Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to schedule PfBlockerNG?

    Scheduled Pinned Locked Moved General pfSense Questions
    18 Posts 4 Posters 1.7k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • GertjanG Offline
      Gertjan @mucip
      last edited by

      PfBlockerNG can't help you out here.
      It's a tool that blocks list with IP's and/or hostnames from which you do not want to 'request' anything. Now now, and not tomorrow.

      It's has no ambition to act like a "parental control" tool, like "Twitter in the afternoon, but not during the evening and night".

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      mucipM 1 Reply Last reply Reply Quote 0
      • mucipM Offline
        mucip @Gertjan
        last edited by mucip

        @gertjan ,
        If we can change the config file and restart the server via cron script, why not?. :)
        I think I must go deeper in the PfBlockerNG mechanism.

        Regards,
        Mucip:)

        NogBadTheBadN 1 Reply Last reply Reply Quote 0
        • NogBadTheBadN Offline
          NogBadTheBad @mucip
          last edited by

          @mucip What exactly are you blocking via DNSBL ?

          Andy

          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

          mucipM 1 Reply Last reply Reply Quote 0
          • mucipM Offline
            mucip @NogBadTheBad
            last edited by

            Hi @nogbadthebad ,
            Some social sites.

            Regards,
            Mucip:)

            NogBadTheBadN 1 Reply Last reply Reply Quote 0
            • NogBadTheBadN Offline
              NogBadTheBad @mucip
              last edited by

              @mucip Can you block them via pfBlockerNG -> IP -> IPv4 and create an alias using the ASN number.

              You could if its Facebook.

              You then could have a time based firewall rule.

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              mucipM 1 Reply Last reply Reply Quote 0
              • mucipM Offline
                mucip @NogBadTheBad
                last edited by mucip

                Dear @nogbadthebad ,
                Could you explain little bit more please?
                Because in my PfBlocker GUI there is only "pfBlockerNG -> IPv4 " menu. And I could not understand what is ASN?...

                P.S. By the way I do this limitations with SquidFilter before but I could not find this package in the PfSense anymore?

                Regards,
                Mucip:)

                NogBadTheBadN 1 Reply Last reply Reply Quote 0
                • NogBadTheBadN Offline
                  NogBadTheBad @mucip
                  last edited by

                  @mucip

                  https://en.wikipedia.org/wiki/Autonomous_system_(Internet)

                  Screenshot 2021-07-01 at 12.54.17.png

                  You could then use pfB_FACEBOOK_v4 in a firewall rule and set a schedule, you'd need to remove Facebook from your DNSBL config.

                  Andy

                  1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                  mucipM 1 Reply Last reply Reply Quote 0
                  • mucipM Offline
                    mucip @NogBadTheBad
                    last edited by

                    Hi @nogbadthebad ,
                    What is your version of the PfBlockerNG?
                    Looks different than mine.

                    Regards,
                    Mucip:)

                    NogBadTheBadN 1 Reply Last reply Reply Quote 0
                    • NogBadTheBadN Offline
                      NogBadTheBad @mucip
                      last edited by

                      @mucip pfBlockerNG-devel

                      Andy

                      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                      NogBadTheBadN 1 Reply Last reply Reply Quote 0
                      • NogBadTheBadN Offline
                        NogBadTheBad @NogBadTheBad
                        last edited by NogBadTheBad

                        You'd then need to create two rules, one that passes traffic to the alias with the time schedule and one that denies without a schedule.

                        I only use a schedule to throttle traffic out my GUEST interface monday - friday 9AM to 5PM to the internet.

                        Screenshot 2021-07-01 at 13.08.45.png

                        Andy

                        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                        mucipM 1 Reply Last reply Reply Quote 0
                        • mucipM Offline
                          mucip @NogBadTheBad
                          last edited by

                          Hi @nogbadthebad ,
                          Thanks a lot.
                          Well I need to upgrade to DEVEL than.
                          By the way where can I find the complete ASN list. How do you know that Facebook ASN is 92934 e.g.?

                          Regards,
                          Mucip:)

                          NogBadTheBadN 1 Reply Last reply Reply Quote 0
                          • NogBadTheBadN Offline
                            NogBadTheBad @mucip
                            last edited by

                            @mucip You can type in Facebook in the IPv4 Source Definitions part.

                            Andy

                            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                            mucipM 1 Reply Last reply Reply Quote 0
                            • mucipM Offline
                              mucip @NogBadTheBad
                              last edited by

                              Dear @nogbadthebad ,
                              Asolutelly I have to upgrade to DEVEL than. :)

                              Regards,
                              Mucip:)

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.