Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Limiters and pfBlockerNG DNSBL

    Scheduled Pinned Locked Moved Traffic Shaping
    5 Posts 2 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mir
      last edited by

      Hi all,

      After some extensive fiddling with DNSBL I might have discovered a bug.

      Pfsense: 2.3.2-RELEASE-p1 (amd64)
      pfBlockerNG: 2.1.1_6
      Multiple internal networks.

      On my interface hosting WIFI traffic I have limiters configured to restrict total bandwidth. Works as expected when DNSBL is not activated but when DNSBL is activated traffic is blocked to the DNSBL Virtual IP causing http traffic to hang. Tested in Safari, Google Chrome, and Firefox on IOS, Android, Windows, Linux, and FreeBSD.

      Read more here: https://forum.pfsense.org/index.php?topic=124890.0

      1 Reply Last reply Reply Quote 0
      • D
        doktornotor Banned
        last edited by

        Limiters and NAT do not work except for 2.4 snapshots. DNSBL is using NAT.

        1 Reply Last reply Reply Quote 0
        • M
          mir
          last edited by

          @doktornotor:

          Limiters and NAT do not work except for 2.4 snapshots. DNSBL is using NAT.

          That explains it. Thanks.

          So my options are:

          1. Disable DNSBL until 2.4 is released
          2. Disable limiter on WIFI until 2.4 is released
          3. Install a second WAN for WIFI and disable DNSBL for WIFI but keep DNSBL for the remaining interfaces and route those interfaces through the first WAN.

          Hmf, I will monitor WIFI usage carefully and see if option 2) is a viable solution.

          1 Reply Last reply Reply Quote 0
          • D
            doktornotor Banned
            last edited by

            Ask BBcan177 about beta pfBNG access. He's got a version that does 0.0.0.0 blackhole instead of redirect to the 1x1px webserver.

            1 Reply Last reply Reply Quote 0
            • M
              mir
              last edited by

              I will do that. Thanks again.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.