Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfblocker use without unbound

    pfBlockerNG
    3
    9
    495
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      blackops786187
      last edited by

      Hi,

      Is there anyway to use the DNSBL feature without unbound and use an upstream provider like cloudflare?

      1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan
        last edited by

        Hi,

        The IP's based lists Pfblocker creates from the feeds are put ito alias(es), and used by pf.
        So, when you limit Pfblocker to IP based feeds, probably yes. Give it a try ?

        The DNSBL presumes the presence of Unbound.

        abf749d2-6cf0-4237-a6bb-4aef3b728d6e-image.png

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        1 Reply Last reply Reply Quote 0
        • B
          blackops786187
          last edited by

          Hi

          I'm basically trying to get it setup like pihole where if a DNS name.is not in the list it will forward then query to the chosen dns provider e.g cloudflare Google DNS etc

          1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan
            last edited by

            pfBlockerNG does somewhat the same thing.

            The advantage of pfBlockerNG is that you do not need another device on your LAN or elsewhere.
            pfBlockerNG , as far as I know, doesn't communicate with other devices - on your LAN, or elsewhere, except loading the feeds.

            Btw : I didn't say that pi-hole and pfBlockerNG are the same thing ^^
            I also presume that if you use pi-home, you do not really need pfBlockerNG - neither unbound as a resolver : just forward to the pi-hole and you're good.

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            1 Reply Last reply Reply Quote 0
            • B
              blackops786187
              last edited by

              I've got pihole setup but I'd rather just use one pfsense box with pfblocker however the dnsnbl features uses unbound which is slow imo hence why I'm asking if I can set cloudflare as my upstream DNS provider rather than using unbound

              1 Reply Last reply Reply Quote 0
              • GertjanG
                Gertjan
                last edited by

                pi-hole and pfBlockerNG ?
                Very strange, as you will be needing unbound in resolver mode. And resolver mode means : unbound speaks to the root - tld and name servers and to no one else (it's not going to inform some company about your DNS requests).

                You have to make a choice.

                Using a pi-hole and then forwarding to cloudfare ?
                Also strange (to me). I thought (?) that pi-hole is/was also a resolver.

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                B 1 Reply Last reply Reply Quote 0
                • B
                  blackops786187 @Gertjan
                  last edited by

                  @Gertjan

                  Nope pihole was always like this. It doesn't use unbound by default.

                  1 Reply Last reply Reply Quote 0
                  • GertjanG
                    Gertjan
                    last edited by

                    I just figured out that pi-hole is based upon dnsmasq - which is a DNS fiorwarder.

                    You have to give your DNS requests, that is, the one that are permitted, to one of these :
                    a21d5888-7e51-4ed2-972e-58cc9c31554b-image.png

                    or - why not, your ISP DNS.

                    WTF : pi-hole is a nice front-end for the major data collectors ??

                    (I was pretty sure this wasn't the case ...)

                    ( ... DNSSEC, as the image shows - doesn't make any sense, when forwarding ).

                    edit :
                    My interrogation is mentioned here : https://discourse.pi-hole.net/t/add-the-ability-to-let-pi-hole-resolve-dns/2368
                    And they included unbound .... https://docs.pi-hole.net/guides/unbound/

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    1 Reply Last reply Reply Quote 0
                    • C
                      chrcoluk
                      last edited by

                      Yes very simple, configure cloud DNS ip's on the general setup screen under "dns server settings"

                      Then go to services -> dns resolver.

                      Tick the box next to "dns query forwarding"

                      Save, apply, done.

                      pfSense CE 2.7.2

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.