Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfBlockerng Dlevel

    Scheduled Pinned Locked Moved pfBlockerNG
    12 Posts 6 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      abidkhanhk @NogBadTheBad
      last edited by

      @NogBadTheBad
      Yep that's already done, it's just that the DNSBL is not picking up those specific ads.
      So maybe there's a specific URL that needs to be blacklisted ,
      I was wondering if there's someway to monitor the TV ips traffic and then watch the URLs that it accesses a d then Black list those accordingly?
      Thanks

      1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad
        last edited by NogBadTheBad

        @abidkhanhk said in PfBlockerng Dlevel:

        was wondering if there's someway to monitor the TV ips traffic and then watch t

        You maybe could use GEOIP to block China via an alias if all the ads are coming from China:-

        Screenshot 2019-10-24 at 13.57.10.png

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        A 2 Replies Last reply Reply Quote 0
        • A
          abidkhanhk @NogBadTheBad
          last edited by

          @NogBadTheBad
          Thanks
          Let me give that a try
          Cheers

          1 Reply Last reply Reply Quote 0
          • A
            abidkhanhk @NogBadTheBad
            last edited by

            @NogBadTheBad
            Hi, did the GeoIP block and it seems chinese IPs are not being blocked, apart from this i noticed that the logs mentioned something like

            [ DNSBL_Malicious - ISC_SDL ] Download Fail [ 10/23/19 23:43:44 ]
            Firewall and/or IDS (Legacy mode only) are not blocking download.
            . unknown http status code | 0

            [ DNSBL_Malicious - Spam404 ] Download Fail [ 10/27/19 00:03:59 ]
            [ raw.githubusercontent.com ] Domain listed in DNSBL

            these 2 lists fail every time, i have set them to update every day 12 hours interval.

            1 Reply Last reply Reply Quote 0
            • NogBadTheBadN
              NogBadTheBad
              last edited by NogBadTheBad

              Looks like they are back working, sometimes the feed maintainer does something that causes the feeds to fail.

              Easiest thing to do is see if you can download them manually.

              Go into the Malicious collection and then copy the URL and paste it into another web browser tab.

              https://raw.githubusercontent.com/Dawsey21/Lists/master/main-blacklist.txt

              https://isc.sans.edu/feeds/suspiciousdomains_High.txt

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              A 1 Reply Last reply Reply Quote 0
              • A
                abidkhanhk @NogBadTheBad
                last edited by

                @NogBadTheBad Thanks, I will try that today.
                Cheers

                1 Reply Last reply Reply Quote 0
                • D
                  durianbusuk
                  last edited by durianbusuk

                  Try these blocklists for Chinese ad servers:

                  https://raw.githubusercontent.com/vokins/yhosts/master/hosts.txt
                  http://tools.yiclear.com/ChinaList2.0.txt

                  alternately go to filterlists.com and search for some Chinese blocklists.

                  Chinese ad servers are named very differently compared to others so you need specific blocklists.

                  or, if you're after one size fits most solution, use: https://dbl.oisd.nl/

                  personal experience has very no false positives on the sites I visit, lots of false positives in Chinese blogging sites but it'll work well in your use case.

                  Wanna take it a step further? add those lists above and turn on TLD. For some strange reason, this speeds up pfblocker too (for me anyway), HP T620 plus with 16GB ram.

                  C 1 Reply Last reply Reply Quote 0
                  • C
                    chrisgtl @durianbusuk
                    last edited by

                    @durianbusuk

                    How do I add https://dbl.oisd.nl/ ?

                    After I add it and update my lists it doesn't appear on the log.

                    1 Reply Last reply Reply Quote 0
                    • GertjanG
                      Gertjan
                      last edited by Gertjan

                      Be careful with this list.
                      It contains 870 thousand domain names. It's huge.

                      That will put a load on any router, even when it's driven a "the latest and greatest AMD/Intel" CPU.
                      8 or even 16 Gbytes of memory becomes a bare minimum.
                      If you use DNSBL => TLD, see minimum memory constraints .
                      The resolver, unbound, has to maintaine a huge internal DNS cache ..... and every DNS request will get compared with this list.
                      Do NOT try to download this list every 10 minutes or so ....

                      Btw : it might be advisable not to visit chinese sites, or visit sites that link back to these sites, and: you won't be needing this list.

                      No "help me" PM's please. Use the forum, the community will thank you.
                      Edit : and where are the logs ??

                      1 Reply Last reply Reply Quote 0
                      • RicoR
                        Rico LAYER 8 Rebel Alliance
                        last edited by

                        Here is the OISD light version: https://dbl.oisd.nl/light/

                        -Rico

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.