Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlockerNG DNSBL Categories not working

    Scheduled Pinned Locked Moved pfBlockerNG
    19 Posts 4 Posters 4.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jayb1
      last edited by

      Hi all,

      I've setup pfBlockerNG for the first time, and tried to use DNSBL Categories (both Shallalist and UT1) but it doesn't seem to working (it allows me to go to obvious porn sites that it should block).

      1.PNG

      I've selected "Porn" under both Shallalist and UT1, and my computer is using pfSense as the DNS server.

      I've updaded, CRON'd, restarted, disenabled and enabled, however I just can't seem to get this to work.

      Any ideas?

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @jayb1
        last edited by Gertjan

        @jayb1 said in pfBlockerNG DNSBL Categories not working:

        I just can't seem to get this to work.

        Can you show us what fails ?

        I selected some of them : Shallalist_aggressive, Shallalist_anonvpn, Shallalist_drugs and Shallalist_violence, just for testing purposes.
        Seems to work :

        d19c0708-69ad-411c-8035-ea99360a498b-image.png

        During a forced update :

        UPDATE PROCESS START [ 06/02/20 07:36:48 ]
        
        ===[  DNSBL Process  ]================================================
        
        Loading DNSBL Statistics... completed
        Loading DNSBL SafeSearch...  enabled
        Loading DNSBL Whitelist... completed
        Loading TOP1M Whitelist... completed
        
        [ Shallalist_adv ]		 Reload . completed ..
         Whitelist: doubleclick.net|googleadservices.com|
         ----------------------------------------------------------------------
         Orig.    Unique     # Dups     # White    # TOP1M    Final                
         ----------------------------------------------------------------------
         9929     9929       0          2          0          9927                 
         ----------------------------------------------------------------------
        
        [ Shallalist_aggressive ]	 Downloading update [ 06/02/20 07:36:49 ] ..
         ----------------------------------------------------------------------
         Orig.    Unique     # Dups     # White    # TOP1M    Final                
         ----------------------------------------------------------------------
         303      303        1          0          0          302                  
         ----------------------------------------------------------------------
        
        [ Shallalist_anonvpn ]		 Downloading update ..
         ----------------------------------------------------------------------
         Orig.    Unique     # Dups     # White    # TOP1M    Final                
         ----------------------------------------------------------------------
         390      390        0          0          0          390                  
         ----------------------------------------------------------------------
        
        [ Shallalist_drugs ]		 Downloading update ..
         ----------------------------------------------------------------------
         Orig.    Unique     # Dups     # White    # TOP1M    Final                
         ----------------------------------------------------------------------
         11015    11015      3          0          0          11012                
         ----------------------------------------------------------------------
        
        [ Shallalist_spyware ]		 Reload [ 06/02/20 07:36:50 ] . completed ..
         ----------------------------------------------------------------------
         Orig.    Unique     # Dups     # White    # TOP1M    Final                
         ----------------------------------------------------------------------
         19593    19593      321        0          0          19272                
         ----------------------------------------------------------------------
        
        [ Shallalist_violence ]		 Downloading update [ 06/02/20 07:36:51 ] ..
         ----------------------------------------------------------------------
         Orig.    Unique     # Dups     # White    # TOP1M    Final                
         ----------------------------------------------------------------------
         179      179        9          0          0          170                  
         ----------------------------------------------------------------------
        ........
        
        ........
        
        ====================[ DNSBL Last Updated List Summary ]==============
        
        Oct 22	2019	MDS_Immortal
        Dec 16	18:34	MalC0de
        Jan 22	13:15	MDL
        Jan 25	00:00	MoneroMiner
        Jan 25	00:00	NoCoin
        Jan 25	00:00	Zeus
        Feb 1	18:42	CoinBlocker_Opt
        Feb 1	18:42	CoinBlocker_All
        Feb 7	00:00	dShield_SD
        Apr 10	07:41	Abuse_DOMBL
        Apr 10	07:41	Abuse_URLBL
        Apr 10	07:42	Spam404
        May 3	07:19	MVPS
        May 11	10:50	AntiSocial_BD
        May 19	04:16	MDS
        May 23	04:34	SWC
        May 26	00:06	OISD
        May 31	06:00	Shallalist_adv
        May 31	06:00	Shallalist_spyware
        May 31	06:42	ISC_SDH
        May 31	23:00	SFS_Toxic_BD
        May 31	23:17	BBC_DC2
        May 31	23:21	D_Me_Malw
        May 31	23:21	D_Me_Malv
        Jun 2	07:36	Shallalist_aggressive
        Jun 2	07:36	Shallalist_anonvpn
        Jun 2	07:36	Shallalist_drugs
        Jun 2	07:36	Shallalist_violence
        ===============================================================
        
