Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    oisd blocklist not working

    Scheduled Pinned Locked Moved pfBlockerNG
    7 Posts 3 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      revengineer
      last edited by revengineer

      Hi,
      I am trying to use the oisd blck list found here. pfBlockerNG seems to process this fine, but unbound will not start afterward. Can anyone advise why this is? I cannot post the full log, as it is too long. Below is the final snippet.

      Thank you.

      ===[ FINAL Processing ]=====================================

      [ Original IP count ] [ 51967 ]

      ===[ Deny List IP Counts ]===========================

      49753 total
      18492 /var/db/pfblockerng/deny/pfB_Top_v4.txt
      16387 /var/db/pfblockerng/deny/FireHOL3_IPs.txt
      6052 /var/db/pfblockerng/deny/pfB_Top_v6.txt
      5789 /var/db/pfblockerng/deny/BD_IPs.txt
      2245 /var/db/pfblockerng/deny/ET_Block_IPs.txt
      788 /var/db/pfblockerng/deny/ET_Comp_IPs.txt

      ===[ DNSBL Domain/IP Counts ] ===================================

      431133 total
      371953 /var/db/pfblockerng/dnsbl/oisd.txt
      24262 /var/db/pfblockerng/dnsbl/MDS.txt
      16794 /var/db/pfblockerng/dnsbl/EasyList.txt
      6097 /var/db/pfblockerng/dnsbl/Cameleon.txt
      5381 /var/db/pfblockerng/dnsbl/PhishTank.txt
      3265 /var/db/pfblockerng/dnsbl/Adaway.txt
      1752 /var/db/pfblockerng/dnsbl/yoyo.txt
      751 /var/db/pfblockerng/dnsbl/MDL.txt
      713 /var/db/pfblockerng/dnsbl/OpenPhish.txt
      92 /var/db/pfblockerng/dnsbl/PhishTank.ip
      49 /var/db/pfblockerng/dnsbl/EasyList.ip
      16 /var/db/pfblockerng/dnsbl/OpenPhish.ip
      8 /var/db/pfblockerng/dnsbl/DNSBL_TLD.txt

      ====================[ Last Updated List Summary ]==============

      Mar 31 00:30 ET_Block_IPs
      Mar 31 00:30 ET_Comp_IPs
      Apr 1 07:04 FireHOL3_IPs
      Apr 1 16:31 BD_IPs
      Apr 1 17:49 pfB_Top_v4
      Apr 1 17:49 pfB_Top_v6

      IPv4 alias tables IP count

      43858

      IPv6 alias tables IP count

      6052

      Alias table IP Counts

      49910 total
      18492 /var/db/aliastables/pfB_Top_v4.txt
      16387 /var/db/aliastables/pfB_FireHOL3.txt
      6052 /var/db/aliastables/pfB_Top_v6.txt
      5789 /var/db/aliastables/pfB_BinaryDefense.txt
      3033 /var/db/aliastables/pfB_EmergingThreatsDShield.txt
      157 /var/db/aliastables/pfB_DNSBLIP.txt

      pfSense Table Stats

      table-entries hard limit 2000000
      Table Usage Count 161305

      UPDATE PROCESS ENDED [ 04/01/20 17:49:17 ]

      BBcan177B 1 Reply Last reply Reply Quote 0
      • RonpfSR
        RonpfS
        last edited by

        Check the pfblockerng.log, system log, resolver log, memory usage, maybe you hit the limit your system can handle going from 60000 DNSBL entries to 430000.

        2.4.5-RELEASE-p1 (amd64)
        Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
        Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

        1 Reply Last reply Reply Quote 0
        • R
          revengineer
          last edited by

          @RonpfS Thank you for the pointer. The problem seems to be that the oisd black list contains one domain for which I also have a local host override. The dual override seems to result in the failed loading of unbound. I would like to keep the local override because I have no control of future changes to the blacklist. Is there a workaround?

          1 Reply Last reply Reply Quote 0
          • RonpfSR
            RonpfS
            last edited by RonpfS

            Put that domain in the DNSBL Whitelist, you might also have to put it (or it's parent domain) in the TLD Exclude list to get better control over whitelisting.

            2.4.5-RELEASE-p1 (amd64)
            Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
            Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

            1 Reply Last reply Reply Quote 0
            • R
              revengineer
              last edited by revengineer

              @RonpfS Perfect, that worked! Adding the domain with subdomains (leading ".") was sufficient to fix the problem. It took me a while to figure it out because I did a "Force Update" which was insufficient. Once I did the "Force Reload" I was good to go. Thanks for the help!

              1 Reply Last reply Reply Quote 0
              • RonpfSR
                RonpfS
                last edited by

                Yeah sometimes you save time by clicking on the 😉

                2.4.5-RELEASE-p1 (amd64)
                Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                1 Reply Last reply Reply Quote 0
                • BBcan177B
                  BBcan177 Moderator @revengineer
                  last edited by

                  @revengineer
                  The is a log snippet above that to show the processing of that feed and the restart of Unbound. Take a look at those two sections of the pfblockerng.log.

                  "Experience is something you don't get until just after you need it."

                  Website: http://pfBlockerNG.com
                  Twitter: @BBcan177  #pfBlockerNG
                  Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.