Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlockerNG-devel v3.0.0_10

    Scheduled Pinned Locked Moved pfBlockerNG
    26 Posts 6 Posters 3.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • BBcan177B
      BBcan177 Moderator @LabDog
      last edited by

      @labdog
      See the following redmine:
      https://redmine.pfsense.org/issues/11398

      "Experience is something you don't get until just after you need it."

      Website: http://pfBlockerNG.com
      Twitter: @BBcan177  #pfBlockerNG
      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

      1 Reply Last reply Reply Quote 0
      • S
        Smoothrunnings
        last edited by

        Seeing these errors in my alert logs.

        There were error(s) loading the rules: /tmp/rules.debug:19: cannot define table bogonsv6: Cannot allocate memory - The line in question reads [19]: table <bogonsv6> persist file "/etc/bogonsv6"

        Not sure if its related to me being on 2.4.5 previously? I just upgraded to 2.5.0

        S 1 Reply Last reply Reply Quote 0
        • S
          SteveITS Galactic Empire @Smoothrunnings
          last edited by

          @smoothrunnings said in pfBlockerNG-devel v3.0.0_10:

          There were error(s) loading the rules: /tmp/rules.debug:19: cannot define table bogonsv6: Cannot allocate memory - The line in question reads [19]: table <bogonsv6> persist file "/etc/bogonsv6"

          What are your Firewall Maximum Table Entries set to in System/Advanced/Firewall & NAT? I believe the recommendation is double the default, minimum 2 million.

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote 👍 helpful posts!

          S 1 Reply Last reply Reply Quote 0
          • S
            Smoothrunnings @SteveITS
            last edited by

            @teamits 400,000 (without the comma)

            RonpfSR 1 Reply Last reply Reply Quote 0
            • RonpfSR
              RonpfS @Smoothrunnings
              last edited by RonpfS

              @smoothrunnings https://forum.netgate.com/topic/149418/cannot-allocate-memor-after-adding-geo-ip/6

              2.4.5-RELEASE-p1 (amd64)
              Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
              Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

              S 1 Reply Last reply Reply Quote 0
              • S
                Smoothrunnings @RonpfS
                last edited by

                @RonpfS

                I running NTopng, HAProxy, plus the pfBlockerNG. And today my firewall has been rebooting every hour or so. After it reboots the haproxy, ntopng, and the pfb_dnsbl and pfb_filter services are not running, as soon as I start them the firewall will reboot upto an update from the time of start.

                The Firewall Maximum Table has been set to 2000000 and it sell reboots.

                (sigh)...looks like I am going to have to rip out pfBlocker. :(

                RonpfSR 1 Reply Last reply Reply Quote 0
                • RonpfSR
                  RonpfS @Smoothrunnings
                  last edited by

                  @smoothrunnings said in pfBlockerNG-devel v3.0.0_10:

                  The Firewall Maximum Table has been set to 2000000 and it sell reboots.

                  Double that.

                  2.4.5-RELEASE-p1 (amd64)
                  Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                  Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                  S 1 Reply Last reply Reply Quote 0
                  • S
                    Smoothrunnings @RonpfS
                    last edited by

                    @ronpfs said in pfBlockerNG-devel v3.0.0_10:

                    @smoothrunnings said in pfBlockerNG-devel v3.0.0_10:

                    The Firewall Maximum Table has been set to 2000000 and it sell reboots.

                    Double that.

                    Ok it's double now. Let's see how it goes. Fingers crossed.

                    RonpfSR 1 Reply Last reply Reply Quote 0
                    • RonpfSR
                      RonpfS @Smoothrunnings
                      last edited by RonpfS

                      @smoothrunnings From what I read double it until the rules load.

                      2.4.5-RELEASE-p1 (amd64)
                      Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                      Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                      J S 2 Replies Last reply Reply Quote 0
                      • J
                        jdeloach @RonpfS
                        last edited by jdeloach

                        @ronpfs said in pfBlockerNG-devel v3.0.0_10:

                        @smoothrunnings From what I read double until the rules load.

                        For what it's worth, on my system it is showing 4000000 as the default for the Firewall Maximum Table Entries. I thought it was set 2000000. I am not having any issues with any problems.

                        S 1 Reply Last reply Reply Quote 0
                        • S
                          Smoothrunnings @RonpfS
                          last edited by

                          @ronpfs

                          pfSense keeps rebooting. I am up to 8000000, just about to double it again. so that will be 16000000.

                          Looks like there is a problem with pfBlockerNG.

                          1 Reply Last reply Reply Quote 0
                          • S
                            SteveITS Galactic Empire
                            last edited by

                            I'm going to post here only because it's the version I installed today. :) I can shorten the description significantly just by saying that if pfBlockerNG has its Enable box unchecked, and I go to the Update tab and click Run, the page scrolls up an inch or two then snaps back to the top of the page and nothing happens.

                            IOW the update process only runs if the Enable box is checked. That's logical, I suppose, for automatic updates, but I figured I would get everything ready before enabling it...and there is no error or notice that it won't run. The log has no output. Perhaps some sort of output that "pfBlocker is disabled, why did you click to update, you knucklehead?"