        Database Sanity check [  PASSED  ]
        ------------------------
        Masterfile/Deny folder uniq check
        Deny folder/Masterfile uniq check
        
        Sync check (Pass=No IPs reported)
        ----------
        
        Alias table IP Counts
        -----------------------------
          32644 total
          24897 /var/db/aliastables/pfB_Top_v4.txt
           2584 /var/db/aliastables/pfB_Top_v6.txt
           2274 /var/db/aliastables/pfB_PRI5_v4.txt
           1778 /var/db/aliastables/pfB_BlockListDE_v4.txt
           1098 /var/db/aliastables/pfB_PRI1_v4.txt
             13 /var/db/aliastables/pfB_Internic_4_v4.txt
        
        pfSense Table Stats
        -------------------
        table-entries hard limit  4000000
        Table Usage Count         145748
        
        UPDATE PROCESS ENDED [ 06/02/20 07:38:03 ]
        
        
        
        

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        1 Reply Last reply Reply Quote 0
        • J
          jayb1
          last edited by jayb1

          Hi,

          This is what is shown with a forced update.

           UPDATE PROCESS START [ 06/02/20 16:52:21 ]
          
          ===[  DNSBL Process  ]================================================
          
           Loading DNSBL Statistics... completed
           Loading DNSBL SafeSearch...  disabled
           Loading DNSBL Whitelist... completed
          
          Clearing all DNSBL Feeds completed
          TLD:
          TLD analysis no changes
          
          Saving DNSBL database... completed
          Reloading Unbound Resolver..... completed [ 06/02/20 16:52:27 ]
          DNSBL update [ 0 | PASSED  ]... completed
          ------------------------------------------------------------------------
          
          ===[  GeoIP Process  ]============================================
          
          
          ===[  IPv4 Process  ]=================================================
          
          [ Abuse_Feodo_C2_v4 ]		 exists.
          [ Abuse_IPBL_v4 ]		 exists.
          [ Abuse_SSLBL_v4 ]		 exists.
          [ BBC_C2_v4 ]			 exists.
          [ CINS_army_v4 ]		 exists.
          [ ET_Block_v4 ]			 exists.
          [ ET_Comp_v4 ]			 exists.
          [ ISC_1000_30_v4 ]		 exists.
          [ ISC_Block_v4 ]		 exists.
          [ Spamhaus_Drop_v4 ]		 exists.
          [ Spamhaus_eDrop_v4 ]		 exists.
          [ Talos_BL_v4 ]			 exists.
          
          ===[  Aliastables / Rules  ]==========================================
          
          No changes to Firewall rules, skipping Filter Reload
          No Changes to Aliases, Skipping pfctl Update
          
           UPDATE PROCESS ENDED
          
          

          It doesn't mention Shallalist.

          1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan
            last edited by

            Your pfBLockerNG version is ?

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            J 1 Reply Last reply Reply Quote 0
            • J
              jayb1 @Gertjan
              last edited by

              @Gertjan thanks for the help. It's pfBlockerNG-devel 2.2.5_32.

              1 Reply Last reply Reply Quote 0
              • GertjanG
                Gertjan
                last edited by

                That's the lastest one, like mine.

                You do have 'checked' some lists ?

                5eaad543-08de-4323-b2cb-dad5de0b5569-image.png

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                J 1 Reply Last reply Reply Quote 0
                • J
                  jayb1 @Gertjan
                  last edited by

                  @Gertjan Hi, yes I do. For example "porn" but then obvious porn sites are not blocked.

                  1 Reply Last reply Reply Quote 0
                  • J
                    jayb1
                    last edited by

                    Any body have any other ideas?

