• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Update lists fail

Scheduled Pinned Locked Moved pfBlockerNG
34 Posts 5 Posters 4.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K
    Kai_null
    last edited by May 10, 2018, 5:52 AM

    Is the date time correct on the pfsense box?

    1 Reply Last reply Reply Quote 0
    • Q
      Qinn
      last edited by May 10, 2018, 9:24 AM

      @Kai_null:

      Is the date time correct on the pfsense box?

      Yup, the dashboard pfS reads "Current date/time Thu May 10 11:23:16 CEST 2018"

      btw what is your MaxMind from, here it reads in the dashboard "MaxMind: Last-Modified: Mon, 06 Nov 2017 19:15:47 GMT"

      Hardeware: Intel(R) Celeron(R) J4125 CPU @ 2.00GHz 102 GB mSATA SSD (ZFS)
      Firmware: Latest-stable-pfSense CE (amd64)
      Packages: pfBlockerNG devel-beta (beta tester) - Avahi - Notes - Ntopng - PIMD/udpbroadcastrelay - Service Watchdog - System Patches

      1 Reply Last reply Reply Quote 0
      • K
        Kai_null
        last edited by May 10, 2018, 3:17 PM May 10, 2018, 3:05 PM

        MaxMind: Last-Modified: Tue, 03 Apr 2018 22:41:00 GMT

        I am out of good ideas to help you :(.

        I did see this which I thought was interesting:
        https://serverfault.com/questions/681835/freebsd-pfsense-root-ca-fails

        Suggests to me your problem is not with pfblockerng but rather with openssl.  Perhaps it is unable to update its cert store?

        other ideas which may or may not help you:

        https://www.google.com/search?q=pfblockerng+%22unable+to+get+local+issuer+certificate%22&oq=pfblockerng+%22unable+to+get+local+issuer+certificate%22

        https://www.google.com/search?q=pfsense+%22unable+to+get+local+issuer+certificate%22&oq=pfsense+%22unable+to+get+local+issuer+certificate%22

        https://www.google.com/search?q=freebsd+%22unable+to+get+local+issuer+certificate%22&oq=pfsense+%22unable+to+get+local+issuer+certificate%22

        https://www.google.com/search?q=openssl+%22unable+to+get+local+issuer+certificate%22&oq=pfsense+%22unable+to+get+local+issuer+certificate%22

        wish I had answers for you.

        Curious to know what you eventually find.

        ps: I have found that a 2 am reinstall in some cases is a quicker bug fix then diving down the rabbit hole.  I guess it depends on how stock your config is.

        1 Reply Last reply Reply Quote 0
        • B
          BBcan177 Moderator
          last edited by May 11, 2018, 2:46 AM May 11, 2018, 2:23 AM

          @Qinn

          All of those feeds are hosted on Github and/or Amazon, so I would assume that a DNSBL Feed or an IP Blocklist is blocking access on download…  Check the pfBlockerNG Alerts Tab...

          Might need to whitelist:

          raw.githubusercontent.com
          s3.amazonaws.com
          

          or wildcard whitelist the whole domain

          .githubusercontent.com
          .amazonaws.com
          

          For the MaxMind issue, from the pfSense box, check to see if you can access the MaxMind site:

          host -t A geolite.maxmind.com
          geolite.maxmind.com has address 104.16.37.47
          geolite.maxmind.com has address 104.16.38.47
          
          

          Then try to ping the resulting IPs and get a reply.

          The MaxMind download errors are reported to the error.log file…

          Once you have fixed connectivity, you can manually download the MaxMind database with this command:

          php -f /usr/local/www/pfblockerng/pfblockerng.php dc
          

          "Experience is something you don't get until just after you need it."

          Website: http://pfBlockerNG.com
          Twitter: @BBcan177  #pfBlockerNG
          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

          1 Reply Last reply Reply Quote 0
          • Q
            Qinn
            last edited by May 12, 2018, 7:34 AM

            @Kai_null:

            MaxMind: Last-Modified: Tue, 03 Apr 2018 22:41:00 GMT

            I am out of good ideas to help you :(.

