Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Issues using DNSBL and IP to block domains

    Scheduled Pinned Locked Moved pfBlockerNG
    26 Posts 4 Posters 2.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      Risfold
      last edited by

      @BBcan177 Do you have any suggestions? I would very much appreciate any help you can offer.

      1 Reply Last reply Reply Quote 0
      • bmeeksB
        bmeeks
        last edited by

        You will need the resolver for DNSBL to work. I am not familiar with the internal details of how pfBlockerNG works. The developer and I have exchanged ideas in the past, but I mostly concentrate on the IDS/IPS packages (Snort and Suricata).

        R 1 Reply Last reply Reply Quote 0
        • R
          Risfold @bmeeks
          last edited by

          @bmeeks said in Issues using DNSBL and IP to block domains:

          You will need the resolver for DNSBL to work. I am not familiar with the internal details of how pfBlockerNG works. The developer and I have exchanged ideas in the past, but I mostly concentrate on the IDS/IPS packages (Snort and Suricata).

          Thanks for your contributions to pfsense! I actually am upgrading to beefier pfsense hardware soon and I plan on looking into those. I am currently on an APU board and from what I hear that doesn't quite cut it for those.

          1 Reply Last reply Reply Quote 0
          • BBcan177B
            BBcan177 Moderator
            last edited by

            Some more info here:
            https://www.reddit.com/r/pfBlockerNG/comments/d3p1gf/doh_server_blocklist/

            "Experience is something you don't get until just after you need it."

            Website: http://pfBlockerNG.com
            Twitter: @BBcan177  #pfBlockerNG
            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

            R 1 Reply Last reply Reply Quote 0
            • R
              Risfold @BBcan177
              last edited by

              @BBcan177 said in Issues using DNSBL and IP to block domains:

              Some more info here:
              https://www.reddit.com/r/pfBlockerNG/comments/d3p1gf/doh_server_blocklist/

              Hi BBcan177 Thanks for the reply. This post is where I got my domain list from. My issue is that I would like to use the DNSBL and block the IP of these addresses. However when the whois lookup occurs during the IP cron, pfblocker only returns the pfblocker VIP because the same list of domains are in the DNSBL.

              Can the whois lookup for an IP blocklist occur ignoring the DNSBL?

              1 Reply Last reply Reply Quote 0
              • R
                Risfold
                last edited by

                I hoped my explanations above were clear enough but in case not I have added the screenshots below. I appreciate the help with this issue!

                Domain list on DNSBL:
                dnsbl.png

                IP block list:
                ipv4 blocklist.png

                List of IPs from block list showing pfblocker VIP only since domains are listed on DNSBL already:
                ip list.png

                1 Reply Last reply Reply Quote 0
                • BBcan177B
                  BBcan177 Moderator
                  last edited by

                  That Heuristics feed is for DNSBL only. Its not an IP list, so it can't be used in the IP tab.
                  What is your IP Placeholder IP? Is it 10.10.10.1? That could interfere with DNSBL depending what you selected for the DNSBL VIP address.

                  "Experience is something you don't get until just after you need it."

                  Website: http://pfBlockerNG.com
                  Twitter: @BBcan177  #pfBlockerNG
                  Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                  1 Reply Last reply Reply Quote 0
                  • R
                    Risfold
                    last edited by

                    I have the feed for Heuristics list in whois format so pfblocker should resolve these, no? That is the issue I'm referring to. When pfblocker uses dns resolver to resolve the list of domains for IP blocking, it uses itself (DNSBL) and only resolves the DNSBL IP (10.10.10.1) for each domain.

                    abb550d2-515f-4b10-8e60-c5c5d16f8746-image.png

                    The IP placeholder and DNSBL IP are default:
                    b519d222-1915-4d90-a146-7f70b666b231-image.png

                    0e4de4ad-c7ec-4580-84f2-fff5bac4223e-image.png

                    BBcan177B 1 Reply Last reply Reply Quote 0
                    • BBcan177B
                      BBcan177 Moderator @Risfold
                      last edited by

                      @Risfold
                      Dont think that duality is possible.

                      "Experience is something you don't get until just after you need it."

                      Website: http://pfBlockerNG.com
                      Twitter: @BBcan177  #pfBlockerNG
                      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                      R 1 Reply Last reply Reply Quote 0
                      • R
                        Risfold @BBcan177
                        last edited by

                        @BBcan177
                        I see. I was hoping there would be a way that I was just ignorant of. Thank you for taking the time to review this.

                        If anyone else has a suggestion beyond manually resolving these domains externally and manually updating the lists, please let us know!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.