Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Confusion on allowing specific client IP's on my LAN to bypass Pfblockerng-devel

    Scheduled Pinned Locked Moved pfBlockerNG
    4 Posts 3 Posters 990 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T Offline
      TupleButter
      last edited by TupleButter

      I know this has been brought up multiple times sorry for being dense I just have some confusion on syntax for this under Services > DNS Resolver > Custom Options.

      Current syntax under Services > DNS Resolver > Custom Options with Pfblockerng enabled is:

      private-domain: "plex.direct"
      server:include: /var/unbound/pfb_dnsbl.conf**

      I have a multiple devices I want to bypass dnsbl (192.168.1.50, 192.168.1.51, 192.168.1.52) but everything else on 192.168.1.0/24 I want running through dnsbl so as I understand it I should just copy and paste the following into the custom options field of the DNS resolver for this:

      *server:
      private-domain: "plex.direct"
      access-control-view: 192.168.1.50/32 bypass
      access-control-view: 192.168.1.51/32 bypass
      access-control-view: 192.168.1.52/32 bypass
      access-control-view: 192.168.1.0/24 dnsbl
      view:
      name: "bypass"
      view-first: yes
      view:
      name: "dnsbl"
      view-first: yes
      include: /var/unbound/pfb_dnsbl.*conf

      T 1 Reply Last reply Reply Quote 0
      • T Offline
        TupleButter @TupleButter
        last edited by

        server:
        private-domain: "plex.direct"
        access-control-view: 192.168.1.50/32 bypass
        access-control-view: 192.168.1.51/32 bypass
        access-control-view: 192.168.1.52/32 bypass
        access-control-view: 192.168.1.0/24 dnsbl
        view:
        name: "bypass"
        view-first: yes
        view:
        name: "dnsbl"
        view-first: yes
        include: /var/unbound/pfb_dnsbl.*conf

        1 Reply Last reply Reply Quote 0
        • NollipfSenseN Offline
          NollipfSense
          last edited by

          The ones you want to bypass DNSBL, you'll need to create a DNSBL feed and place the sites in the DNSBL custom_list...be sure to set group order to PRIMARY and logging to DISABLE, then force reload.

          Screen Shot 2019-11-13 at 6.48.42 PM.png
          Screen Shot 2019-11-13 at 6.48.56 PM.png

          pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
          pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

          BBcan177B 1 Reply Last reply Reply Quote 0
          • BBcan177B Offline
            BBcan177 Moderator @NollipfSense
            last edited by

            Does this help:
            https://forum.netgate.com/topic/129365/bypassing-dnsbl-for-specific-ips

            "Experience is something you don't get until just after you need it."

            Website: http://pfBlockerNG.com
            Twitter: @BBcan177  #pfBlockerNG
            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.