Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlocker not logging after 2.5.2 pfSense upgrade

    Scheduled Pinned Locked Moved pfBlockerNG
    53 Posts 17 Posters 10.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      berthis1958 @bs09
      last edited by

      @bs09 Exactly the same thing happened to me and I tried much the same things as you ... I continue to investigate for a possible solution ...

      1 Reply Last reply Reply Quote 1
      • D
        dpseattle @RonpfS
        last edited by dpseattle

        @ronpfs after letting it run for 12hrs. the widget count is 0 for blocked packets (but confirm ads are being blocked). here is the dnsbl log that only shows a handful from yesterday.

        1e078ff1-9549-4d11-a0d6-ef72397e9016-image.png

        RonpfSR 1 Reply Last reply Reply Quote 0
        • RonpfSR
          RonpfS @dpseattle
          last edited by

          @dpseattle Maybe the .sqlite files have the wrong ownership ?

          ls -al /var/unbound/
          
          total 42831
          drwxr-xr-x   7 unbound  unbound        39 Jul  9 12:26 .
          drwxr-xr-x  27 root     wheel          27 Jun  2  2020 ..
          -rw-r--r--   1 root     unbound       176 Jul  5 04:24 access_lists.conf
          drwxr-xr-x   2 unbound  unbound         2 Jun  2  2020 conf.d
          dr-xr-xr-x   8 root     wheel         512 Jul  5 08:20 dev
          -rw-r--r--   1 root     unbound         0 Jul  5 04:24 dhcpleases_entries.conf
          -rw-r--r--   1 root     unbound      3371 May  1 00:18 dnsbl_cert.pem
          -rw-r--r--   1 root     unbound         0 Jul  5 04:24 domainoverrides.conf
          -rw-r--r--   1 root     unbound      3816 Jul  5 04:24 host_entries.conf
          drwxr-xr-x   4 root     wheel          58 Oct  2  2020 lib
          -rw-r--r--   1 root     unbound      1697 Mar 22 22:01 pfb_dnsbl_lighty.conf
          -rw-r--r--   1 root     unbound         0 Jan  8 11:52 pfb_py_cache.dnsbl
          -rw-r--r--   1 unbound  unbound      8192 Jul  9 12:13 pfb_py_cache.sqlite
          -rw-r--r--   1 root     unbound         7 Jul  9 08:20 pfb_py_count
          -rw-r--r--   1 root     unbound  13071812 Jul  9 08:20 pfb_py_data.txt
          -rw-r--r--   1 unbound  unbound      8192 Jul  9 12:20 pfb_py_dnsbl.sqlite
          -rwxr-xr-x   1 root     wheel     1687428 Jun 28  2020 pfb_py_hsts.txt
          -rw-r--r--   1 root     unbound   1687428 Jun 28  2020 pfb_py_hsts.txt.pkgsave
          -rw-r--r--   1 root     unbound         0 Jan  8 11:52 pfb_py_resolver.dnsbl
          -rw-r--r--   1 unbound  unbound     16384 Jul  9 12:26 pfb_py_resolver.sqlite
          -rw-r--r--   1 root     unbound      3475 Apr 18 01:16 pfb_py_ss.txt
          -rw-r--r--   1 root     unbound      2793 Mar  2  2019 pfb_py_whitelist.json
          -rw-r--r--   1 root     unbound      2750 Mar 22 22:01 pfb_py_whitelist.txt
          -rw-r--r--   1 root     wheel    52420053 Jul  9 08:20 pfb_py_zone.txt
          -rw-r--r--   1 root     unbound       782 Feb 28 20:19 pfb_unbound.ini
          -rwxr-xr-x   1 root     wheel       66726 Apr  7 12:46 pfb_unbound.py
          -rw-r--r--   1 root     unbound     43906 Nov  1  2020 pfb_unbound.py.pkgsave
          -rwxr-xr-x   1 root     wheel        7077 Mar  6 11:44 pfb_unbound_include.inc
          -rw-r--r--   1 root     unbound      5454 Nov  1  2020 pfb_unbound_include.inc.pkgsave
          -rw-r--r--   1 root     unbound       300 Dec  8  2018 remotecontrol.conf
          -rw-r--r--   1 unbound  unbound       758 Jul  9 08:20 root.key
          -rw-r--r--   1 unbound  unbound      2141 Jul  5 04:24 unbound.conf
          -rw-r--r--   1 root     unbound      2140 Mar  4 08:19 unbound.conf.error
          -rw-r-----   1 unbound  unbound      2459 Dec  8  2018 unbound_control.key
          -rw-r-----   1 unbound  unbound      1330 Dec  8  2018 unbound_control.pem
          -rw-r-----   1 unbound  unbound      2459 Dec  8  2018 unbound_server.key
          -rw-r-----   1 unbound  unbound      1318 Dec  8  2018 unbound_server.pem
          drwxr-xr-x   3 root     unbound         3 Mar 22 22:01 usr
          drwxr-xr-x   3 root     unbound         3 Mar 22 22:03 var
          
