Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfBlockerng Dlevel

    Scheduled Pinned Locked Moved pfBlockerNG
    12 Posts 6 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NogBadTheBadN
      NogBadTheBad
      last edited by

      Enable DNSBL:-

      Screenshot 2019-10-24 at 13.37.37.png

      Andy

      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

      A 1 Reply Last reply Reply Quote 0
      • A
        abidkhanhk @NogBadTheBad
        last edited by

        @NogBadTheBad
        Yep that's already done, it's just that the DNSBL is not picking up those specific ads.
        So maybe there's a specific URL that needs to be blacklisted ,
        I was wondering if there's someway to monitor the TV ips traffic and then watch the URLs that it accesses a d then Black list those accordingly?
        Thanks

        1 Reply Last reply Reply Quote 0
        • NogBadTheBadN
          NogBadTheBad
          last edited by NogBadTheBad

          @abidkhanhk said in PfBlockerng Dlevel:

          was wondering if there's someway to monitor the TV ips traffic and then watch t

          You maybe could use GEOIP to block China via an alias if all the ads are coming from China:-

          Screenshot 2019-10-24 at 13.57.10.png

          Andy

          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

          A 2 Replies Last reply Reply Quote 0
          • A
            abidkhanhk @NogBadTheBad
            last edited by

            @NogBadTheBad
            Thanks
            Let me give that a try
            Cheers

            1 Reply Last reply Reply Quote 0
            • A
              abidkhanhk @NogBadTheBad
              last edited by

              @NogBadTheBad
              Hi, did the GeoIP block and it seems chinese IPs are not being blocked, apart from this i noticed that the logs mentioned something like

              [ DNSBL_Malicious - ISC_SDL ] Download Fail [ 10/23/19 23:43:44 ]
              Firewall and/or IDS (Legacy mode only) are not blocking download.
              . unknown http status code | 0

              [ DNSBL_Malicious - Spam404 ] Download Fail [ 10/27/19 00:03:59 ]
              [ raw.githubusercontent.com ] Domain listed in DNSBL

              these 2 lists fail every time, i have set them to update every day 12 hours interval.

              1 Reply Last reply Reply Quote 0
              • NogBadTheBadN
                NogBadTheBad
                last edited by NogBadTheBad

                Looks like they are back working, sometimes the feed maintainer does something that causes the feeds to fail.

                Easiest thing to do is see if you can download them manually.

                Go into the Malicious collection and then copy the URL and paste it into another web browser tab.

                https://raw.githubusercontent.com/Dawsey21/Lists/master/main-blacklist.txt

                https://isc.sans.edu/feeds/suspiciousdomains_High.txt

                Andy

                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                A 1 Reply Last reply Reply Quote 0
                • A
                  abidkhanhk @NogBadTheBad
                  last edited by

                  @NogBadTheBad Thanks, I will try that today.
                  Cheers

                  1 Reply Last reply Reply Quote 0
                  • D
                    durianbusuk
                    last edited by durianbusuk

                    Try these blocklists for Chinese ad servers:

                    https://raw.githubusercontent.com/vokins/yhosts/master/hosts.txt
                    http://tools.yiclear.com/ChinaList2.0.txt

                    alternately go to filterlists.com and search for some Chinese blocklists.

                    Chinese ad servers are named very differently compared to others so you need specific blocklists.

                    or, if you're after one size fits most solution, use: https://dbl.oisd.nl/

                    personal experience has very no false positives on the sites I visit, lots of false positives in Chinese blogging sites but it'll work well in your use case.

                    Wanna take it a step further? add those lists above and turn on TLD. For some strange reason, this speeds up pfblocker too (for me anyway), HP T620 plus with 16GB ram.

                    C 1 Reply Last reply Reply Quote 0
                    • C
                      chrisgtl @durianbusuk
                      last edited by

                      @durianbusuk

                      How do I add https://dbl.oisd.nl/ ?

                      After I add it and update my lists it doesn't appear on the log.

                      1 Reply Last reply Reply Quote 0
                      • GertjanG
                        Gertjan
                        last edited by Gertjan

                        Be careful with this list.
                        It contains 870 thousand domain names. It's huge.

                        That will put a load on any router, even when it's driven a "the latest and greatest AMD/Intel" CPU.
                        8 or even 16 Gbytes of memory becomes a bare minimum.
                        If you use DNSBL => TLD, see minimum memory constraints .
                        The resolver, unbound, has to maintaine a huge internal DNS cache ..... and every DNS request will get compared with this list.
                        Do NOT try to download this list every 10 minutes or so ....

                        Btw : it might be advisable not to visit chinese sites, or visit sites that link back to these sites, and: you won't be needing this list.

                        No "help me" PM's please. Use the forum, the community will thank you.
                        Edit : and where are the logs ??

                        1 Reply Last reply Reply Quote 0
                        • RicoR
                          Rico LAYER 8 Rebel Alliance
                          last edited by

                          Here is the OISD light version: https://dbl.oisd.nl/light/

                          -Rico

                          1 Reply Last reply Reply Quote 1
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.