Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    TLD issues/questions....

    Scheduled Pinned Locked Moved pfBlockerNG
    20 Posts 4 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      whizatit
      last edited by whizatit

      I currently have an at home/home brew box 16Gb ram Intel quad core 3.5 Ghz processor and an Intel Pro 10/100/1000 PCIExpress card basic setup.

      PfBlocker is setup and running great, i read and saw some places to enable TLD, so i give it a shot!

      Once enabled it immediately maxes 16Gb of ram and system is unresponsive enough that i tried a reboot and it still is locked up so much the buzzer sounds like its dying trying to do the startup sound...halarious.

      So i reinstalled PfSense and restored my backup and tried again ...same issue. Am i missing something or is this setting meant for a bad ass rack mount system?

      NollipfSenseN 1 Reply Last reply Reply Quote 0
      • NollipfSenseN
        NollipfSense @whizatit
        last edited by

        @whizatit Logs are always helpful in understanding your issue. It seems that something is wrong with your configuration...so, post logs!

        pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
        pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

        1 Reply Last reply Reply Quote 0
        • W
          whizatit
          last edited by whizatit

          Can't retrieve/post logs if system freezes :-(

          I cant even log into the GUI/on the box itself it just locks up entirely!

          EDIT:
          Default pfblocker load with GeoIP enabled and setup, IP settings in shalalist and UT1 setup for the bad stuff (porn, pishing, Dangerous kits, etc of the like) and thats it.

          EDIT EDIT:
          I was under the assumption checking TLD was the only option unless you blacklist/whitelist a site.

          NollipfSenseN RonpfSR 2 Replies Last reply Reply Quote 0
          • NollipfSenseN
            NollipfSense @whizatit
            last edited by

            @whizatit Did you installed pfBockerNG-dev? If not, that's what you need.

            pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
            pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

            W 1 Reply Last reply Reply Quote 0
            • W
              whizatit @NollipfSense
              last edited by whizatit

              @NollipfSense yes sorry should've mentioned it's the dev version

              W 1 Reply Last reply Reply Quote 0
              • W
                whizatit @whizatit
                last edited by

                Really nobody has ANY thoughts? I guess an actual forum might be more helpful...

                NollipfSenseN 1 Reply Last reply Reply Quote 0
                • NollipfSenseN
                  NollipfSense @whizatit
                  last edited by

                  @whizatit You may not want to hear this however, your solution is a clean install and reconfigured...do not restore from backup configuration.

                  pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                  pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                  W 1 Reply Last reply Reply Quote 0
                  • W
                    whizatit @NollipfSense
                    last edited by

                    @NollipfSense I did multiple times same issue, changed processor and ram just for the hell of it thinking one of the two could be bad to no avail.

                    NollipfSenseN 1 Reply Last reply Reply Quote 0
                    • NollipfSenseN
                      NollipfSense @whizatit
                      last edited by

                      @whizatit I don't know what else to say other than you might have blocked ten million domains or more since it consuming all your available RAM to the point that your system freezes. Did you enable all in the shallalist? You have 16GB RAM...2.5 million domains will occupy 7GB RAM...see image below!

                      Screen Shot 2020-02-01 at 12.47.58 PM.png

                      pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                      pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                      W 1 Reply Last reply Reply Quote 0
                      • W
                        whizatit @NollipfSense
                        last edited by whizatit

                        @NollipfSense no only bad stuff such as porn, redirectors, ads, proxies and the like are enabled only, I have a total of 21 enabled in both lists together.👍

                        DNSBL is enabled with Block on all top offenders/Deny Inbound on most everything else.

                        Dont host but have a multitude of devices in home for automation that have been attacked in the past, cameras, gate openers, etc etc most ALL attacks came from Russia.

                        1 Reply Last reply Reply Quote 0
                        • W
                          whizatit
                          last edited by

                          OK question, is there a way to see the lists i checked, how many per list i select, there are in the said list?

                          Is there a site/sites per list to check the amount of blocked sites/domains?

                          1 Reply Last reply Reply Quote 0
                          • RonpfSR
                            RonpfS @whizatit
                            last edited by

                            @whizatit said in TLD issues/questions....:

                            Can't retrieve/post logs if system freezes :-(
                            I cant even log into the GUI/on the box itself it just locks up entirely!

                            Can you access the box using the Console or SSH ?
                            From there you can inspect the logs.

                            2.4.5-RELEASE-p1 (amd64)
                            Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                            Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                            W 1 Reply Last reply Reply Quote 0
                            • W
                              whizatit @RonpfS
                              last edited by

                              @RonpfS nope totally locked up not even serial just shows gibberish.

                              RonpfSR 1 Reply Last reply Reply Quote 0
                              • RonpfSR
                                RonpfS @whizatit
                                last edited by

                                @whizatit And when it boot does it only show gibberish?

                                2.4.5-RELEASE-p1 (amd64)
                                Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                W 1 Reply Last reply Reply Quote 0
                                • W
                                  whizatit @RonpfS
                                  last edited by

                                  @RonpfS after post it takes about 5 seconds then it's locked up

                                  1 Reply Last reply Reply Quote 0
                                  • RonpfSR
                                    RonpfS
                                    last edited by

                                    I guess it's time to start over without pfblocker to see if the system is stable.

                                    2.4.5-RELEASE-p1 (amd64)
                                    Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                    Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                    1 Reply Last reply Reply Quote 0
                                    • W
                                      whizatit
                                      last edited by

                                      System is stable always until TLD is enabled reload or not.

                                      NollipfSenseN 1 Reply Last reply Reply Quote 0
                                      • RonpfSR
                                        RonpfS
                                        last edited by

                                        Post some debug info here then we can see what is going on.

                                        What others package are you using ? What pfsense version? What is your DNS services setting? What is your network configuration?

                                        Before enabling pfblockerNG, inspect the system logs, resolver logs, pfblockerng logs to see if something is broken.

                                        Then enable only pfblockerNG , DNSBL disabled, inspect the pfblockerng logs during a Force Update and Force Reload All.

                                        Enable DNSBL without TLD, with only one DNSBL group enabled, enabling more until something break.

                                        Inspect the logs, how many domains are used etc.

                                        2.4.5-RELEASE-p1 (amd64)
                                        Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                        Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                        1 Reply Last reply Reply Quote 0
                                        • NollipfSenseN
                                          NollipfSense @whizatit
                                          last edited by

                                          @whizatit I find it baffling that you installed a clean new copy of pfSense that works, then you added pfBlockerNG-dev and still worked, then you configured your list and checked TLD, force reloaded/update pfBlockerNG-dev and system freezes...it's not making sense...unless you have a hardware issue; and the suspect is RAM. However, you said RAM checked out good!

                                          pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                                          pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                                          1 Reply Last reply Reply Quote 0
                                          • GertjanG
                                            Gertjan
                                            last edited by Gertjan

                                            Also :

                                            @whizatit said in TLD issues/questions....:

                                            Can't retrieve/post logs if system freezes :-(

                                            That why logs shouldn't stay on the router.
                                            You have to 'backup' your logs. Because: if you have them, you wont need them - and the other way around.

                                            I've TLD selected since the beginning on a very old plain vanilla "Intel(R) Pentium(R) 4 CPU 3.20GHz
                                            2 CPUs: 1 package(s) x 2 hardware threads " with 2 GB.
                                            Four or five classic feeds ( DNSBL ).

                                            Here you can see memory and system resources (yep, another way to 'log' outside the box).

                                            pfSense freezes ? I don't recall freezing mine on me ...

                                            No "help me" PM's please. Use the forum, the community will thank you.
                                            Edit : and where are the logs ??

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.