Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfBlockerNG v2.1 w/TLD

    Scheduled Pinned Locked Moved pfBlockerNG
    124 Posts 42 Posters 261.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      MoonKnight
      last edited by

      @BBcan177:

      @CiscoX:

      After updating to 2.1.1_2 i can't "clear DNSBL Packets" from the pfBlockerNG widge
      The DNSBL_EasyList won't delete the packets

      I am away for a few weeks but will check that out. Seems like some regression somewhere. Thanks for reporting.

      Hi, No problem. Have a nice Holiday :)

      --- 24.11 ---
      Intel(R) Xeon(R) CPU D-1518 @ 2.20GHz
      Kingston DDR4 2666MHz 16GB ECC
      2 x HyperX Fury SSD 120GB (ZFS-mirror)
      2 x Intel i210 (ports)
      4 x Intel i350 (ports)

      1 Reply Last reply Reply Quote 0
      • QinnQ
        Qinn
        last edited by

        Hi there I followed this guide, http://fredmerc.com/2016/07/15/pfsense-adblock-using-pfblockerng-guide/ a rather short setup, there is only DNSBL and no IP4 is that new or is this guide missing it? Thanks for any help.

        Hardeware: Intel(R) Celeron(R) J4125 CPU @ 2.00GHz 102 GB mSATA SSD (ZFS)
        Firmware: Latest-stable-pfSense CE (amd64)
        Packages: pfBlockerNG devel-beta (beta tester) - Avahi - Notes - Ntopng - PIMD/udpbroadcastrelay - Service Watchdog - System Patches

        1 Reply Last reply Reply Quote 0
        • RonpfSR
          RonpfS
          last edited by

          @Qinn:

          Hi there I followed this guide, http://fredmerc.com/2016/07/15/pfsense-adblock-using-pfblockerng-guide/ a rather short setup, there is only DNSBL and no IP4 is that new or is this guide missing it? Thanks for any help.

          Here are the original pfBlockerNG thread https://forum.pfsense.org/index.php?topic=86212.0
          and the pfBlockerNG v2.0 w/DNSBL thread https://forum.pfsense.org/index.php?topic=102470

          2.4.5-RELEASE-p1 (amd64)
          Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
          Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

          1 Reply Last reply Reply Quote 0
          • H
            Heimire
            last edited by

            I am getting this error when I try to use the Spamhaus list in this tread.

            ===[  DNSBL Process  ]================================================

            [ EasywoElements ] exists.
            [ SpamHouse_TLDS ] Downloading update .. 200 OK
              Remote timestamp missing .
              –--------------------------------------------------------------------
              Orig.    Unique    # Dups    # White    # Alexa    Final               
              ----------------------------------------------------------------------
              3        3          0          0          0          3                   
              ----------------------------------------------------------------------

            [ DNSBL FAIL ] [ Skipping : SpamHouse_TLDS ]

            [1470071701] unbound-checkconf[87654:0] error: error parsing local-data at 38 '(xmlhttp.readystate 60 IN A 10.10.10.1': Syntax error, could not parse the RR
            [1470071701] unbound-checkconf[87654:0] error: Bad local-data RR (xmlhttp.readystate 60 IN A 10.10.10.1
            [1470071701] unbound-checkconf[87654:0] fatal error: failed local-zone, local-data configuration
            [ Malware_1month ] Downloading update [ 08/01/16 12:15:01 ] .. 200 OK
              Remote timestamp missing .
              –--------------------------------------------------------------------
              Orig.    Unique    # Dups    # White    # Alexa    Final               
              ----------------------------------------------------------------------
              1221    956        0          0          0          956                 
              ----------------------------------------------------------------------

            [ Malware_1week ] Downloading update [ 08/01/16 12:15:04 ] .. 200 OK
              Remote timestamp missing .
              –--------------------------------------------------------------------
              Orig.    Unique    # Dups    # White    # Alexa    Final               
              ----------------------------------------------------------------------
              526      487        487        0          0          0                   
              ----------------------------------------------------------------------