                    1 Reply Last reply Reply Quote 0
                    • RonpfSR
                      RonpfS
                      last edited by

                      @jayb1 said in pfBlockerNG DNSBL Categories not working:

                      telist... complet

                      You should post in the pfblockerNG Forum subsection.

                      So you ran a Force Update. Did you run a Force Reload DNSBL ?

                      Do you have DNSBL enabled? If not, enabled it, than run a Force Update and a Force Reload DNSBL. Inspect the logs.

                      Do you have any other DNSBL groups enabled? Enable at least one group, Force Update/Reload DNSBL, inspect the logs.

                      2.4.5-RELEASE-p1 (amd64)
                      Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                      Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                      J 1 Reply Last reply Reply Quote 1
                      • GertjanG
                        Gertjan
                        last edited by Gertjan

                        @RonpfS 👍 For DNSBL to be enabled, it should be enabled. Sounds stupid, but very true.

                        Btw : I selected this 'porn' thing, and saw this at the top of the page, after validating :

                        4581c896-3008-4983-9403-bcf7e6a2b9ce-image.png

                        what this means is that the list is typically huge.
                        "tld" condition apply : like this one eats Gigabytes of memory. If memory starts to fail, the rest of the list will get ignored.

                        edit : the porn list contains 730 000 entries - it's huge.

                        [ Shallalist_porn ]		 Downloading update [ 06/03/20 07:29:29 ] .
                          IDN converted: [ sendesık.com ]	 [ xn--sendesk-wfb.com ].
                          ----------------------------------------------------------------------
                          Orig.    Unique     # Dups     # White    # TOP1M    Final                
                          ----------------------------------------------------------------------
                          727947   727947     449        0          0          727498               
                          ----------------------------------------------------------------------
                        

                        Because my pfSEnse only contains 2 Gbytes of memory,I had this message :

                        TLD analysis..xxxxxxx completed [ 06/03/20 07:32:18 ]
                        
                          ** TLD Domain count exceeded. [ 150000 ] All subsequent Domains listed as-is **
                        
                        TLD finalize......................
                        

                        as explained. For this list you'll be needing something like 4 GBytes or even more.

                        When everything works, you would be able to :

                        1cd85635-dcdc-46e9-ad53-789843bcdad7-image.png

                        @jayb1 said in pfBlockerNG DNSBL Categories not working:

                        For example "porn" but then obvious porn sites are not blocked.

                        Always keep in mind that pfBlockerNG has no brains ^^
                        It just download for you a list that should represent sites of a certain kind. IP addresses keep changing all the time. Especially if they contain a lot of arguable content (and a lot of publicity). The people that created the list are doing this manually, as AI can't classify the entire Internet. So, false hits always exist.

                        No "help me" PM's please. Use the forum, the community will thank you.
                        Edit : and where are the logs ??

                        J 1 Reply Last reply Reply Quote 0
                        • J
                          jayb1 @RonpfS
                          last edited by

                          @RonpfS Sorry, did realise there was a pfBlockerNG forum section. Happy for a mod to shift it.

                          Yes, I've run multiple forced updates and reloaded DNSBL.

                          DBNSL is enabled.

                          The logs show no errors. Just the usual from the forced update.

                           UPDATE PROCESS START [ 06/03/20 16:17:34 ]
                          
                          ===[  DNSBL Process  ]================================================
                          
                           Loading DNSBL Statistics... completed
                           Loading DNSBL SafeSearch...  disabled
                           Loading DNSBL Whitelist... completed
                          
                          Clearing all DNSBL Feeds completed
                          TLD:
                          TLD analysis no changes
                          
                          Saving DNSBL database... completed
                          Reloading Unbound Resolver..... completed [ 06/03/20 16:17:40 ]
                          DNSBL update [ 0 | PASSED  ]... completed
                          ------------------------------------------------------------------------
                          
                          ===[  GeoIP Process  ]============================================
                          
                          
                          ===[  IPv4 Process  ]=================================================
                          
                          [ Abuse_Feodo_C2_v4 ]		 exists.
                          [ Abuse_IPBL_v4 ]		 exists.
                          [ Abuse_SSLBL_v4 ]		 exists.
                          [ BBC_C2_v4 ]			 exists.
                          [ CINS_army_v4 ]		 exists.
                          [ ET_Block_v4 ]			 exists.
                          [ ET_Comp_v4 ]			 exists.
                          [ ISC_1000_30_v4 ]		 exists.
                          [ ISC_Block_v4 ]		 exists.
                          [ Spamhaus_Drop_v4 ]		 exists.
                          [ Spamhaus_eDrop_v4 ]		 exists.
                          [ Talos_BL_v4 ]			 exists.
                          
