Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Re: DNSBL Interface

    Scheduled Pinned Locked Moved pfBlockerNG
    7 Posts 3 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • BBcan177B
      BBcan177 Moderator
      last edited by

      @Derelict:

      This originally came up because pfBlocker adds this:

      10.10.10.1/32 LAN  IP Alias pfB DNSBL - DO NOT EDIT

      I do not know why he chose to put that on LAN and not localhost. Probably has a good reason.

      Lighttpd (which serves the 1x1pix) is running on the VIP address as it can't bind to localhost or 0.0.0.0, plus the sinkholed DNS request(s) need to be directed to the DNSBL VIP listening ports.

      "Experience is something you don't get until just after you need it."

      Website: http://pfBlockerNG.com
      Twitter: @BBcan177  #pfBlockerNG
      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

      1 Reply Last reply Reply Quote 0
      • BBcan177B
        BBcan177 Moderator
        last edited by

        @BBcan177:

        @Derelict:

        This originally came up because pfBlocker adds this:

        10.10.10.1/32 LAN  IP Alias pfB DNSBL - DO NOT EDIT

        I do not know why he chose to put that on LAN and not localhost. Probably has a good reason.

        Lighttpd (which serves the 1x1pix) is running on the VIP address as it can't bind to localhost or 0.0.0.0, plus the sinkholed DNS request(s) need to be directed to the DNSBL VIP listening ports.

        @Derelict: Oh, I see what you mean now… Just tested the VIP Interface using "localhost" and it seems to work fine.

        I assume that this would negate any needed "permit" rules for other LAN subnets to access the DNSBL VIP since its on localhost?

        "Experience is something you don't get until just after you need it."

        Website: http://pfBlockerNG.com
        Twitter: @BBcan177  #pfBlockerNG
        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          Seems to me if the traffic is passed from the clients to 10.10.10.1 it will work whether the VIP is on LAN or Localhost.

          Most probably pass the traffic via the default any rule on LAN.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • H
            HeatmiserNYC
            last edited by

            Hey BBCan,
            Ran into some strangeness over the last few days. Why would I only be getting this in my logs? It appears that nothing else is resolving….

            DNSBL.png
            DNSBL.png_thumb

            1 Reply Last reply Reply Quote 0
            • BBcan177B
              BBcan177 Moderator
              last edited by

              @HeatmiserNYC:

              Hey BBCan,
              Ran into some strangeness over the last few days. Why would I only be getting this in my logs? It appears that nothing else is resolving….

              If your referring to the "unknown" msg, then that is normal for HTTPS alerts, the browser fails to load the DNSBL webserver (as expected) and as such only a portion of the alert can be logged. Hover over the key icon.

              "Experience is something you don't get until just after you need it."

              Website: http://pfBlockerNG.com
              Twitter: @BBcan177  #pfBlockerNG
              Reddit: https://www.reddit.com/r/pfBlockerNG/new/

              1 Reply Last reply Reply Quote 0
              • BBcan177B
                BBcan177 Moderator
                last edited by

                @vocal:

                My settings are:

                I'm not sure what the question is?

                "Experience is something you don't get until just after you need it."

                Website: http://pfBlockerNG.com
                Twitter: @BBcan177  #pfBlockerNG
                Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                1 Reply Last reply Reply Quote 0
                • H
                  HeatmiserNYC
                  last edited by

                  @BBcan177:

                  @HeatmiserNYC:

                  Hey BBCan,
                  Ran into some strangeness over the last few days. Why would I only be getting this in my logs? It appears that nothing else is resolving….

                  If your referring to the "unknown" msg, then that is normal for HTTPS alerts, the browser fails to load the DNSBL webserver (as expected) and as such only a portion of the alert can be logged. Hover over the key icon.

                  Did something change in with the logging? I'm fairly certain I never saw those messages on a regular basis. It was always source/destination of visited websites…..

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.