Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Issues using DNSBL and IP to block domains

    Scheduled Pinned Locked Moved pfBlockerNG
    26 Posts 4 Posters 2.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      Risfold @Risfold
      last edited by

      @Risfold said in Issues using DNSBL and IP to block domains:

      I have been thinking disabling DNS resolver responding on the local host might work, but I'm not sure if that will work or what else it will effect.

      Well that didn't work. Got the error below. Plus then my resolver wouldn't use the DoH I have setup.
      53e6b9e3-796a-4bf9-96ad-fd645fd2d9cc-image.png

      1 Reply Last reply Reply Quote 0
      • R
        Risfold
        last edited by

        @BBcan177 Do you have any suggestions? I would very much appreciate any help you can offer.

        1 Reply Last reply Reply Quote 0
        • bmeeksB
          bmeeks
          last edited by

          You will need the resolver for DNSBL to work. I am not familiar with the internal details of how pfBlockerNG works. The developer and I have exchanged ideas in the past, but I mostly concentrate on the IDS/IPS packages (Snort and Suricata).

          R 1 Reply Last reply Reply Quote 0
          • R
            Risfold @bmeeks
            last edited by

            @bmeeks said in Issues using DNSBL and IP to block domains:

            You will need the resolver for DNSBL to work. I am not familiar with the internal details of how pfBlockerNG works. The developer and I have exchanged ideas in the past, but I mostly concentrate on the IDS/IPS packages (Snort and Suricata).

            Thanks for your contributions to pfsense! I actually am upgrading to beefier pfsense hardware soon and I plan on looking into those. I am currently on an APU board and from what I hear that doesn't quite cut it for those.

            1 Reply Last reply Reply Quote 0
            • BBcan177B
              BBcan177 Moderator
              last edited by

              Some more info here:
              https://www.reddit.com/r/pfBlockerNG/comments/d3p1gf/doh_server_blocklist/

              "Experience is something you don't get until just after you need it."

              Website: http://pfBlockerNG.com
              Twitter: @BBcan177  #pfBlockerNG
              Reddit: https://www.reddit.com/r/pfBlockerNG/new/

              R 1 Reply Last reply Reply Quote 0
              • R
                Risfold @BBcan177
                last edited by

                @BBcan177 said in Issues using DNSBL and IP to block domains:

                Some more info here:
                https://www.reddit.com/r/pfBlockerNG/comments/d3p1gf/doh_server_blocklist/

                Hi BBcan177 Thanks for the reply. This post is where I got my domain list from. My issue is that I would like to use the DNSBL and block the IP of these addresses. However when the whois lookup occurs during the IP cron, pfblocker only returns the pfblocker VIP because the same list of domains are in the DNSBL.

                Can the whois lookup for an IP blocklist occur ignoring the DNSBL?

                1 Reply Last reply Reply Quote 0
                • R
                  Risfold
                  last edited by

                  I hoped my explanations above were clear enough but in case not I have added the screenshots below. I appreciate the help with this issue!

                  Domain list on DNSBL:
                  dnsbl.png

                  IP block list:
                  ipv4 blocklist.png

                  List of IPs from block list showing pfblocker VIP only since domains are listed on DNSBL already:
                  ip list.png

                  1 Reply Last reply Reply Quote 0
                  • BBcan177B
                    BBcan177 Moderator
                    last edited by

                    That Heuristics feed is for DNSBL only. Its not an IP list, so it can't be used in the IP tab.
                    What is your IP Placeholder IP? Is it 10.10.10.1? That could interfere with DNSBL depending what you selected for the DNSBL VIP address.

                    "Experience is something you don't get until just after you need it."

                    Website: http://pfBlockerNG.com
                    Twitter: @BBcan177  #pfBlockerNG
                    Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                    1 Reply Last reply Reply Quote 0
                    • R
                      Risfold
                      last edited by

                      I have the feed for Heuristics list in whois format so pfblocker should resolve these, no? That is the issue I'm referring to. When pfblocker uses dns resolver to resolve the list of domains for IP blocking, it uses itself (DNSBL) and only resolves the DNSBL IP (10.10.10.1) for each domain.

                      abb550d2-515f-4b10-8e60-c5c5d16f8746-image.png

                      The IP placeholder and DNSBL IP are default:
                      b519d222-1915-4d90-a146-7f70b666b231-image.png

                      0e4de4ad-c7ec-4580-84f2-fff5bac4223e-image.png

                      BBcan177B 1 Reply Last reply Reply Quote 0
                      • BBcan177B
                        BBcan177 Moderator @Risfold
                        last edited by

                        @Risfold
                        Dont think that duality is possible.

                        "Experience is something you don't get until just after you need it."

                        Website: http://pfBlockerNG.com
                        Twitter: @BBcan177  #pfBlockerNG
                        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                        R 1 Reply Last reply Reply Quote 0
                        • R
                          Risfold @BBcan177
                          last edited by

                          @BBcan177
                          I see. I was hoping there would be a way that I was just ignorant of. Thank you for taking the time to review this.

                          If anyone else has a suggestion beyond manually resolving these domains externally and manually updating the lists, please let us know!

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.