Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNSBL not working with vpn

    Scheduled Pinned Locked Moved pfBlockerNG
    15 Posts 2 Posters 2.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • BBcan177B
      BBcan177 Moderator
      last edited by

      Take a look here:
      https://www.reddit.com/r/PFSENSE/comments/8o8zf1/pfblockerng_adblock_on_all_vlans/

      "Experience is something you don't get until just after you need it."

      Website: http://pfBlockerNG.com
      Twitter: @BBcan177  #pfBlockerNG
      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

      X 1 Reply Last reply Reply Quote 0
      • X
        xerno @BBcan177
        last edited by

        @bbcan17 Im a beginner in this and having trouble following you.
        my vpn is using dhcp with the dns from general tab
        103.86.96.100
        103.86.99.100
        If I delete or change these the whole internet stops working.

        BBcan177B 1 Reply Last reply Reply Quote 0
        • BBcan177B
          BBcan177 Moderator @xerno
          last edited by

          @xerno The lan devices have to use pfSense IP address so that Unbound/DNSBL will reply... If you set your LAN devices DNS to use the General Tab DNS IPs, then that will bypass Unbound and DNSBL will not filter it.

          "Experience is something you don't get until just after you need it."

          Website: http://pfBlockerNG.com
          Twitter: @BBcan177  #pfBlockerNG
          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

          X 1 Reply Last reply Reply Quote 0
          • X
            xerno @BBcan177
            last edited by

            @bbcan17 Ok I set my windows machine to use pfsense ip as dns but ads are still showing up

            BBcan177B 1 Reply Last reply Reply Quote 0
            • BBcan177B
              BBcan177 Moderator @xerno
              last edited by

              @xerno DNSBL will only block the AD domains that are in the DNSBL Feeds that you defined.

              See this thread:
              https://forum.netgate.com/topic/91736/pfblockerng-v2-0-w-dnsbl

              "Experience is something you don't get until just after you need it."

              Website: http://pfBlockerNG.com
              Twitter: @BBcan177  #pfBlockerNG
              Reddit: https://www.reddit.com/r/pfBlockerNG/new/

              X 1 Reply Last reply Reply Quote 0
              • X
                xerno @BBcan177
                last edited by

                @bbcan17 Yes I have configured the feeds. It was working until I setup the vpn.

                BBcan177B 1 Reply Last reply Reply Quote 0
                • BBcan177B
                  BBcan177 Moderator @xerno
                  last edited by

                  @xerno

                  Ensure that from this LAN Device, that you can:

                  1. ping the DNSBL VIP and get a reply
                  2. Browse to the DNSBL VIP and get the 1x1 pixel
                  3. ping one of the DNSBL domains and get the DNSBL VIP Address

                  "Experience is something you don't get until just after you need it."

                  Website: http://pfBlockerNG.com
                  Twitter: @BBcan177  #pfBlockerNG
                  Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                  X 1 Reply Last reply Reply Quote 0
                  • X
                    xerno @BBcan177
                    last edited by

                    @bbcan17 I can ping dnsbl vip and get a reply.
                    if I browser it I get a timeout
                    if I ping one of the dnsbl domains I dont get the dnsbl vip adress

                    BBcan177B 1 Reply Last reply Reply Quote 0
                    • BBcan177B
                      BBcan177 Moderator @xerno
                      last edited by

                      @xerno In the DNSBL Tab, enable the "DNSBL Permit" rule and select all LAN/VLANS that need access to the DNSBL VIP...

                      "Experience is something you don't get until just after you need it."

                      Website: http://pfBlockerNG.com
                      Twitter: @BBcan177  #pfBlockerNG
                      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                      X 2 Replies Last reply Reply Quote 0
                      • X
                        xerno @BBcan177
                        last edited by

                        @bbcan17 said in DNSBL not working with vpn:

                        AN/VLANS that need access to

                        Those settings are already there

                        1 Reply Last reply Reply Quote 0
                        • X
                          xerno @BBcan177
                          last edited by

                          @bbcan17 I did some digging in the log files.
                          for example this
                          local-data: "adaway.org/hosts.txt 60 IN A 10.10.10.1"
                          when I ping one of the addresses in that site it does not use 10.10.10.1
                          however I do have this local-data: "jujuads.com 60 IN A 10.10.10.1" and that will ping with response 10.10.10.1

                          1 Reply Last reply Reply Quote 0
                          • BBcan177B
                            BBcan177 Moderator
                            last edited by

                            @xerno said in DNSBL not working with vpn:

                            local-data: "adaway.org/hosts.txt 60 IN A 10.10.10.1"

                            Something is wrong with this line as it shouldn't contain the "/hosts.txt".. What URL are you using... Compare that to the URL in the link I posted above.

                            After reviewing the URL, remove the previous feed in the Log Browser > DNSBL Files > Adaway.txt, by selecting the "Delete Icon"... Follow that with a Force Reload - DNSBL.

                            "Experience is something you don't get until just after you need it."

                            Website: http://pfBlockerNG.com
                            Twitter: @BBcan177  #pfBlockerNG
                            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                            X 2 Replies Last reply Reply Quote 0
                            • X
                              xerno @BBcan177
                              last edited by

                              @bbcan17 I found the problem, in the DNSBL Feeds I didnt put unique headers. they where all named the same. after reloading it now blocks ads.
                              However is the blocking correct? The ads just show up as grey and after about 5-10 seconds they dissapear.

                              1 Reply Last reply Reply Quote 0
                              • X
                                xerno @BBcan177
                                last edited by

                                @bbcan17 I still cant acess 10.10.10.1 in my browser.

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.