          
          

          2.4.5-RELEASE-p1 (amd64)
          Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
          Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

          D C 2 Replies Last reply Reply Quote 0
          • D
            dpseattle @RonpfS
            last edited by

            @ronpfs looks like .sqlite are set to unbound:unbound/
            424f68de-48f5-4450-a125-455b8b8ba28b-image.png

            1 Reply Last reply Reply Quote 0
            • C
              cefleet @RonpfS
              last edited by

              @ronpfs Looks like the sqlite files are correct

              ad7d3904-3571-4c4c-b540-e54bbe520f78-image.png

              1 Reply Last reply Reply Quote 0
              • N
                NickD 0
                last edited by

                I'm seeing the same issues with DNSBL. pfSense 2.5.2 upgrade with pfBlocker 3.0.0.16. I just noticed that all blocked HTTP requests are logged fine, however, blocked HTTPS requests are not logged.

                1 Reply Last reply Reply Quote 4
                • C
                  cefleet
                  last edited by

                  Looks like mine is logging only HTTP and not HTTPS as well.

                  N D 2 Replies Last reply Reply Quote 0
                  • N
                    NickD 0 @cefleet
                    last edited by

                    @cefleet looks like unbound was regressed from 1.13.x to 1.12.x in 2.5.2 due to some other issues... likely related? although IDK when 1.13.x was added to the main tree. Maybe a configuration option available in 1.13.x but not in 1.12.x is borking the logging?

                    https://docs.netgate.com/pfsense/en/latest/releases/2-5-2.html#dns-resolver

                    https://redmine.pfsense.org/issues/11915

                    https://redmine.pfsense.org/issues/11316

                    B 1 Reply Last reply Reply Quote 4
                    • B
                      berthis1958 @NickD 0
                      last edited by

                      @nickd-0 said in pfBlocker not logging after 2.5.2 pfSense upgrade:

                      @cefleet looks like unbound was regressed from 1.13.x to 1.12.x in 2.5.2 due to some other issues... likely related? although IDK when 1.13.x was added to the main tree. Maybe a configuration option available in 1.13.x but not in 1.12.x is borking the logging?

                      https://docs.netgate.com/pfsense/en/latest/releases/2-5-2.html#dns-resolver

                      https://redmine.pfsense.org/issues/11915

                      https://redmine.pfsense.org/issues/11316

                      oops .. very interesting. It seems a possible cause.

                      1 Reply Last reply Reply Quote 0
                      • D
                        dotsch @cefleet
                        last edited by

                        @cefleet said in pfBlocker not logging after 2.5.2 pfSense upgrade:

                        Looks like mine is logging only HTTP and not HTTPS as well.

                        I have the same problems. Blocking works afer reload, but don't log anymore.

