Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlockerNG-devel not showing blocked DNS requests

    pfBlockerNG
    3
    12
    2.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      vjizzle
      last edited by vjizzle

      Hi BBcan177!

      Thanks for getting back to me. I am already using pfBlockerNG-devel :). I just did the update to version 2.2.5_28 for MaxMind GeoIP. On pfSense I am using VLAN's for IPTV but not for my LAN. My LAN is the also the only interface selected in the DNSBL configuration. So the dns name I am talking about is: webhook.logentries.com. It is not showing anything when I enter it in a browser. Also this build of pfSense is like a week old and nothing special has been done. Just a basic install and then added pfBlocker-NG package.

      Another dns name I found to show the same behavior is ping.ui.com. It is blocked by pfBlocker-NG but it does not show up in the Alerts tab. I can find the lookup in the DNS Resolver logs but nothing being reported by pfBlocker-NG. I'm sure that I am doing something wrong or looking at the wrong place. I expect pfblocker-NG to be "honest" with me and show me exactly what DNS names are being sinkholed. At the moment it seems like for some reason it is not doing that. All help is appreciated guys!

      -- Edit: added screenshot from pfsense shell

      2020-01-03 16_00_30-Command Prompt.png

      As you can see a ping solves the domain ping.ui.com to the DNSBL vip. But the entry is not logged in the dnsbl.log file on pfsense. Do I need to adjust logfile settings somewhere in pfsense?

      BBcan177B 1 Reply Last reply Reply Quote 0
      • BBcan177B
        BBcan177 Moderator @vjizzle
        last edited by

        @vjizzle
        Do you have the "TLD" option enabled (wildcard blocking)?

        If so, then I would guess that the root domain of the two domains you posted are being blocked and those should be visible in your Reports tab.

        If you click on the "+" icon to whitelist those domains, you will see instructions on how to best whitelist.

        Try this command to see what domains are in the DNSBL database:

        grep "logentries.com" /var/unbound/pfb_dnsbl.conf
        

        "Experience is something you don't get until just after you need it."

        Website: http://pfBlockerNG.com
        Twitter: @BBcan177  #pfBlockerNG
        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

        1 Reply Last reply Reply Quote 0
        • V
          vjizzle
          last edited by

          @BBcan177
          I have double checked for TLD but it is off. I have never used that option. See attached screenshot for the grep command you asked. I was doing some testing an changed the DNSBL VIP to 172.16.0.1. That didn't solve my problem.

          2020-01-04 11_15_19-.png

          1 Reply Last reply Reply Quote 0
          • V
            vjizzle
            last edited by

            Hi guys!

            I have done some more testing and it seems like pfBlockerNG is only showing the HTTP and HTTPS blocked entries. When you do a ICMP (or other type besides http and https) lookup to a host which is blocked by pfBlockerNG it doesn't show up in the Alerts Tab. Any thoughts on this? I am struggling for some time now and I would really like to have pfBlockerNG running with pfsense and go for the all-in-one solution.

            1 Reply Last reply Reply Quote 0
            • BBcan177B
              BBcan177 Moderator
              last edited by

              There is no facility to log oher types of DNSBL blocked events at the moment. It will be possible with pfSense 2.4.5 and once the pfBlockerNG Unbound python integration is integrated.

              "Experience is something you don't get until just after you need it."

              Website: http://pfBlockerNG.com
              Twitter: @BBcan177  #pfBlockerNG
              Reddit: https://www.reddit.com/r/pfBlockerNG/new/

              V 1 Reply Last reply Reply Quote 0
              • V
                vjizzle
                last edited by vjizzle

                Ok clear BBcan177. Do you have a timeline for when that version and the unbound option is going to be released?
                If you need help in testing, I’m here.

                V 1 Reply Last reply Reply Quote 0
                • V
                  vjizzle @vjizzle
                  last edited by

                  @vjizzle said in pfBlockerNG-devel not showing blocked DNS requests:

                  Ok clear BBcan177. Do you have a timeline for when that version and the unbound option is going to be released?
                  If you need help in testing, I’m here.

                  Nevermind, I can see that there is no release date yet. Thanks BBcan. This topic can be closed I suppose.

                  1 Reply Last reply Reply Quote 0
                  • V
                    vjizzle @BBcan177
                    last edited by

                    @BBcan177 : the new version of pfSense is here with the python integration. Any word on the next pfBlockerNG release which will use that to show all allowed and blocked DNS requests? I'd be happy to help with testing.

                    1 Reply Last reply Reply Quote 0
                    • S
                      SriG
                      last edited by

                      @vjizzle I am facing the same issue, Is it possible to share the domains you have whitelisted to make Ikea gateway work? Thanks!

                      V 1 Reply Last reply Reply Quote 0
                      • V
                        vjizzle @SriG
                        last edited by

                        @srig Hi! The only domain I whitelisted for the Ikea gateway to work was webhook.logentries.com.
                        But now I got rid of the Ikea gateway. I hate it when a device will not work when you block all the telemetry and "phone-home" domains.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.