                          ===[  Aliastables / Rules  ]==========================================
                          
                          No changes to Firewall rules, skipping Filter Reload
                          No Changes to Aliases, Skipping pfctl Update
                          
                           UPDATE PROCESS ENDED
                          

                          It is blocking from my computer when I check that log, but I assume this is the IPv4 ad blocking?

                          Jun 3 16:12:38,1770008388,igb1,LAN,block,4,17,UDP,192.168.128.109,212.178.154.174,51149,18183,out,NL,pfB_PRI1_v4,212.178.154.174,CINS_army_v4,D4B29AAE.static.ziggozakelijk.nl,JASON,null,-
                          Jun 3 16:12:38,1770008388,igb1,LAN,block,4,17,UDP,192.168.128.109,212.178.154.174,51149,18183,out,NL,pfB_PRI1_v4,212.178.154.174,CINS_army_v4,D4B29AAE.static.ziggozakelijk.nl,JASON,null,-
                          

                          I did have other groups enabled and it wasn't working, so I removed them all to simplify it and narrow down the problem (didn't help!).

                          Thanks for your time helping, it's much appreciated.

                          1 Reply Last reply Reply Quote 0
                          • RonpfSR
                            RonpfS
                            last edited by

                            That's IP blocking.

                            It looks like it doesn't enable DNSBL, do you use the DNS Resolver ?

                            2.4.5-RELEASE-p1 (amd64)
                            Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                            Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                            J 1 Reply Last reply Reply Quote 0
                            • J
                              jayb1 @Gertjan
                              last edited by

                              @Gertjan thanks for you response.

                              I have 4GB of memory and it doesn't seem to be stressing that out with only a few computers on the network.

                              It's not showing a Shallalist log...

                              Capture.PNG

                              Perhaps I just delete pfBlockerNG and start again?

                              1 Reply Last reply Reply Quote 0
                              • J
                                jayb1 @RonpfS
                                last edited by

                                @RonpfS said in pfBlockerNG DNSBL Categories not working:

                                DNS Resolver

                                Yes, the DNS resolver is on.

                                1 Reply Last reply Reply Quote 0
                                • GertjanG
                                  Gertjan
                                  last edited by

                                  Extra info : I activated that 'porn' list.
                                  unbound (the Resolver) never ended reloading- restarting.
                                  No more DNS :> no more surf. I had to remove it ....

                                  No "help me" PM's please. Use the forum, the community will thank you.
                                  Edit : and where are the logs ??

                                  1 Reply Last reply Reply Quote 0
                                  • RonpfSR
                                    RonpfS
                                    last edited by

                                    Try to un-tick Keep Settings, disable pfblockerNG, save Settings this will clear the DB.
                                    Uninstall, Install again, reconfigure, etc, remember to click on all

                                    2.4.5-RELEASE-p1 (amd64)
                                    Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                    Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                    J 1 Reply Last reply Reply Quote 2
                                    • J
                                      jayb1 @RonpfS
                                      last edited by

                                      @RonpfS said in pfBlockerNG DNSBL Categories not working:

                                      Try to un-tick Keep Settings, disable pfblockerNG, save Settings this will clear the DB.
                                      Uninstall, Install again, reconfigure, etc, remember to click on all

                                      This worked. I have no idea what was wrong with the first config.

                                      RonpfSR 1 Reply Last reply Reply Quote 0
                                      • RonpfSR
                                        RonpfS @jayb1
                                        last edited by

                                        @jayb1 👍

                                        2.4.5-RELEASE-p1 (amd64)
                                        Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                        Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                        1 Reply Last reply Reply Quote 0
                                        • G
                                          gurpreets
                                          last edited by

                                          dnsbl.png

                                          category filtering not working when I enter custom domain it works, could you please help me do block things category wise

                                          1 Reply Last reply Reply Quote 0
                                          • stephenw10S stephenw10 moved this topic from General pfSense Questions on
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.