                        1 Reply Last reply Reply Quote 1
                        • C
                          cefleet
                          last edited by

                          I changed from Unbound mode to Unbound Python mode and that has seemed to have fixed things. I thought I did this the other day and it did not work. In any case, it appears to be working now. Thanks for everyone's input.

                          28b96ba1-10ac-4ad2-b0ff-a80e9f058ce2-image.png

                          keyserK D 2 Replies Last reply Reply Quote 2
                          • keyserK
                            keyser Rebel Alliance @cefleet
                            last edited by

                            @cefleet Please monitor your disk usage as python mode on 21.05/2.5.2 has a an issue on some systems with slowly consuming all diskspace. The key issue is that no files/logfiles report a size / diskusage that accounts for the space usage - they remain sized like before. So you cannot locate the file/problem that fills the filesystem.

                            This leads to a situation where the filesystem is full, and you need to stop/start pfBlockerNG completely or reboot pfSense to regain your filesystem space.

                            Love the no fuss of using the official appliances :-)

                            C 1 Reply Last reply Reply Quote 2
                            • C
                              cefleet @keyser
                              last edited by

                              @keyser Thanks for the heads up. I will keep an eye on the disk usage. So far everything looks good.

                              1 Reply Last reply Reply Quote 1
                              • D
                                dotsch @cefleet
                                last edited by dotsch

                                @cefleet said in pfBlocker not logging after 2.5.2 pfSense upgrade:

                                I changed from Unbound mode to Unbound Python mode and that has seemed to have fixed things. I thought I did this the other day and it did not work. In any case, it appears to be working now. Thanks for everyone's input.

                                Thank you very much for the hint. I can confirm, that it is working for me with Unbound Python and enabling Python in pfBlocker DNBL.

                                N 1 Reply Last reply Reply Quote 1
                                • N
                                  NickD 0 @dotsch
                                  last edited by

                                  @dotsch Same here, no issues with the python module and logging.

                                  1 Reply Last reply Reply Quote 0
                                  • badprocessB
                                    badprocess
                                    last edited by

                                    Ok so i also enabled Python Unbound mode and actually the logs are working again. I'll monitor in the coming days the disk occupation

                                    1 Reply Last reply Reply Quote 0
                                    • S
                                      SillieWous
                                      last edited by SillieWous

                                      Same story for me. Upgraded on the 15th (as clearly visible in the pictures below). Next to not logging of DNSBL there also seems to be a memory leak, unsure if related.

                                      4d48d88e-2214-4fce-9de0-ef30c4ada062-image.png

                                      Is it possible to switch to python unbound with DHCP registration? As it still says "Python DNSBL mode is not compatable with the DNS Resolver DHCP Registration option (Unbound will Crash)!" in the information for selecting python unbound.

                                      1 Reply Last reply Reply Quote 0
                                      • M
                                        maddy_in65
                                        last edited by maddy_in65

                                        I have faced similar issue, DNSBL stopped blocking after 2.5.2 upgrade. I reinstalled pfsense but it didn't work. Later I changed mode to python unbound and it started working. However post this upgrade, my CPU and memory utilization is very high, earlier I had large list of IP and DNSBL but after this upgrade i cant enable all the list. I am running with only few list b of IP and DNSBL but after this upgrade i cant enable all the list. I am running with only few list but memory is still high. ut memory is still high. Is there any solution for this.

                                        d50fe12e-8e8b-4ccd-a92f-d26deb6fbc5e-image.png

                                        GertjanG 1 Reply Last reply Reply Quote 0
                                        • GertjanG
                                          Gertjan @maddy_in65
                                          last edited by

                                          @maddy_in65
                                          What is your CPU doing ?
                                          See here Diagnostics > System Activity
                                          Or better : console or SSH access, option 8 and enter

                                          top
                                          

                                          See here for more info.

                                          No "help me" PM's please. Use the forum, the community will thank you.
                                          Edit : and where are the logs ??

