Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    PfBlockerNG v2.1.1_7

    Scheduled Pinned Locked Moved pfBlockerNG
    6 Posts 3 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • BBcan177B Offline
      BBcan177 Moderator
      last edited by

      pfBlockerNG v2.1.1_7 has been posted for review by the devs.

      https://github.com/pfsense/FreeBSD-ports/pull/331

      Changelog:

      • Some feeds are now using the HTTP Status code '304 not-modified'. The download function now reports this as a successful download.

      • DNSBL uses the Lighttpd conditional error_log to collect HTTPS alert details. A previous Lighttpd update changed the syntax of the log which stopped HTTPS logging. The code has been patched to address the change in log format syntax.

      • Typically when IPv4 feeds are downloaded, it uses string functions to parse the lines, however, a regex parser is used when the line is not in a standard format. The previous regex could incorrectly parse certain IPs:

        1.2.3.4/8fdhy[.]net/index.php

        Previous regex = 1.2.3.4/8
              New regex      = 1.2.3.4

      • Log Browser tab - check if file exists before attempting to view it.

      • Threat Source Lookups:

        Changed some feeds from http to https.
        Removed C-SIRT "Incidents-on-demand" as its doesn't seem to be online.
        Added new lookups to:  Shodan.io, urlscan.io, viewdns.info, VirusTotal (for DNSBL) and OTX Alienvault.

      "Experience is something you don't get until just after you need it."

      Website: http://pfBlockerNG.com
      Twitter: @BBcan177  #pfBlockerNG
      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

      1 Reply Last reply Reply Quote 0
      • G Offline
        garyd9
        last edited by

        BBcan177, I didn't see it in the list of changes…  does this update include the fix for IPv6 block lists being configured as IPv4?

        1 Reply Last reply Reply Quote 0
        • BBcan177B Offline
          BBcan177 Moderator
          last edited by

          @garyd9:

          BBcan177, I didn't see it in the list of changes…  does this update include the fix for IPv6 block lists being configured as IPv4?

          This PR doesn't have the IPv6 fix. That fix will be in the next release… Still working on some loose ends...

          "Experience is something you don't get until just after you need it."

          Website: http://pfBlockerNG.com
          Twitter: @BBcan177  #pfBlockerNG
          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

          1 Reply Last reply Reply Quote 0
          • BBcan177B Offline
            BBcan177 Moderator
            last edited by

            @BBcan177:

            pfBlockerNG v2.1.1_7 has been posted for review by the devs.

            https://github.com/pfsense/FreeBSD-ports/pull/331

            Changelog:

            • Some feeds are now using the HTTP Status code '304 not-modified'. The download function now reports this as a successful download.

            • DNSBL uses the Lighttpd conditional error_log to collect HTTPS alert details. A previous Lighttpd update changed the syntax of the log which stopped HTTPS logging. The code has been patched to address the change in log format syntax.

            • Typically when IPv4 feeds are downloaded, it uses string functions to parse the lines, however, a regex parser is used when the line is not in a standard format. The previous regex could incorrectly parse certain IPs:

              1.2.3.4/8fdhy[.]net/index.php

              Previous regex = 1.2.3.4/8
                    New regex      = 1.2.3.4

            • Log Browser tab - check if file exists before attempting to view it.

            • Threat Source Lookups:

              Changed some feeds from http to https.
              Removed C-SIRT "Incidents-on-demand" as its doesn't seem to be online.
              Added new lookups to:  Shodan.io, urlscan.io, viewdns.info, VirusTotal (for DNSBL) and OTX Alienvault.

            This has now been merged and is available for download.

            "Experience is something you don't get until just after you need it."

            Website: http://pfBlockerNG.com
            Twitter: @BBcan177  #pfBlockerNG
            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

            1 Reply Last reply Reply Quote 0
            • W Offline
              Wolf666
              last edited by

              I don't see it available on 2.4 repository.

              ISP FTTH PPPoE 1000/300 Mbps
              pfSense 25.11.1 CPU i5-11320H @ 3.20GHz - 16GB RAM - NVMe 256GB -
              Switch Zyxel XGS1210-12
              AP Netgear RAX200 (Stock FW)
              NAS Synology DS1621+

              1 Reply Last reply Reply Quote 0
              • BBcan177B Offline
                BBcan177 Moderator
                last edited by

                @Wolf666:

                I don't see it available on 2.4 repository.

                Thanks, I sent the devs a message!

                "Experience is something you don't get until just after you need it."

                Website: http://pfBlockerNG.com
                Twitter: @BBcan177  #pfBlockerNG
                Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                Privacy Policy · Cookie Policy