            [ Malware_1day ] Downloading update [ 08/01/16 12:15:05 ] .. 200 OK
              Remote timestamp missing .
              –--------------------------------------------------------------------
              Orig.    Unique    # Dups    # White    # Alexa    Final               
              ----------------------------------------------------------------------
              48      47        47        0          0          0                   
              ----------------------------------------------------------------------

            [ Malware_1hour ] Downloading update .. 200 OK
              Remote timestamp missing
            No Domains Found

            –----------------------------------------
            Assembling database... completed
            Executing TLD
            TLD analysis. completed
            Finalizing TLD...  completed

            Original    Matches    Removed    Final

            6062        5530      1          6061

            Validating database... completed [ 08/01/16 12:15:08 ]
            Reloading Unbound…. completed
            DNSBL update [ 6061 | PASSED  ]… completed

            1 Reply Last reply Reply Quote 0
            • RonpfSR
              RonpfS
              last edited by

              Which Spamhaus URL are you using ?
              this https://www.spamhaus.org/statistics/tlds/ is just a web page, not a feed DNSBL can use.

              as for the H3X, only one is needed
              https://forum.pfsense.org/index.php?topic=115357.msg643896#msg643896

              And do a Force Reload after making the modifications.

              2.4.5-RELEASE-p1 (amd64)
              Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
              Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

              1 Reply Last reply Reply Quote 0
              • H
                Heimire
                last edited by

                @RonpfS:

                Which Spamhouse URL are you using ?
                this https://www.spamhaus.org/statistics/tlds/ is just a web page, not a feed DNSBL can use.

                as for the H3X, only one is needed
                https://forum.pfsense.org/index.php?topic=115357.msg643896#msg643896

                And do a Force Reload after making the modifications.

                Thank you.
                i see my mistake now.
                I was certain I had 2 feeds that contained data but I must have misplaced it?

                1 Reply Last reply Reply Quote 0
                • RonpfSR
                  RonpfS
                  last edited by

                  Read the first posts (or more  ;)) of each of these threads:
                  pfBlockerNG
                  pfBlockerNG v2.0 w/DNSBL
                  pfBlockerNG v2.1 w/TLD

                  You will find some posts about IP and DNSBL Feed.

                  2.4.5-RELEASE-p1 (amd64)
                  Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                  Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                  1 Reply Last reply Reply Quote 0
                  • M
                    minority
                    last edited by

                    First of all thank you very much for your hard work and this awesome package!

                    I was just wondering is it possible to somehow change the Rule Order setting to something like:
                    pfB_Pass/Match | pfB_Block/Reject | All other Rules | (original format)
                    so the first IP-list would be the whitelist?

                    Right now I can't seem to figure out how to make custom LAN IPv4 whitelist (Permit_Outbound) rule to be the first in the rule list of the LAN interface. If I manually move it first. Next list update puts it bellow the blocklists (Deny_Outbound) again. Right now only the default setting | pfB_Block/Reject | All other Rules | (Original format) is partly usable for me (whitelist won't work) and all other rule order settings just mess my original LAN rules.

                    I use Traffic Shaper queues in the floating rules so prefer not to move pfBlockerNG's rules in there too.

                    Is this somehow possible or what am I missing, thanks?

                    1 Reply Last reply Reply Quote 0
                    • RonpfSR
                      RonpfS
                      last edited by

                      Which version are you using ?

                      with pfBlockerNG 2.1.1_2 I have these choices.

                      And you can still use the Floating Rules, it won't affect the Traffic Shaper rules.

                      rulepass.jpg
                      rulepass.jpg_thumb

                      2.4.5-RELEASE-p1 (amd64)
                      Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                      Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                      1 Reply Last reply Reply Quote 0
                      • RonpfSR
                        RonpfS
                        last edited by

                        @Heimire:

                        @RonpfS:

                        Which Spamhouse URL are you using ?
                        this https://www.spamhaus.org/statistics/tlds/ is just a web page, not a feed DNSBL can use.

