Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfblocker ports

    Scheduled Pinned Locked Moved pfBlockerNG
    8 Posts 2 Posters 905 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mikekoke
      last edited by mikekoke

      Hi everyone
      I configured a vlan isolated from the main network to connect the guests and I also enabled on this pfblockerng network.
      But I noticed some requests from the guest network router to the vip address of dnsbl, blocked by one of my rules, such as the udp port 443 or tcp:s port 4070.
      The nat rules of the main network and the hidden rules added to the guest network by pfblocker should only allow tcp ports 80, 443, 8446 and 8448.
      I would like to know if other TCP and UDP ports should be used besides those mentioned.
      Thanks for your help.

      1 Reply Last reply Reply Quote 0
      • M
        mikekoke
        last edited by

        Does anyone know the ports used?

        1 Reply Last reply Reply Quote 0
        • M
          mikekoke
          last edited by

          @BBcan177 could you tell me if other doors should be used besides those mentioned? Thanks for your help.

          1 Reply Last reply Reply Quote 0
          • BBcan177B
            BBcan177 Moderator
            last edited by

            In the DNSBL tab. there is an option to create a Permit rule to allow VLANs to hit the DNSBL VIP on the open ports.

            "Experience is something you don't get until just after you need it."

            Website: http://pfBlockerNG.com
            Twitter: @BBcan177  #pfBlockerNG
            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

            M 1 Reply Last reply Reply Quote 0
            • M
              mikekoke @BBcan177
              last edited by

              @BBcan177 said in Pfblocker ports:

              In the DNSBL tab. there is an option to create a Permit rule to allow VLANs to hit the DNSBL VIP on the open ports.

              I have already used that setting to select the two VLANs, but randomly the udp 443 and the tcp 4070 are also requested

              1 Reply Last reply Reply Quote 0
              • BBcan177B
                BBcan177 Moderator
                last edited by

                @mikekoke said in Pfblocker ports:

                @BBcan177 said in Pfblocker ports:

                In the DNSBL tab. there is an option to create a Permit rule to allow VLANs to hit the DNSBL VIP on the open ports.

                I have already used that setting to select the two VLANs, but randomly the udp 443 and the tcp 4070 are also requested

                Not by DNSBL. Maybe the device that has domains being blocked tries to hit those ports?

                https://www.speedguide.net/port.php?port=4070

                "Experience is something you don't get until just after you need it."

                Website: http://pfBlockerNG.com
                Twitter: @BBcan177  #pfBlockerNG
                Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                M 1 Reply Last reply Reply Quote 0
                • M
                  mikekoke
                  last edited by

                  Thanks, so I'm sure I don't block some DNSBL ports.
                  I will try to understand which device requires those ports, the problem that neighbors are connected to the guest network.

                  1 Reply Last reply Reply Quote 0
                  • M
                    mikekoke @BBcan177
                    last edited by

                    @BBcan177 said in Pfblocker ports:

                    @mikekoke said in Pfblocker ports:

                    @BBcan177 said in Pfblocker ports:

                    In the DNSBL tab. there is an option to create a Permit rule to allow VLANs to hit the DNSBL VIP on the open ports.

                    I have already used that setting to select the two VLANs, but randomly the udp 443 and the tcp 4070 are also requested

                    Not by DNSBL. Maybe the device that has domains being blocked tries to hit those ports?

                    https://www.speedguide.net/port.php?port=4070

                    The device that continues to connect to udp port 443 is a Sony Android smartphone but it is not possible to specify which one.
                    It appears that the connection to port 443 udp is linked to a warning in DNSBL.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.