                                          M 1 Reply Last reply Reply Quote 0
                                          • M
                                            maddy_in65 @Gertjan
                                            last edited by

                                            @gertjan
                                            Here is "Top" output:

                                             processes:  4 running, 56 sleeping
                                            CPU: 91.3% user,  0.0% nice,  8.7% system,  0.0% interrupt,  0.0% idle
                                            Mem: 958M Active, 337M Inact, 750M Wired, 208K Buf, 1698M Free
                                            ARC: 278M Total, 161M MFU, 105M MRU, 2654K Anon, 2044K Header, 8178K Other
                                                 160M Compressed, 585M Uncompressed, 3.66:1 Ratio
                                            Swap: 2048M Total, 2048M Free
                                            
                                              PID USERNAME    THR PRI NICE   SIZE    RES STATE    C   TIME    WCPU COMMAND
                                            62378 root         88  20    0   468M   423M nanslp   0   0:37 132.04% ntopng
                                            38952 unbound       1  77    0    91M    79M RUN      1   0:03  32.27% unbound
                                              347 root          1  52    0   102M    39M piperd   0   1:06  25.19% php-fpm
                                            43559 root          1  20    0    13M  3508K CPU1     1   0:00   0.59% top
                                            62111 root          4  20    0    22M  5356K kqread   1   0:00   0.29% redis-server
                                             9748 root          1  20    0    19M  6824K select   1   0:03   0.12% ntpd
                                            36481 root          1  20    0    20M  9220K select   0   0:00   0.10% sshd
                                            85972 root          5  52    0    11M  2592K uwait    0   0:00   0.06% dpinger
                                            47972 dhcpd         1  25    0    23M    12M select   1   0:00   0.02% dhcpd
                                            47822 root          1  20    0    18M  7552K kqread   0   0:00   0.01% lighttpd_pfb
                                             5149 root          3  20    0    18M  7168K select   1   0:06   0.01% pcscd
                                            85427 root          5  52    0    11M  2592K uwait    1   0:00   0.01% dpinger
                                              346 root          1  52    0   102M    39M accept   0   2:03   0.00% php-fpm
                                            48256 root          1  52    0   102M    39M accept   1   1:06   0.00% php-fpm
                                            44666 root          1  52    0   102M    39M accept   1   0:51   0.00% php-fpm
                                            62020 root          1  23    0   102M    38M accept   0   0:35   0.00% php-fpm
                                            19548 root          1  20    0    11M  2648K select   0   0:07   0.00% syslogd
                                            95969 root          2  20    0   229M   191M bpf      0   0:02   0.00% snort
                                            19460 root          1  20    0   104M    36M nanslp   0   0:01   0.00% php-cgi
                                             8574 root          1  20    0    30M  9792K kqread   0   0:01   0.00% nginx
                                            49739 root          1  20    0    61M    39M piperd   0   0:00   0.00% php_pfb
                                              345 root          1  20    0   102M    27M kqread   0   0:00   0.00% php-fpm
                                            31190 root          1  20    0    12M  2956K bpf      1   0:00   0.00% filterlog
                                             8290 root          1  20    0    29M  9248K kqread   1   0:00   0.00% nginx
                                             9162 root          1  45    0    11M  2484K nanslp   1   0:00   0.00% cron
                                            24662 root          1  20    0    21M  8448K select   0   0:00   0.00% mpd5
                                              376 root          1  40   20    11M  2840K kqread   0   0:00   0.00% check_reload_status
                                            49643 root          1  20    0    11M  2212K kqread   0   0:00   0.00% tail_pfb
                                            54837 root          1  20    0    44M    35M bpf      0   0:00   0.00% arpwatch
                                            56501 root          1  20    0    44M    35M bpf      0   0:00   0.00% arpwatch
                                            [2.5.2-RELEASE][admin@
                                            
                                            
                                            GertjanG 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.