            I did see this which I thought was interesting:
            https://serverfault.com/questions/681835/freebsd-pfsense-root-ca-fails

            Suggests to me your problem is not with pfblockerng but rather with openssl.  Perhaps it is unable to update its cert store?

            other ideas which may or may not help you:

            https://www.google.com/search?q=pfblockerng+%22unable+to+get+local+issuer+certificate%22&oq=pfblockerng+%22unable+to+get+local+issuer+certificate%22

            https://www.google.com/search?q=pfsense+%22unable+to+get+local+issuer+certificate%22&oq=pfsense+%22unable+to+get+local+issuer+certificate%22

            https://www.google.com/search?q=freebsd+%22unable+to+get+local+issuer+certificate%22&oq=pfsense+%22unable+to+get+local+issuer+certificate%22

            https://www.google.com/search?q=openssl+%22unable+to+get+local+issuer+certificate%22&oq=pfsense+%22unable+to+get+local+issuer+certificate%22

            wish I had answers for you.

            Curious to know what you eventually find.

            ps: I have found that a 2 am reinstall in some cases is a quicker bug fix then diving down the rabbit hole.  I guess it depends on how stock your config is.

            Thanks for your time and thoughts.

            cheers Qinn

            Hardeware: Intel(R) Celeron(R) J4125 CPU @ 2.00GHz 102 GB mSATA SSD (ZFS)
            Firmware: Latest-stable-pfSense CE (amd64)
            Packages: pfBlockerNG devel-beta (beta tester) - Avahi - Notes - Ntopng - PIMD/udpbroadcastrelay - Service Watchdog - System Patches

            1 Reply Last reply Reply Quote 0
            • Q
              Qinn
              last edited by May 12, 2018, 7:34 AM

              @BBcan177:

              @Qinn

              All of those feeds are hosted on Github and/or Amazon, so I would assume that a DNSBL Feed or an IP Blocklist is blocking access on download…  Check the pfBlockerNG Alerts Tab...

              Might need to whitelist:

              raw.githubusercontent.com
              s3.amazonaws.com
              

              or wildcard whitelist the whole domain

              .githubusercontent.com
              .amazonaws.com
              

              For the MaxMind issue, from the pfSense box, check to see if you can access the MaxMind site:

              host -t A geolite.maxmind.com
              geolite.maxmind.com has address 104.16.37.47
              geolite.maxmind.com has address 104.16.38.47
              
              

              Then try to ping the resulting IPs and get a reply.

              The MaxMind download errors are reported to the error.log file…

              Once you have fixed connectivity, you can manually download the MaxMind database with this command:

              php -f /usr/local/www/pfblockerng/pfblockerng.php dc
              

              Thanks, I will try and report back.

              Cheers Qinn

              Hardeware: Intel(R) Celeron(R) J4125 CPU @ 2.00GHz 102 GB mSATA SSD (ZFS)
              Firmware: Latest-stable-pfSense CE (amd64)
              Packages: pfBlockerNG devel-beta (beta tester) - Avahi - Notes - Ntopng - PIMD/udpbroadcastrelay - Service Watchdog - System Patches

              1 Reply Last reply Reply Quote 0
              • Q
                Qinn
                last edited by May 12, 2018, 8:02 AM May 12, 2018, 7:55 AM

                a```
                host -t A geolite.maxmind.com

                returns```
                geolite.maxmind.com has address 10.10.10.1
                

                If I disable DNSBL I get

                host -t A geolite.maxmind.com
                geolite.maxmind.com has address 104.16.38.47
                geolite.maxmind.com has address 104.16.37.47
                
                

                I added .geolite.maxmind.com to the Custom Domain Whitelist in DNSBL, but nothing changes, still I get the ip of the VIP, instead op 104.16.etc.

                Hardeware: Intel(R) Celeron(R) J4125 CPU @ 2.00GHz 102 GB mSATA SSD (ZFS)
                Firmware: Latest-stable-pfSense CE (amd64)
                Packages: pfBlockerNG devel-beta (beta tester) - Avahi - Notes - Ntopng - PIMD/udpbroadcastrelay - Service Watchdog - System Patches

                1 Reply Last reply Reply Quote 0
                • B
                  BBcan177 Moderator
                  last edited by May 12, 2018, 2:13 PM

                  @Qinn:

                  a```
                  host -t A geolite.maxmind.com

                  returns```
                  geolite.maxmind.com has address 10.10.10.1
                  

                  If I disable DNSBL I get

                  host -t A geolite.maxmind.com
                  geolite.maxmind.com has address 104.16.38.47
                  geolite.maxmind.com has address 104.16.37.47
                  
                  

                  I added .geolite.maxmind.com to the Custom Domain Whitelist in DNSBL, but nothing changes, still I get the ip of the VIP, instead op 104.16.etc.

