Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNSBL service unable to enable

    Scheduled Pinned Locked Moved pfBlockerNG
    8 Posts 2 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      trewflight48
      last edited by

      Novice user***
      that's reallly lost..help me please.

      I just cant get DNSBL to enable. When I run update - reload. I always get the same message. ---->

      START OF MESSAGEthe reload update message*****************
      [1607002644] unbound[6451:0] error: bind: address already in use
      [1607002644] unbound[6451:0] fatal error: could not open ports

      ====================

      Stopping Unbound Resolver..............................
      Additional mounts:
      Starting Unbound Resolver.. Not completed. [ 12/03/20 07:37:56 ]
      [1607002676] unbound[13596:0] error: bind: address already in use
      [1607002676] unbound[13596:0] fatal error: could not open ports
      error: SSL handshake failed
      1085559856:error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed:/usr/home/luiz/crossbuild/sources/FreeBSD-src/crypto/openssl/ssl/s3_clnt.c:1269:

      *** DNSBL update [ 0 ] [ 445119 ] ... OUT OF SYNC ! *** [ 12/03/20 07:37:57 ]
      END--------------------------------------------------------------------

      dns resolver log enteries.JPG

      VIP.JPG

      T 1 Reply Last reply Reply Quote 0
      • T
        trewflight48 @trewflight48
        last edited by

        @trewflight48
        hit the submit button on accident.

        I've also made sure the VIP address is something that nothing uses and I made sure the port doesnt conflict.

        Status Log of System Log.JPG

        Also dpinger keeps on giving me these messages

        DPINGER.JPG

        thanks in advance.
        Trewflight

        1 Reply Last reply Reply Quote 0
        • T
          trewflight48
          last edited by

          Ok I solved the problem. This is what i did. I manually stopped the DNS resolver service and then re-enabled it; manually. Had to watch the update logs to be on point but I got it.

          One thing is wierd though I dont understand why under Status/DNS Resolver it is a block status.

          Under System/General Setup under the "DNS Server Settings" i have 2 dns server's ip's. i chose Cloudfares. I left the DNS Host name blank. Thats the only place anykind of DNS setting is placed.
          Please help. Thanks.

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan @trewflight48
            last edited by

            @trewflight48 said in DNSBL service unable to enable:

            under Status/DNS Resolver it is a block status.

            Block status ?
            All I see is an ongoing list like :

            7c81ea13-ffd6-41f4-b019-7a1f21251cd7-image.png

            @trewflight48 said in DNSBL service unable to enable:

            Also dpinger keeps on giving me these messages

            It can reach the gateway - the IP it uses to ping, chose another one.

            /etc/rc.packages

            What pfBlockerNG version are you using ?
            What pfSense version ?

            unbound :

            Your using a cert somewhere that is :

            c0a68967-5e08-4e1e-80cb-0c1f7569b216-image.png

            Expired as your credit card expires : you know what to do.

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            T 1 Reply Last reply Reply Quote 0
            • T
              trewflight48 @Gertjan
              last edited by

              @gertjan
              @Gertjan said Block Status ?

              new DNS Resolver status.JPG

              i'm using pfblockerNG-devel
              and
              2.4.5-RELEASE-p1 (arm64)
              built on Tue Sep 15 10:30:40 EDT 2020
              FreeBSD 11.3-STABLE

              @Gertjan said "Your using a cert somewhere that is:

              I didnt know i had one.

              also wanted to point out i'm using a netgate 1100 bought from pfsense. It has vlans set up.
              on General Setup should I even be setting DNS server?

              GertjanG 1 Reply Last reply Reply Quote 0
              • GertjanG
                Gertjan @trewflight48
                last edited by

                @trewflight48 said in DNSBL service unable to enable:

                on General Setup should I even be setting DNS server?

                No.

                Block status :
                The Status / DNS Resolver page lists host names resolved by the resolver.
                That list will never be empty, except maybe the first second or two after a reboot, with no devices connected on LAN.

                The Status / DNS Resolver page has nothing to do with pfblockerNG-devel.

                @trewflight48 said in DNSBL service unable to enable:

                I didnt know i had one.

                See System / Certificate Manager / Certificates and CA.

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                T 1 Reply Last reply Reply Quote 0
                • T
                  trewflight48 @Gertjan
                  last edited by

                  @gertjan

                  it's the pfSense webConfigurator Self-Signed Certificate

                  What should I do?

                  T 1 Reply Last reply Reply Quote 0
                  • T
                    trewflight48 @trewflight48
                    last edited by

                    @trewflight48
                    gonna watch this video I guess I have alot to learn still.

                    How To Setup ACME, Let's Encrypt, and HAProxy HTTPS offloading on pfsense.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.