                        as for the H3X, only one is needed
                        https://forum.pfsense.org/index.php?topic=115357.msg643896#msg643896

                        And do a Force Reload after making the modifications.

                        Thank you.
                        i see my mistake now.
                        I was certain I had 2 feeds that contained data but I must have misplaced it?

                        The https://www.spamhaus.org/statistics/tlds/ page can be useful to find TLD to put in the TLD Blacklist.

                        2.4.5-RELEASE-p1 (amd64)
                        Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                        Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                        1 Reply Last reply Reply Quote 0
                        • H
                          hulleyrob
                          last edited by

                          There were error(s) loading the rules: /tmp/rules.debug:37: cannot define table pfB_Europe_v6: Cannot allocate memory - The line in question reads [37]: table <pfB_Europe_v6> persist file "/var/db/aliastables/pfB_Europe_v6.txt" @ 2016-07-31 14:55:00
                          There were error(s) loading the rules: /tmp/rules.debug:37: cannot define table pfB_Europe_v6: Cannot allocate memory - The line in question reads [37]: table <pfB_Europe_v6> persist file "/var/db/aliastables/pfB_Europe_v6.txt" @ 2016-07-31 14:55:11
                          There were error(s) loading the rules: /tmp/rules.debug:37: cannot define table pfB_Europe_v6: Cannot allocate memory - The line in question reads [37]: table <pfB_Europe_v6> persist file "/var/db/aliastables/pfB_Europe_v6.txt" @ 2016-07-31 14:55:20 
                          

                          Check what is selected in this tab, as i had a similar problem and found since the update that the inverse of what i had previously selected had been selected causing over 1.5M IP's for this section and using up all the available memory.

                          Rob

                          1 Reply Last reply Reply Quote 0
                          • RonpfSR
                            RonpfS
                            last edited by

                            PFBlockerNG 2.1.1_2 Memory Errors

                            2.4.5-RELEASE-p1 (amd64)
                            Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                            Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                            1 Reply Last reply Reply Quote 0
                            • C
                              coolspot
                              last edited by

                              When I try to add a new TLD Blacklist i.e. "Google.com", I get the following error:

                              Clearing all DNSBL Feeds…  completed
                              Executing TLD
                              Blocking full TLD/Sub-Domain(s)... |google.com| completed
                              TLD analysis completed
                              Finalizing TLD... head: 1: No such file or directory
                              tail: 1: No such file or directory
                              completed

                              Original    Matches    Removed    Final

                              0          0          -1        1

                              Validating database... completed

                              DNSBL enabled FAIL - restoring Unbound conf
                              /var/unbound/pfb_dnsbl.conf:1: error: unknown keyword '.google.com'
                              /var/unbound/pfb_dnsbl.conf:1: error: unknown keyword '60'
                              read /var/unbound/unbound.tmp failed: 2 errors in configuration file

                              Any ideas why DNSBL is failing to add the TLD blacklist entries?

                              Thanks.

                              1 Reply Last reply Reply Quote 0
                              • RonpfSR
                                RonpfS
                                last edited by

                                Do you have any DNSBL feeds defined and enabled?
                                I did put Google.com in the DNSBL TLD Blacklist, ran a Force Reload and things looks ok.

                                This is the part of pfblockerNG log after the last DNSBL feed

                                [ BBC_C2 ]		 Reload [ 08/08/16 15:25:16 ] . completed ..
                                  ----------------------------------------------------------------------
                                  Orig.    Unique     # Dups     # White    # Alexa    Final                
                                  ----------------------------------------------------------------------
                                  332      332        331        0          0          1                    
                                  ----------------------------------------------------------------------
                                
                                [ DNSBL_IP ]		 Updating aliastable [ 08/08/16 15:25:22 ]... 
                                  no changes.
                                  Total IP count = 280
                                