                  When you manually add a domain or an IP to a whitelist, you need to run a Reload to get it to apply the change or wait until the next cron run to execute… Alternatively, when you whitelist from the Alerts Tab, the whitelist/suppression will take effect immediately.

                  "Experience is something you don't get until just after you need it."

                  Website: http://pfBlockerNG.com
                  Twitter: @BBcan177  #pfBlockerNG
                  Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                  1 Reply Last reply Reply Quote 0
                  • Q
                    Qinn
                    last edited by May 12, 2018, 2:32 PM

                    Thanks yeah I was pulling my hair ;)  After I added it to the whitelist, I did a "Select 'Reload' option" All and hit run got a "exists" in return. Then I realized it and a reload solved it.

                    Now

                    host -t A geolite.maxmind.com
                    geolite.maxmind.com has address 104.16.37.47
                    geolite.maxmind.com has address 104.16.38.47
                    
                    

                    Now I works, btw I can do a manual update of MaxMind, but when will pfblockerNG do it automatically?

                    Thanks BBCan177 I hope everything it going well with the next major release, thumbs up!!

                    Hardeware: Intel(R) Celeron(R) J4125 CPU @ 2.00GHz 102 GB mSATA SSD (ZFS)
                    Firmware: Latest-stable-pfSense CE (amd64)
                    Packages: pfBlockerNG devel-beta (beta tester) - Avahi - Notes - Ntopng - PIMD/udpbroadcastrelay - Service Watchdog - System Patches

                    1 Reply Last reply Reply Quote 0
                    • B
                      BBcan177 Moderator
                      last edited by May 12, 2018, 2:39 PM

                      @Qinn:

                      Thanks yeah I was pulling my hair ;)  After I added it to the whitelist, I did a "Select 'Reload' option" All and hit run got a "exists" in return. Then I realized it and a reload solved it.

                      Now

                      host -t A geolite.maxmind.com
                      geolite.maxmind.com has address 104.16.37.47
                      geolite.maxmind.com has address 104.16.38.47
                      
                      

                      Now I works, btw I can do a manual update of MaxMind, but when will pfblockerNG do it automatically?

                      Thanks BBCan177 I hope everything it going well with the next major release, thumbs up!!

                      MaxMind is updated once per month. You will see the cron task in pfSense for that…

                      Thanks! Its been submitted and awaiting review by the devs...

                      "Experience is something you don't get until just after you need it."

                      Website: http://pfBlockerNG.com
                      Twitter: @BBcan177  #pfBlockerNG
                      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                      1 Reply Last reply Reply Quote 0
                      • Q
                        Qinn
                        last edited by May 12, 2018, 2:55 PM

                        Thanks, did a manual update and worked like a charm.

                         php -f /usr/local/www/pfblockerng/pfblockerng.php dc
                        Country code update Start
                         Converting MaxMind Country databases for pfBlockerNG.
                         Processing ISO IPv4 Continent/Country Data
                         Processing ISO IPv6 Continent/Country Data [ 05/12/18 16:45:27 ]
                         Creating pfBlockerNG Continent XML files
                         IPv4 Africa                     [ 05/12/18 16:45:48 ]
                         IPv6 Africa                     [ 05/12/18 16:45:49 ]
                         IPv4 Antarctica                 [ 05/12/18 16:45:50 ]
                         IPv6 Antarctica
                         IPv4 Asia
                         IPv6 Asia                       [ 05/12/18 16:45:59 ]
                         IPv4 Europe                     [ 05/12/18 16:46:01 ]
                         IPv6 Europe                     [ 05/12/18 16:46:30 ]
                         IPv4 North America              [ 05/12/18 16:46:40 ]
                         IPv6 North America              [ 05/12/18 16:47:01 ]
                         IPv4 Oceania                    [ 05/12/18 16:47:04 ]
                         IPv6 Oceania                    [ 05/12/18 16:47:06 ]
                         IPv4 South America
                         IPv6 South America              [ 05/12/18 16:47:08 ]
                         IPv4 Proxy and Satellite        [ 05/12/18 16:47:10 ]
                         IPv6 Proxy and Satellite
                         IPv4 TOP 20
                         IPv6 TOP 20
                         pfBlockerNG Reputation Tab
                        Country Code Update Ended [ 05/12/18 16:47:11 ]
                        
                        [2.4.3-RELEASE][root@pfSense.localdomain]/root:
                        
                        

                        Just to be sure I added the MaxMind IP's to my IPV4 whitelist also.

