• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

pfBlockerNG IP Reputation

2.5 Development Snapshots (Retired)
6
35
4.8k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • N
    NollipfSense @serbus
    last edited by NollipfSense May 25, 2020, 3:27 AM May 25, 2020, 3:16 AM

    @serbus said in pfBlockerNG IP Reputation:

    php /usr/local/www/pfblockerng/pfblockerng.php gc

    Hey John, I am reporting that worked. However, the command result shows geolocation files not found confirmed that IP reputation list is derived from geolocation feed. Just discovered making the page had produced a crash

    login-to-view

    login-to-view

    login-to-view

    pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
    pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

    1 Reply Last reply Reply Quote 0
    • G
      Gertjan
      last edited by May 25, 2020, 6:01 AM

      @NollipfSense :

      [2.4.5-RELEASE][admin@pfsense.brit-hotel-fumel.net]/root: php /usr/local/www/pfblockerng/pfblockerng.php gc
       Creating pfBlockerNG Continent PHP files
       IPv4 Africa                     [ 05/25/20 07:16:41 ]
       IPv6 Africa                     [ 05/25/20 07:16:43 ]
       IPv4 Antarctica
       IPv6 Antarctica
       IPv4 Asia
       IPv6 Asia                       [ 05/25/20 07:16:46 ]
       IPv4 Europe                     [ 05/25/20 07:16:47 ]
       IPv6 Europe                     [ 05/25/20 07:16:55 ]
       IPv4 North America              [ 05/25/20 07:16:58 ]
       IPv6 North America              [ 05/25/20 07:17:04 ]
       IPv4 Oceania                    [ 05/25/20 07:17:05 ]
       IPv6 Oceania                    [ 05/25/20 07:17:06 ]
       IPv4 South America
       IPv6 South America              [ 05/25/20 07:17:07 ]
       IPv4 Proxy and Satellite
       IPv6 Proxy and Satellite        [ 05/25/20 07:17:08 ]
       IPv4 Top Spammers
       IPv6 Top Spammers
       pfBlockerNG Reputation Tab
      Country Code Update Ended
      

      and

      [2.4.5-RELEASE][admin@pfsense.brit-hotel-fumel.net]/root: php /usr/local/www/pfblockerng/pfblockerng.php ugc
      Country code update Start [ 05/25/20 07:42:27 ]
       Processing ISO IPv4 Continent/Country Data
       Processing ISO IPv6 Continent/Country Data [ 05/25/20 07:42:55 ]
       Creating pfBlockerNG Continent PHP files
       IPv4 Africa                     [ 05/25/20 07:43:05 ]
       IPv6 Africa                     [ 05/25/20 07:43:06 ]
       IPv4 Antarctica
       IPv6 Antarctica
       IPv4 Asia
       IPv6 Asia                       [ 05/25/20 07:43:09 ]
       IPv4 Europe                     [ 05/25/20 07:43:10 ]
       IPv6 Europe                     [ 05/25/20 07:43:19 ]
       IPv4 North America              [ 05/25/20 07:43:21 ]
       IPv6 North America              [ 05/25/20 07:43:27 ]
       IPv4 Oceania                    [ 05/25/20 07:43:29 ]
       IPv6 Oceania
       IPv4 South America
       IPv6 South America              [ 05/25/20 07:43:30 ]
       IPv4 Proxy and Satellite        [ 05/25/20 07:43:31 ]
       IPv6 Proxy and Satellite
       IPv4 Top Spammers
       IPv6 Top Spammers               [ 05/25/20 07:43:32 ]
       pfBlockerNG Reputation Tab
      Country Code Update Ended
      

      @serbus said in pfBlockerNG IP Reputation:

      Did you run a full update of pfbng? I think that file might be dynamically generated at some point during that process.

      Well .... @servus is right.
      I was wrong.
      This file "reputation" IS actually regenerated out of /usr/local/www/pfblockerng/pfblockerng.php ...