                            @jdeloach said in pfBlockerNG-devel v3.0.0_10:

                            showing 4000000 as the default for the Firewall Maximum Table Entries

                            The default varies based on RAM, IIRC. Interestingly the SG-2100 I was setting up came with 2.4.5, we upgraded to 21.02, and it was showing as 400000. But after I changed it to 2m I noticed it says the default is 2m. So perhaps it increased in 21.02?

                            @smoothrunnings said in pfBlockerNG-devel v3.0.0_10:

                            pfSense keeps rebooting

                            The out of memory error can't really cause a reboot AFAIK. I think those are two different symptoms. You only need a table size big enough to handle the table entries you're loading.

                            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                            Upvote 👍 helpful posts!

                            RonpfSR S 2 Replies Last reply Reply Quote 0
                            • S
                              Smoothrunnings @jdeloach
                              last edited by

                              @jdeloach

                              You likely aren't running the extra stuff I have such as haproxy, and ntopng. I also have my guest WiFi connection going through my pfSense from Unifi. It wasn't crashing before I installed pfBlockerNG, after that's been nothing but issues. :(

                              1 Reply Last reply Reply Quote 0
                              • RonpfSR
                                RonpfS @SteveITS
                                last edited by

                                @teamits said in pfBlockerNG-devel v3.0.0_10:

                                So perhaps it increased in 21.02?

                                Nope, it just take your number as default. :)

                                2.4.5-RELEASE-p1 (amd64)
                                Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                S 2 Replies Last reply Reply Quote 0
                                • S
                                  SteveITS Galactic Empire @RonpfS
                                  last edited by

                                  @ronpfs said in pfBlockerNG-devel v3.0.0_10:

                                  Nope, it just take your number as default. :)

                                  You're right. That's dumb. 2.4.5 does that too.

                                  Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                  When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                                  Upvote 👍 helpful posts!

                                  1 Reply Last reply Reply Quote 0
                                  • S
                                    Smoothrunnings @SteveITS
                                    last edited by

                                    @teamits said in pfBlockerNG-devel v3.0.0_10:

                                    @smoothrunnings said in pfBlockerNG-devel v3.0.0_10:

                                    pfSense keeps rebooting

                                    The out of memory error can't really cause a reboot AFAIK. I think those are two different symptoms. You only need a table size big enough to handle the table entries you're loading.

                                    So provide me with the tool/instructions to verify that instead of just stating it.

                                    What I am stating and will continue to state is I am running this on a WatchGuard M400 with an intel i5-4750, 8GB of RAM, and 250GB SSD.

                                    Since last week I have been running my M400 with DHCP services for my WiFi Guest network, along with haproxy and ntopng for about a year without any issues, at the time I installed pfBlockerNG 3.0 Devel I was running on 2.4.5 and was getting the random reboots of pfSense on 2.4.5 which why I rolled over to 2.5.0.

                                    Looking at my pfSense this morning its uptime is 55 minutes right now, meaning through the night its rebooted.

                                    I think at this point someone needs to give me a hand looking through the logs to see why the pfsense keeps rebooting. Maybe it's coincidence that it started happening after pfBlockerNG was installed, but maybe it's it not, no one will really know until I get some help (the firewall just rebooted again), looks like its this time it hit about 6764 blocked IPs and rebooted. As I was saying the answer will likely be in the logs, but I don't know what to look for, so instead of just pointing fingers or saying "its working here" help.

                                    Thanks,

                                    RonpfSR 1 Reply Last reply Reply Quote 0
                                    • RonpfSR
                                      RonpfS @Smoothrunnings
                                      last edited by

                                      @smoothrunnings Maybe start a new forum post with Settings info and logs.

                                      2.4.5-RELEASE-p1 (amd64)
                                      Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                      Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                      S 1 Reply Last reply Reply Quote 1
                                      • S
                                        Smoothrunnings @RonpfS
                                        last edited by Smoothrunnings

                                        @ronpfs

                                        Looks like there might be an issue with ntopng and pfBlockerNG. I saw some errors in the logs for ntopng, so decided to remove the service and so far (knock on wood) pfSense has been running for over 4 hours and pfBlockerNG has blocked over 28k IPs without a reboot.

                                        Whats a good forum to start a new thread in, in case there is some weird issue going on?

                                        Thanks,

                                        Updated typo's

                                        RonpfSR 1 Reply Last reply Reply Quote 0
                                        • RonpfSR
                                          RonpfS @Smoothrunnings
                                          last edited by

                                          @smoothrunnings Maybe in https://forum.netgate.com/category/54/traffic-monitoring

                                          2.4.5-RELEASE-p1 (amd64)
                                          Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                          Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                          1 Reply Last reply Reply Quote 0
                                          • S
                                            SteveITS Galactic Empire @RonpfS
                                            last edited by

                                            @ronpfs said in pfBlockerNG-devel v3.0.0_10:

                                            it just take your number as default

                                            FWIW I made https://redmine.pfsense.org/issues/11566

                                            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                                            Upvote 👍 helpful posts!

                                            S 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.