                        Hardeware: Intel(R) Celeron(R) J4125 CPU @ 2.00GHz 102 GB mSATA SSD (ZFS)
                        Firmware: Latest-stable-pfSense CE (amd64)
                        Packages: pfBlockerNG devel-beta (beta tester) - Avahi - Notes - Ntopng - PIMD/udpbroadcastrelay - Service Watchdog - System Patches

                        1 Reply Last reply Reply Quote 0
                        • Q
                          Qinn
                          last edited by May 20, 2018, 4:11 PM

                          @BBcan177:

                          MaxMind is updated once per month. You will see the cron task in pfSense for that…

                          I did a```
                          crontab -l

                          
                          Cheers Qinn

                          Hardeware: Intel(R) Celeron(R) J4125 CPU @ 2.00GHz 102 GB mSATA SSD (ZFS)
                          Firmware: Latest-stable-pfSense CE (amd64)
                          Packages: pfBlockerNG devel-beta (beta tester) - Avahi - Notes - Ntopng - PIMD/udpbroadcastrelay - Service Watchdog - System Patches

                          1 Reply Last reply Reply Quote 0
                          • RonpfSR
                            RonpfS
                            last edited by May 20, 2018, 4:26 PM

                            Did you leave MaxMind Updates unticked ?

                            There is a Cron package you can install  ;)

                            The job run from 4th to 10th of the month

                            /usr/local/bin/php /usr/local/www/pfblockerng/pfblockerng.php dcc >> /var/log/pfblockerng/extras.log 2>&1
                            

                            2.4.5-RELEASE-p1 (amd64)
                            Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                            Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                            1 Reply Last reply Reply Quote 0
                            • Q
                              Qinn
                              last edited by May 21, 2018, 1:31 PM

                              @RonpfS:

                              Did you leave MaxMind Updates unticked ?

                              There is a Cron package you can install  ;)

                              The job run from 4th to 10th of the month

                              /usr/local/bin/php /usr/local/www/pfblockerng/pfblockerng.php dcc >> /var/log/pfblockerng/extras.log 2>&1
                              

                              Thanks for you reply RonpfS. Nope I haven't disabled it, I just thought a```
                              crontab -l

                              Hardeware: Intel(R) Celeron(R) J4125 CPU @ 2.00GHz 102 GB mSATA SSD (ZFS)
                              Firmware: Latest-stable-pfSense CE (amd64)
                              Packages: pfBlockerNG devel-beta (beta tester) - Avahi - Notes - Ntopng - PIMD/udpbroadcastrelay - Service Watchdog - System Patches

                              1 Reply Last reply Reply Quote 1
                              • RonpfSR
                                RonpfS
                                last edited by May 21, 2018, 5:14 PM

                                On my system I get :

                                crontab -l
                                
                                crontab: no crontab for root
                                ```  :o

                                2.4.5-RELEASE-p1 (amd64)
                                Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                1 Reply Last reply Reply Quote 0
                                • Q
                                  Qinn
                                  last edited by May 22, 2018, 3:13 PM

                                  So what does the MaxMind updates trigger?

                                  Hardeware: Intel(R) Celeron(R) J4125 CPU @ 2.00GHz 102 GB mSATA SSD (ZFS)
                                  Firmware: Latest-stable-pfSense CE (amd64)
                                  Packages: pfBlockerNG devel-beta (beta tester) - Avahi - Notes - Ntopng - PIMD/udpbroadcastrelay - Service Watchdog - System Patches

                                  Q 1 Reply Last reply Jun 5, 2018, 12:41 PM Reply Quote 1
                                  • Q
                                    Qinn @Qinn
                                    last edited by Jun 5, 2018, 12:41 PM

                                    @qinn Is there a way to check when the next update of MaxMind will run?