      @NollipfSense : Yes, I have an activated MaxiMind account.

      login-to-view

      @NollipfSense : How many files - what ype of files do you have here /usr/local/share/GeoIP/cc/ ?

      I have more the 1500 files - it depends probably on which regions I've selected, I guess.
      Some of them have a time stamp like 03/09/2019 - others 07/05/2020 - and the better part was downloaded just today : 25/05/2020 - 07h17.

      Also : /usr/local/share/GeoIP/ ? This directory gets filled with files from MaxMind - if you have an account with them.

      So : files actually get downloaded , No file system full ? Run a "fsck" just to be sure.

      Btw : The Diagnostic > Command propmpt : never use that one. It could hide stuff. Keyboard command belong on a real command line. It's one click away with Putty or any other SSH client. Better get used to it ^^

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      N 1 Reply Last reply May 27, 2020, 2:41 AM Reply Quote 0
      • N
        NollipfSense @Gertjan
        last edited by May 27, 2020, 2:41 AM

        @Gertjan said in pfBlockerNG IP Reputation:

        How many files - what ype of files do you have here /usr/local/share/GeoIP/cc/ ?

        Appeared empty!

        login-to-view

        @Gertjan said in pfBlockerNG IP Reputation:

        Also : /usr/local/share/GeoIP/ ?

        Also, appeared empty!

        login-to-view

        pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
        pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

        1 Reply Last reply Reply Quote 0
        • S
          serbus
          last edited by May 27, 2020, 3:53 AM

          Hello!

          php /usr/local/www/pfblockerng/pfblockerng.php dc

          should re-download the maxmind files. They should appear in the /usr/local/share/GeoIP folder.

          the "dc" command will also run the "ugc" functions after the download.

          John

          Lex parsimoniae

          N 1 Reply Last reply May 27, 2020, 4:56 PM Reply Quote 0
          • G
            Gertjan
            last edited by May 27, 2020, 7:51 AM

            @NollipfSense : do not use the GUI for this. Use the console/SSH.

            There is a little surprise here, see the last two lines :

            [2.4.5-RELEASE][admin@pfsense.brit-hotel-fumel.net]/root: php /usr/local/www/pfblockerng/pfblockerng.php dc
            
            Download Process Starting [ 05/27/20 09:48:21 ]
             /usr/local/share/GeoIP/GeoLite2-Country.tar.gz         200 OK
             /usr/local/share/GeoIP/GeoLite2-Country-CSV.zip                200 OK
            Download Process Ended [ 05/27/20 09:48:26 ]
            
            Country code update Start
             Processing ISO IPv4 Continent/Country Data
             Processing ISO IPv6 Continent/Country Data [ 05/27/20 09:48:55 ]
             Creating pfBlockerNG Continent PHP files
             IPv4 Africa                     [ 05/27/20 09:49:03 ]
             IPv6 Africa                     [ 05/27/20 09:49:04 ]
             IPv4 Antarctica
             IPv6 Antarctica
             IPv4 Asia
             IPv6 Asia                       [ 05/27/20 09:49:08 ]
             IPv4 Europe
             IPv6 Europe                     [ 05/27/20 09:49:17 ]
             IPv4 North America              [ 05/27/20 09:49:20 ]
             IPv6 North America              [ 05/27/20 09:49:25 ]
             IPv4 Oceania                    [ 05/27/20 09:49:27 ]
             IPv6 Oceania
             IPv4 South America              [ 05/27/20 09:49:28 ]
             IPv6 South America
             IPv4 Proxy and Satellite        [ 05/27/20 09:49:29 ]
             IPv6 Proxy and Satellite        [ 05/27/20 09:49:30 ]
             IPv4 Top Spammers
             IPv6 Top Spammers
             pfBlockerNG Reputation Tab
            Country Code Update Ended
            

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            1 Reply Last reply Reply Quote 0
            • N
              NollipfSense @serbus
              last edited by May 27, 2020, 4:56 PM