                                ------------------------------------------
                                Assembling database... completed
                                Executing TLD
                                 Blocking full TLD/Sub-Domain(s)... |google.com| completed
                                TLD analysis...xxxxxxxxxxx completed
                                ** TLD Domain count exceeded. [ 250000 ] All subsequent Domains listed as-is **
                                Finalizing TLD...  completed
                                 ----------------------------------------
                                 Original    Matches    Removed    Final     
                                 ----------------------------------------
                                 1323464     87716      169286     1154178   
                                 -----------------------------------------
                                Validating database... completed [ 08/08/16 15:31:20 ]
                                Reloading Unbound.... completed
                                DNSBL update [ 1154178 | PASSED  ]... completed [ 08/08/16 15:32:02 ]
                                ------------------------------------------
                                
                                ===[  Continent Process  ]============================================
                                

                                2.4.5-RELEASE-p1 (amd64)
                                Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                1 Reply Last reply Reply Quote 0
                                • C
                                  coolspot
                                  last edited by

                                  @RonpfS:

                                  Do you have any DNSBL feeds defined and enabled?
                                  I did put Google.com in the DNSBL TLD Blacklist, ran a Force Reload and things looks ok.

                                  No, I only want to block a couple domains and not use any DNSBL lists.

                                  Must I have a DNSBL list for TLD to work?

                                  1 Reply Last reply Reply Quote 0
                                  • RonpfSR
                                    RonpfS
                                    last edited by

                                    @coolspot:

                                    @RonpfS:

                                    Do you have any DNSBL feeds defined and enabled?
                                    I did put Google.com in the DNSBL TLD Blacklist, ran a Force Reload and things looks ok.

                                    No, I only want to block a couple domains and not use any DNSBL lists.

                                    I solved the issue by create a dummy feed, the inside the feed add the "Custom Block List" this seems to allow the domains to be blocked.

                                    Is this the expected behaviour?

                                    Well maybe nobody tested a setup without any DNSBL feed. Using a Custom Block List does create a feed and seems to remove the issue.

                                    2.4.5-RELEASE-p1 (amd64)
                                    Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                    Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                    1 Reply Last reply Reply Quote 0
                                    • C
                                      coolspot
                                      last edited by

                                      @RonpfS:

                                      Well maybe nobody tested a setup without any DNSBL feed. Using a Custom Block List does create a feed and seems to remove the issue.

                                      BBCan177 got back to me even though he was on vacation (thanks!).

                                      Basically create a dummy DNSBL feed, in the bottom section called Custom Domains, add the subdomains there. This will block the domains correctly.

                                      1 Reply Last reply Reply Quote 0
                                      • R
                                        reg1982
                                        last edited by

                                        Hello BBcan177 and pfsense users,

                                        Great work on pfblockerng. I have one question. I have DNSBL listening port 8081 and when I type 10.10.10.1:8081 I get the gif image. Now when I try the DNSBL SSL listening port 8443 10.10.10.1:8443 I get the connection was reset. So it doesn't work.

                                        I have been doing some reading on why I was getting the "googleads.g.doubleclick.net" and in one post someone talked about limiters causing problem. I don't have any limiters setup. I think it's because DNSBL SSL isn't working.

                                        Anyone have an idea why DNSBL SSL isn't working for me ?

                                        Thanks

                                        1 Reply Last reply Reply Quote 0
                                        • RonpfSR
                                          RonpfS
                                          last edited by

                                          http://10.10.10.1:8443 return a gif

                                          It should be https://10.10.10.1:443 but that doesn't return and doesn't it log to dnsbl.log either.

                                          2.4.5-RELEASE-p1 (amd64)
                                          Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                          Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                          1 Reply Last reply Reply Quote 0
                                          • R
                                            reg1982
                                            last edited by

                                            I tried https://10.10.10.1:443 and it returned a gif so that works. Anyone else have the google ads certificate popup? I get the popup in Safari and in Firefox I see the error message where the ads used to be.

                                            It would be nice to have just empty space without the error.

                                            Thanks Ronpfs for your reply.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.