Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    https

    Scheduled Pinned Locked Moved pfBlockerNG
    4 Posts 3 Posters 513 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I
      ik2189
      last edited by

      Hi,

      Sorry for my English.
      I installed pfBockerNG-devel 3.0.0_16 and it blocks all porn sites It's good !
      When the site is in http I see the pfBlockerNG page but when the site is in https I see an error page with code erreur : SSL_ERROR_INTERNAL_ERROR_ALERT.
      Why ?

      Thanks for your help

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @ik2189
        last edited by

        @ik2189 said in https:

        Why ?

        The short answer : because no one** can break https = TLS.
        If a web server want to connect to some 'p0rn-site-here.tld' and a web server, the one used by pfBlockerNG answers (because the DNS record matches a list) then the web browser tells you that that pfB web server, on your pfSense, does not have 'p0rn-site-here.tld' in it's certificate.
        Which is understandable.
        So, your web browser does not show the 'this site is blocked' page at all.

        You might think : because 99,99 % of all traffic is https these days, is it useful to have this page 'this site is blocked' page being shown ?
        Answer : of course not. It's something of the past. We see our browser telling us that 'there was an (cert !) issue'.

        This is a TLS issue, not a pfBlockerNG issue ;)

        ** and the day some one breaks it, is the day that 'Internet' dies.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        I 1 Reply Last reply Reply Quote 1
        • I
          ik2189 @Gertjan
          last edited by

          @gertjan

          So if i understand it's not possible to display a web page displaying that the site is not allowed ?

          fireodoF 1 Reply Last reply Reply Quote 0
          • fireodoF
            fireodo @ik2189
            last edited by

            @ik2189 said in https:

            So if i understand it's not possible to display a web page displaying that the site is not allowed ?

            Thats correct. Gertjan has explained you the reason why thats so.

            Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
            SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
            pfsense 2.7.2 CE
            Packages: Apcupsd Cron Iftop Iperf LCDproc Nmap pfBlockerNG RRD_Summary Shellcmd Snort Speedtest System_Patches.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.