              @serbus and @Gertjan I used the CLI and here is the result:

              [2.5.0-DEVELOPMENT][admin@NollipfSense.nollipfsense.lan]/root: php /usr/local/www/pfblockerng/pfblockerng.php dc

              Download Process Starting [ 05/27/20 10:55:35 ]
              /usr/local/share/GeoIP/GeoLite2-Country.tar.gz 401 Unauthorized

              Failed to Download GeoLite2-Country.mmdb
              /usr/local/share/GeoIP/GeoLite2-Country-CSV.zip 401 Unauthorized

              Failed to Download
              Download Process Ended [ 05/27/20 10:55:36 ]

              [2.5.0-DEVELOPMENT][admin@NollipfSense.nollipfsense.lan]/root:

              What I don't understand is I have a registered key; so, not sure what the unauthorized is all about nor what to do to resolve.

              login-to-view

              pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
              pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

              G 1 Reply Last reply May 28, 2020, 8:35 AM Reply Quote 0
              • R
                RonpfS
                last edited by May 27, 2020, 5:23 PM

                Goto Maxminds and check your account and Download History.

                2.4.5-RELEASE-p1 (amd64)
                Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                N 1 Reply Last reply May 28, 2020, 2:52 AM Reply Quote 0
                • N
                  NollipfSense @RonpfS
                  last edited by May 28, 2020, 2:52 AM

                  @RonpfS Last download was on May 5, 2020 at 14.56pm ... so, I guess I'll have to wait for June. I had to reinstall a fresh pfSense 2.5-dev so may explain why I haven't got the feed since its once per month.

                  pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                  pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                  J 1 Reply Last reply May 28, 2020, 8:29 AM Reply Quote 0
                  • R
                    RonpfS
                    last edited by RonpfS May 28, 2020, 2:56 AM May 28, 2020, 2:55 AM

                    It changes every 6 days, do you see the md5 download every day ?

                    2.4.5-RELEASE-p1 (amd64)
                    Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                    Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                    1 Reply Last reply Reply Quote 0
                    • S
                      serbus
                      last edited by May 28, 2020, 4:59 AM

                      Hello!

                      Is there a limit to the number of times per month you can download the files from maxmind?

                      I use the same license key in a number of different routers and routinely download "off schedule" when setting things up or troubleshooting.

                      Maybe you could create a new license key at the maxmind site and try that in your router.

                      John

                      Lex parsimoniae

                      1 Reply Last reply Reply Quote 0
                      • J
                        jdeloach @NollipfSense
                        last edited by May 28, 2020, 8:29 AM

                        @NollipfSense said in pfBlockerNG IP Reputation:

                        @RonpfS Last download was on May 5, 2020 at 14.56pm ... so, I guess I'll have to wait for June. I had to reinstall a fresh pfSense 2.5-dev so may explain why I haven't got the feed since its once per month.

                        Run this command from the command prompt to force Maxmind to update: php /usr/local/www/pfblockerng/pfblockerng.php dc . This should force the Maxmind.com database to update.

                        1 Reply Last reply Reply Quote 0
                        • G
                          Gertjan @NollipfSense
                          last edited by May 28, 2020, 8:35 AM

                          @jdeloach said in pfBlockerNG IP Reputation:

                          Run this command from the command prompt to force Maxmind to update: php /usr/local/www/pfblockerng/pfblockerng.php dc . This should force the Maxmind.com database to update.

                          He did ( see above ) :

                          @NollipfSense said in pfBlockerNG IP Reputation:

                          [2.5.0-DEVELOPMENT][admin@NollipfSense.nollipfsense.lan]/root: php /usr/local/www/pfblockerng/pfblockerng.php dc
                          Download Process Starting [ 05/27/20 10:55:35 ]

                          He wasn't authorized.

