Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfb_dnsbl.conf too big?

    Scheduled Pinned Locked Moved pfBlockerNG
    8 Posts 3 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mugabemkomo
      last edited by

      I currently have the problem, that my pfb_dnsbl.conf is about 700k lines long ~35MB size.
      As soon as I enable it in the DNS Resolver (server:include: /var/unbound/pfb_dnsbl.conf) it wont resolve any dns entries anymore.
      I tried increasing the cache size and a few other options with no success.
      When I decrease the size of the conf it works, but is there any way around this limit or have I setup something wrong?

      1 Reply Last reply Reply Quote 0
      • RonpfSR
        RonpfS
        last edited by

        How much memory do you have ?

        2.4.5-RELEASE-p1 (amd64)
        Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
        Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

        1 Reply Last reply Reply Quote 0
        • M
          mugabemkomo
          last edited by

          8GB

          1 Reply Last reply Reply Quote 0
          • M
            mugabemkomo
            last edited by

            I just deleted only the last line and now it works?
            DNS Resolver Logs shows no errors either.
            I don't know whats happening, I should go to sleep.

            1 Reply Last reply Reply Quote 0
            • BBcan177B
              BBcan177 Moderator
              last edited by

              You shouldn't need to edit the Unbound Adv. custom line, that is managed by the pkg.

              When DNSBL downloads each feed, it does a validation to ensure there is no bad data in the parsing… So check the pfblockerng.log for any anomalies.. When all the DNSBL feeds are downloaded and parsed, it will create the new pfb_dnsbl.conf file automatically and reload that…. You shouldn't need to make any changes to it.

              This will confirm if Unbound is running:

              unbound-control -c /var/unbound/unbound.conf status
              

              Also check the pfBlockerNG Alerts tab for any blocked domains/IPs that could be causing this issue…

              "Experience is something you don't get until just after you need it."

              Website: http://pfBlockerNG.com
              Twitter: @BBcan177  #pfBlockerNG
              Reddit: https://www.reddit.com/r/pfBlockerNG/new/

              1 Reply Last reply Reply Quote 0
              • M
                mugabemkomo
                last edited by

                It's really odd, I get some DNS outages once in a while, but sometimes only for a few minutes, maybe during cron?
                The only errors I get is:
                unbound 22943:0 error: cannot chdir to directory: (No such file or directory)

                1 Reply Last reply Reply Quote 0
                • BBcan177B
                  BBcan177 Moderator
                  last edited by

                  During a cron update of DNSBL it can temporarily stop DNS requests since its reloading Unbound…. Next release will have a Live Sync feature.. Just working out the bugs with it .... So try to set DNSBL to update once per night so it will minimize the impact.

                  Could you be affected by the following:
                  https://redmine.pfsense.org/issues/7326

                  Hoping to get some resolution to that asap from the DEVS…

                  "Experience is something you don't get until just after you need it."

                  Website: http://pfBlockerNG.com
                  Twitter: @BBcan177  #pfBlockerNG
                  Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                  1 Reply Last reply Reply Quote 0
                  • RonpfSR
                    RonpfS
                    last edited by

                    @mugabemkomo:

                    The only errors I get is:
                    unbound 22943:0 error: cannot chdir to directory: (No such file or directory)

                    This "error" has been present for ages. It doesn't cause any problem as far as I know.

                    2.4.5-RELEASE-p1 (amd64)
                    Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                    Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.