be much appreciated.

                    Regards

                    1 Reply Last reply Reply Quote 0
                    • R Offline
                      RonpfS
                      last edited by Mar 4, 2017, 3:27 AM

                      You should probably open a Topic in the DHCP and DNS forum now as DNS leaks don't come from DNSBL.

                      2.4.5-RELEASE-p1 (amd64)
                      Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                      Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                      1 Reply Last reply Reply Quote 0
                      • M Offline
                        micropone
                        last edited by Mar 20, 2017, 10:04 PM

                        dont worry i'm in the same boat… after i updated to 2.3.3 all my list stopped working..i cant figure it out... none of my config changed... now i see porn and stupid ads...

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                          This community forum collects and processes your personal information.
                          consent.not_received