                          /usr/local/share/GeoIP/GeoLite2-Country.tar.gz 401 Unauthorized
                          Failed to Download GeoLite2-Country.mmdb
                          /usr/local/share/GeoIP/GeoLite2-Country-CSV.zip 401 Unauthorized
                          Failed to Download
                          Download Process Ended [ 05/27/20 10:55:36 ]

                          No "help me" PM's please. Use the forum, the community will thank you.
                          Edit : and where are the logs ??

                          1 Reply Last reply Reply Quote 0
                          • N
                            NollipfSense
                            last edited by NollipfSense May 30, 2020, 12:00 AM May 29, 2020, 9:34 PM

                            So, I contacted MaxMind support that confirmed that somehow when I did the force the update, it kept downloading last month's (April) database ... which is not available ... hence, the unauthorized message.

                            Support suggested "If you alter your download URL and remove the 'date' parameter entirely, that will make it download the most recent database available rather than a specific database version. Alternatively, you can use the 'Get permalinks' link in your Download Files page to get a permanent download URL that you can use."

                            So, m question: where would I find the download file to change or replace with "permalinks."

                            pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                            pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                            S 1 Reply Last reply May 30, 2020, 4:59 AM Reply Quote 0
                            • R
                              RonpfS
                              last edited by May 29, 2020, 9:55 PM

                              Maybe it's time to move this topic to pfblockerNG forum.

                              2.4.5-RELEASE-p1 (amd64)
                              Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                              Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                              N 1 Reply Last reply May 29, 2020, 11:16 PM Reply Quote 0
                              • N
                                NollipfSense @RonpfS
                                last edited by May 29, 2020, 11:16 PM

                                @RonpfS That's okay with me ... admin.

                                pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                                pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                                1 Reply Last reply Reply Quote 0
                                • S
                                  serbus @NollipfSense
                                  last edited by serbus May 30, 2020, 1:13 PM May 30, 2020, 4:59 AM

                                  @NollipfSense

                                  Hello!

                                  Pfb uses the maxmind permalink url for retrieving the maxmind db. It does not look like it asks for a specific version or month.

                                  Here is the url from the pfb code:

                                  https://download.maxmind.com/app/geoip_download?edition_id=GeoLite2-Country&license_key=MAXMIND_KEY&suffix=tar.gz

                                  You should be able to replace MAXMIND_KEY with your key and try the url in your browser.

                                  John

                                  Lex parsimoniae

                                  N 1 Reply Last reply May 30, 2020, 6:44 PM Reply Quote 0
                                  • N
                                    NollipfSense @serbus
                                    last edited by May 30, 2020, 6:44 PM

                                    @serbus Hello John, I preferred to let pfSense do the downloading instead of downloading it by way of the browser. I looked at this file: /usr/local/www/pfblockerng/pfblockerng_feeds.php ... however, no MaxMind url was in the file.

                                    Alternatively, I could wait until next Thursday when the new file would be available.

                                    pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                                    pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                                    1 Reply Last reply Reply Quote 0
                                    • S
                                      serbus
                                      last edited by May 30, 2020, 7:02 PM

                                      Hello!

                                      The maxmind urls are in usr/local/www/pfblockerng/pfblockerng.php

                                      Loading that link in your browser would just be a general test for your maxmind account, license key, and networks access to the download.

                                      John

                                      Lex parsimoniae

                                      N 1 Reply Last reply Jun 4, 2020, 10:03 AM Reply Quote 0
                                      • N
                                        NollipfSense @serbus
                                        last edited by Jun 4, 2020, 10:03 AM

                                        @serbus Well John, early this morning I tried again and got same unauthorized ... so, I tried the browser and got invalid key; so, I just generated a new key ... all is good.

                                        pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                                        pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                                        1 Reply Last reply Reply Quote 0
                                        • G Gertjan referenced this topic on Nov 26, 2021, 11:59 AM
                                        • G Gertjan referenced this topic on Nov 26, 2021, 12:00 PM
                                        26 out of 35
                                        • First post
                                          26/35
                                          Last post
                                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.