DNSBL Not Blocking Ads or Yahoo



  • Can't seem to get DNSBL working properly; configs attached. Pulled the updated ad list that isn't working nor is my yahoo.com custom list working. Please review and let me know what I'm doing wrong.
    ![Screen Shot 2017-12-27 at 6.15.08 PM.png](/public/imported_attachments/1/Screen Shot 2017-12-27 at 6.15.08 PM.png)
    ![Screen Shot 2017-12-27 at 6.15.08 PM.png_thumb](/public/imported_attachments/1/Screen Shot 2017-12-27 at 6.15.08 PM.png_thumb)
    ![Screen Shot 2017-12-27 at 6.15.21 PM.png](/public/imported_attachments/1/Screen Shot 2017-12-27 at 6.15.21 PM.png)
    ![Screen Shot 2017-12-27 at 6.15.21 PM.png_thumb](/public/imported_attachments/1/Screen Shot 2017-12-27 at 6.15.21 PM.png_thumb)
    ![Screen Shot 2017-12-27 at 6.17.57 PM.png](/public/imported_attachments/1/Screen Shot 2017-12-27 at 6.17.57 PM.png)
    ![Screen Shot 2017-12-27 at 6.17.57 PM.png_thumb](/public/imported_attachments/1/Screen Shot 2017-12-27 at 6.17.57 PM.png_thumb)
    ![Screen Shot 2017-12-27 at 6.18.13 PM.png](/public/imported_attachments/1/Screen Shot 2017-12-27 at 6.18.13 PM.png)
    ![Screen Shot 2017-12-27 at 6.18.13 PM.png_thumb](/public/imported_attachments/1/Screen Shot 2017-12-27 at 6.18.13 PM.png_thumb)
    ![Screen Shot 2017-12-27 at 6.18.44 PM.png](/public/imported_attachments/1/Screen Shot 2017-12-27 at 6.18.44 PM.png)
    ![Screen Shot 2017-12-27 at 6.18.44 PM.png_thumb](/public/imported_attachments/1/Screen Shot 2017-12-27 at 6.18.44 PM.png_thumb)


  • Moderator

    Settings look ok… Are you sure that your LAN devices have their DNS settings configured to use pfSense DNS Only?  If you have other DNS Servers configured then it will bypass DNSBL.

    From pfSense you can confirm that a domain is blocked via:

    host -t A example.com
    

    And on Windows use a```
    nslookup example.com

    
    If the Domain is filtered via DNSBL, it will reply with the DNSBL VIP Address that you configured.


  • Thanks for the config verification, but still no go. Should my host DNS be set to the 10.10.10.1 address? I have them pulling the DNS from pfsense DHCP. Still no luck…



  • Your host has to use pfsense+DNSBL DNS Resolver service.
    From a PC I get

    C:\Users\User1>nslookup steepto.com
    Server :   pfsense.local
    Address:  172.xx.xxx.254
    
    Nom :    steepto.com
    Address:  10.10.10.1
    


  • That was it!! Thank you ;D


Log in to reply