Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    shopify sites

    Scheduled Pinned Locked Moved pfBlockerNG
    33 Posts 10 Posters 3.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jpvonhemel
      last edited by

      My blocked sites, clivecoffee.com and huckleberrycoffee.com do not display the pfblocker black and red screen on load, they simply return this. I am thinking the ipv4 ip address is blocked, and not the domain. I am trying to create an alias whitelist with the ip address, but it does not seem to fix the issue.

      Annotation 2020-07-08 095819.jpg

      J 1 Reply Last reply Reply Quote 0
      • J
        jdeloach @jpvonhemel
        last edited by

        @jpvonhemel said in shopify sites:

        My blocked sites, clivecoffee.com and huckleberrycoffee.com do not display the pfblocker black and red screen on load, they simply return this. I am thinking the ipv4 ip address is blocked, and not the domain. I am trying to create an alias whitelist with the ip address, but it does not seem to fix the issue.

        Annotation 2020-07-08 095819.jpg

        If you haven't already done so, you might give this doc a read as it explains a lot about how to configure DNSBL on pfBlockerNG. It's a little dated but for the most part it is still accurate https://linuxincluded.com/block-ads-malvertising-on-pfsense-using-pfblockerng-dnsbl/.

        J 2 Replies Last reply Reply Quote 0
        • J
          jpvonhemel @jdeloach
          last edited by

          @johnpoz said in shopify sites:

          And how do you know its blocking? what IP is it resolving too? Are you getting NX, Refused when you try and query it?

          Hi John Poz,

          I'm sorry, but I don't know what you mean by NX, refused. Would you mind explaining this to me. I would like to learn this.

          Thanks,

          Jerold

          1 Reply Last reply Reply Quote 0
          • J
            jpvonhemel @jdeloach
            last edited by

            If you haven't already done so, you might give this doc a read as it explains a lot about how to configure DNSBL on pfBlockerNG. It's a little dated but for the most part it is still accurate https://linuxincluded.com/block-ads-malvertising-on-pfsense-using-pfblockerng-dnsbl/.

            Thanks, I will take a look

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator
              last edited by

              A query with your fav dns query tool, dig, host, nslookup NXdomain meaning what you looking for does not exist, or can not be found. While Refused NS saying he not going to answer you - even if he knew the answer.. SERVFAIL would be another possible status listed in your query.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              1 Reply Last reply Reply Quote 0
              • GertjanG
                Gertjan
                last edited by

                The coffee sites are Cloudfare based - a big web hosting operator.

                My guess : you're using a pfBockerNG feed that blacklists entire 'cloudfare' networks, not just the coffee domain names.
                Like 23.227.38.64 and 23.227.38.32 you could find 23.227.0.0/16

                When you see http://23.227.38.64/ you know that http://23.227.38.64/ is a coffee site, but also site that sells book, heavy porn, etc etc (examples) It's a shared virtual web server. One IP hosts many web sites.

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by johnpoz

                  Blocking cloudflare IPs would be a horrible idea if you actually want to you know use the internet ;)

                  edit: Quick number pulled up
                  "Cloudflare is used by 81.2% of all the websites whose reverse proxy service we know. This is 13.6% of all websites."

                  That would be a huge freaking chunk of net to just block ;)

                  Blocking IPs of major CDN's not really a good idea if you actually want to use the internet ;) Blocking by specific domain names is much better way to block stuff you want to block.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                  1 Reply Last reply Reply Quote 1
                  • SebMS
                    SebM
                    last edited by

                    Did someone ever come up with an elegant solution to this problem?
                    Or is it suggested to whitelist the IP address 23.227.38.32?

                    Thanks.

                    GertjanG 1 Reply Last reply Reply Quote 0
                    • GertjanG
                      Gertjan @SebM
                      last edited by

                      @sebm I guess none of us has issues with that IP.

                      No "help me" PM's please. Use the forum, the community will thank you.
                      Edit : and where are the logs ??

                      SebMS 1 Reply Last reply Reply Quote 0
                      • SebMS
                        SebM @Gertjan
                        last edited by

                        @gertjan said in shopify sites:

                        @sebm I guess none of us has issues with that IP.

                        None? I would think I’m not the only one who has to allow access to Shopify.

                        GertjanG 1 Reply Last reply Reply Quote 0
                        • GertjanG
                          Gertjan @SebM
                          last edited by

                          @sebm said in shopify sites:

                          Shopify

                          Dono what it is - don't use that site - don't block it.

                          I'm probably not using DNSBL lists/feeds that block cloudfaire IPs and/or domains hosted by ckoudfaire.
                          And if so, whitelisting the domain name should do it.

                          No "help me" PM's please. Use the forum, the community will thank you.
                          Edit : and where are the logs ??

                          1 Reply Last reply Reply Quote 0
                          • BBcan177B
                            BBcan177 Moderator @jpvonhemel
                            last edited by

                            @jpvonhemel said in shopify sites:

                            Add domain to the DNSBL Whitelist, not the TLD Whitelist. Click on the blue infoblock Icons for more details.

                            Also recommend to whitelist from the Reports Tab, but clicking the "+" icon, as that will also check if there are CNAMES associated with the domain.

                            "Experience is something you don't get until just after you need it."

                            Website: http://pfBlockerNG.com
                            Twitter: @BBcan177  #pfBlockerNG
                            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                            1 Reply Last reply Reply Quote 0
                            • M
                              MrFrenchFry
                              last edited by MrFrenchFry

                              I'm having the same issue with IP 23.227.38.32 - My Forum Post

                              This is blocking a lot of common Shopify sites, slamcity.com, rollersnakes.com

                              I can see the blocked IP in the URL Alias PRI1_V4 which is an auto generated list, more details in my post on what I've seen.

                              Issue I have is that the blocked sites are not showing on alerts and whitelisting the Domain Names doesn't work.

                              BBcan177B 1 Reply Last reply Reply Quote 0
                              • BBcan177B
                                BBcan177 Moderator @MrFrenchFry
                                last edited by

                                @mrfrenchfry
                                You can't mix DNSBL and IP Blocking, they are two different animals.

                                Whitelist IPs for blocked IP Events, and Whitelist DNSBL for DNSBL Blocked events.

                                See the Reports Tab for the "+" whitelist Icons.

                                "Experience is something you don't get until just after you need it."

                                Website: http://pfBlockerNG.com
                                Twitter: @BBcan177  #pfBlockerNG
                                Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                                1 Reply Last reply Reply Quote 0
                                • R
                                  Ramosel @jpvonhemel
                                  last edited by Ramosel

                                  @jpvonhemel said in shopify sites:

                                  When I disable pfblockerng, or add the domain to the whitelist, the sites load. I am not at home now, I’ll get back on the other questions, I know I the ip they resolve to is the same, and that is from Shopify.

                                  Yeah, I ran across a similar event when I was trying to get to Maglite.com. I didn't disable pfBlockerNG, I just caught the Shopify by time stamp in the alert tab and did a temporary unlock on it. Maglite.com then worked.

                                  1 Reply Last reply Reply Quote 0
                                  • N
                                    NeasMacha
                                    last edited by

                                    This post is deleted!
                                    N 1 Reply Last reply Reply Quote 0
                                    • N
                                      NeasMacha @NeasMacha
                                      last edited by NeasMacha

                                      This post is deleted!
                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post
                                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.