Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlockerNG-devel not showing blocked DNS requests

    pfBlockerNG
    3
    12
    2.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • BBcan177B
      BBcan177 Moderator @vjizzle
      last edited by

      @vjizzle
      Are you using VLANs? If you put that domain in a browser directly what does it show in the Alerts tab. Would also recommend to use pfBlockerNG-devel.

      "Experience is something you don't get until just after you need it."

      Website: http://pfBlockerNG.com
      Twitter: @BBcan177  #pfBlockerNG
      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

      1 Reply Last reply Reply Quote 0
      • V
        vjizzle
        last edited by vjizzle

        Hi BBcan177!

        Thanks for getting back to me. I am already using pfBlockerNG-devel :). I just did the update to version 2.2.5_28 for MaxMind GeoIP. On pfSense I am using VLAN's for IPTV but not for my LAN. My LAN is the also the only interface selected in the DNSBL configuration. So the dns name I am talking about is: webhook.logentries.com. It is not showing anything when I enter it in a browser. Also this build of pfSense is like a week old and nothing special has been done. Just a basic install and then added pfBlocker-NG package.

        Another dns name I found to show the same behavior is ping.ui.com. It is blocked by pfBlocker-NG but it does not show up in the Alerts tab. I can find the lookup in the DNS Resolver logs but nothing being reported by pfBlocker-NG. I'm sure that I am doing something wrong or looking at the wrong place. I expect pfblocker-NG to be "honest" with me and show me exactly what DNS names are being sinkholed. At the moment it seems like for some reason it is not doing that. All help is appreciated guys!

        -- Edit: added screenshot from pfsense shell

        2020-01-03 16_00_30-Command Prompt.png

        As you can see a ping solves the domain ping.ui.com to the DNSBL vip. But the entry is not logged in the dnsbl.log file on pfsense. Do I need to adjust logfile settings somewhere in pfsense?

        BBcan177B 1 Reply Last reply Reply Quote 0
        • BBcan177B
          BBcan177 Moderator @vjizzle
          last edited by

          @vjizzle
          Do you have the "TLD" option enabled (wildcard blocking)?

          If so, then I would guess that the root domain of the two domains you posted are being blocked and those should be visible in your Reports tab.

          If you click on the "+" icon to whitelist those domains, you will see instructions on how to best whitelist.

          Try this command to see what domains are in the DNSBL database:

          grep "logentries.com" /var/unbound/pfb_dnsbl.conf
          

          "Experience is something you don't get until just after you need it."

          Website: http://pfBlockerNG.com
          Twitter: @BBcan177  #pfBlockerNG
          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

          1 Reply Last reply Reply Quote 0
          • V
            vjizzle
            last edited by

            @BBcan177
            I have double checked for TLD but it is off. I have never used that option. See attached screenshot for the grep command you asked. I was doing some testing an changed the DNSBL VIP to 172.16.0.1. That didn't solve my problem.

            2020-01-04 11_15_19-.png

            1 Reply Last reply Reply Quote 0
            • V
              vjizzle
              last edited by

              Hi guys!

              I have done some more testing and it seems like pfBlockerNG is only showing the HTTP and HTTPS blocked entries. When you do a ICMP (or other type besides http and https) lookup to a host which is blocked by pfBlockerNG it doesn't show up in the Alerts Tab. Any thoughts on this? I am struggling for some time now and I would really like to have pfBlockerNG running with pfsense and go for the all-in-one solution.

              1 Reply Last reply Reply Quote 0
              • BBcan177B
                BBcan177 Moderator
                last edited by

                There is no facility to log oher types of DNSBL blocked events at the moment. It will be possible with pfSense 2.4.5 and once the pfBlockerNG Unbound python integration is integrated.

                "Experience is something you don't get until just after you need it."

                Website: http://pfBlockerNG.com
                Twitter: @BBcan177  #pfBlockerNG
                Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                V 1 Reply Last reply Reply Quote 0
                • V
                  vjizzle
                  last edited by vjizzle

                  Ok clear BBcan177. Do you have a timeline for when that version and the unbound option is going to be released?
                  If you need help in testing, I’m here.

                  V 1 Reply Last reply Reply Quote 0
                  • V
                    vjizzle @vjizzle
                    last edited by

                    @vjizzle said in pfBlockerNG-devel not showing blocked DNS requests:

                    Ok clear BBcan177. Do you have a timeline for when that version and the unbound option is going to be released?
                    If you need help in testing, I’m here.

                    Nevermind, I can see that there is no release date yet. Thanks BBcan. This topic can be closed I suppose.

                    1 Reply Last reply Reply Quote 0
                    • V
                      vjizzle @BBcan177
                      last edited by

                      @BBcan177 : the new version of pfSense is here with the python integration. Any word on the next pfBlockerNG release which will use that to show all allowed and blocked DNS requests? I'd be happy to help with testing.

                      1 Reply Last reply Reply Quote 0
                      • S
                        SriG
                        last edited by

                        @vjizzle I am facing the same issue, Is it possible to share the domains you have whitelisted to make Ikea gateway work? Thanks!

                        V 1 Reply Last reply Reply Quote 0
                        • V
                          vjizzle @SriG
                          last edited by

                          @srig Hi! The only domain I whitelisted for the Ikea gateway to work was webhook.logentries.com.
                          But now I got rid of the Ikea gateway. I hate it when a device will not work when you block all the telemetry and "phone-home" domains.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.