                                    Hardeware: Intel(R) Celeron(R) J4125 CPU @ 2.00GHz 102 GB mSATA SSD (ZFS)
                                    Firmware: Latest-stable-pfSense CE (amd64)
                                    Packages: pfBlockerNG devel-beta (beta tester) - Avahi - Notes - Ntopng - PIMD/udpbroadcastrelay - Service Watchdog - System Patches

                                    RonpfSR 1 Reply Last reply Jun 5, 2018, 4:09 PM Reply Quote 1
                                    • RonpfSR
                                      RonpfS @Qinn
                                      last edited by Jun 5, 2018, 4:09 PM

                                      @qinn You can check /var/log/pfblockerng/extras.log to see when the last update was done.

                                      2.4.5-RELEASE-p1 (amd64)
                                      Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                      Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                      1 Reply Last reply Reply Quote 1
                                      • Q
                                        Qinn
                                        last edited by Jun 5, 2018, 4:31 PM

                                        Thanks, nice overview btw of the last 2 years, seems I have to wait for 11 juni (when updating comes once a month)

                                        Hardeware: Intel(R) Celeron(R) J4125 CPU @ 2.00GHz 102 GB mSATA SSD (ZFS)
                                        Firmware: Latest-stable-pfSense CE (amd64)
                                        Packages: pfBlockerNG devel-beta (beta tester) - Avahi - Notes - Ntopng - PIMD/udpbroadcastrelay - Service Watchdog - System Patches

                                        1 Reply Last reply Reply Quote 0
                                        • Q
                                          Qinn
                                          last edited by Qinn Jun 22, 2018, 3:43 PM Jun 22, 2018, 3:40 PM

                                          Hmm it's been well over a month and as from what it looks in the dashboard MaxMind isn't updated, I looked in

                                          cat /var/log/pfblockerng/extras.log 
                                          

                                          and it reads:

                                          Download Process Starting [ 06/05/18 07:00:00 ]
                                           /usr/local/share/GeoIP/GeoIP.dat.gz            200 OK
                                           /usr/local/share/GeoIP/GeoIPv6.dat.gz          200 OK
                                           /usr/local/share/GeoIP/GeoLite2-Country-CSV.zip                200 OK
                                           /var/db/pfblockerng/top-1m.csv.zip             200 OK
                                          Download Process Ended [ 06/05/18 07:00:28 ]
                                          
                                          Country code update Start
                                           Converting MaxMind Country databases for pfBlockerNG.
                                           Processing ISO IPv4 Continent/Country Data
                                           Processing ISO IPv6 Continent/Country Data [ 06/05/18 07:01:46 ]
                                           Creating pfBlockerNG Continent XML files
                                           IPv4 Africa                     [ 06/05/18 07:02:07 ]
                                           IPv6 Africa                     [ 06/05/18 07:02:08 ]
                                           IPv4 Antarctica
                                           IPv6 Antarctica
                                           IPv4 Asia
                                           IPv6 Asia                       [ 06/05/18 07:02:17 ]
                                           IPv4 Europe                     [ 06/05/18 07:02:19 ]
                                           IPv6 Europe                     [ 06/05/18 07:02:48 ]
                                           IPv4 North America              [ 06/05/18 07:02:58 ]
                                           IPv6 North America              [ 06/05/18 07:03:19 ]
                                           IPv4 Oceania                    [ 06/05/18 07:03:22 ]
                                           IPv6 Oceania                    [ 06/05/18 07:03:24 ]
                                           IPv4 South America
                                           IPv6 South America              [ 06/05/18 07:03:26 ]
                                           IPv4 Proxy and Satellite        [ 06/05/18 07:03:28 ]
                                           IPv6 Proxy and Satellite
                                           IPv4 TOP 20
                                           IPv6 TOP 20
                                           pfBlockerNG Reputation Tab
                                          Country Code Update Ended [ 06/05/18 07:03:29 ]
                                          
                                          

                                          So it confirms that the last one, was the one I did manually, what goes wrong, why doesn't it update automatically once a month?

                                          Thnx for any advise

                                          Cheers Qinn

                                          Hardeware: Intel(R) Celeron(R) J4125 CPU @ 2.00GHz 102 GB mSATA SSD (ZFS)
                                          Firmware: Latest-stable-pfSense CE (amd64)
                                          Packages: pfBlockerNG devel-beta (beta tester) - Avahi - Notes - Ntopng - PIMD/udpbroadcastrelay - Service Watchdog - System Patches

                                          RonpfSR 1 Reply Last reply Jun 22, 2018, 5:19 PM Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received