Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNSBL not working with vpn

    Scheduled Pinned Locked Moved pfBlockerNG
    15 Posts 2 Posters 2.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • X
      xerno
      last edited by

      I need some help with configuration to make dnsbl work togheter with my vpn.
      DNSBL worked before I added the vpn.

      1 Reply Last reply Reply Quote 0
      • BBcan177B
        BBcan177 Moderator
        last edited by

        Take a look here:
        https://www.reddit.com/r/PFSENSE/comments/8o8zf1/pfblockerng_adblock_on_all_vlans/

        "Experience is something you don't get until just after you need it."

        Website: http://pfBlockerNG.com
        Twitter: @BBcan177  #pfBlockerNG
        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

        X 1 Reply Last reply Reply Quote 0
        • X
          xerno @BBcan177
          last edited by

          @bbcan17 Im a beginner in this and having trouble following you.
          my vpn is using dhcp with the dns from general tab
          103.86.96.100
          103.86.99.100
          If I delete or change these the whole internet stops working.

          BBcan177B 1 Reply Last reply Reply Quote 0
          • BBcan177B
            BBcan177 Moderator @xerno
            last edited by

            @xerno The lan devices have to use pfSense IP address so that Unbound/DNSBL will reply... If you set your LAN devices DNS to use the General Tab DNS IPs, then that will bypass Unbound and DNSBL will not filter it.

            "Experience is something you don't get until just after you need it."

            Website: http://pfBlockerNG.com
            Twitter: @BBcan177  #pfBlockerNG
            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

            X 1 Reply Last reply Reply Quote 0
            • X
              xerno @BBcan177
              last edited by

              @bbcan17 Ok I set my windows machine to use pfsense ip as dns but ads are still showing up

              BBcan177B 1 Reply Last reply Reply Quote 0
              • BBcan177B
                BBcan177 Moderator @xerno
                last edited by

                @xerno DNSBL will only block the AD domains that are in the DNSBL Feeds that you defined.

                See this thread:
                https://forum.netgate.com/topic/91736/pfblockerng-v2-0-w-dnsbl

                "Experience is something you don't get until just after you need it."

                Website: http://pfBlockerNG.com
                Twitter: @BBcan177  #pfBlockerNG
                Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                X 1 Reply Last reply Reply Quote 0
                • X
                  xerno @BBcan177
                  last edited by

                  @bbcan17 Yes I have configured the feeds. It was working until I setup the vpn.

                  BBcan177B 1 Reply Last reply Reply Quote 0
                  • BBcan177B
                    BBcan177 Moderator @xerno
                    last edited by

                    @xerno

                    Ensure that from this LAN Device, that you can:

                    1. ping the DNSBL VIP and get a reply
                    2. Browse to the DNSBL VIP and get the 1x1 pixel
                    3. ping one of the DNSBL domains and get the DNSBL VIP Address

                    "Experience is something you don't get until just after you need it."

                    Website: http://pfBlockerNG.com
                    Twitter: @BBcan177  #pfBlockerNG
                    Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                    X 1 Reply Last reply Reply Quote 0
                    • X
                      xerno @BBcan177
                      last edited by

                      @bbcan17 I can ping dnsbl vip and get a reply.
                      if I browser it I get a timeout
                      if I ping one of the dnsbl domains I dont get the dnsbl vip adress

                      BBcan177B 1 Reply Last reply Reply Quote 0
                      • BBcan177B
                        BBcan177 Moderator @xerno
                        last edited by

                        @xerno In the DNSBL Tab, enable the "DNSBL Permit" rule and select all LAN/VLANS that need access to the DNSBL VIP...

                        "Experience is something you don't get until just after you need it."

                        Website: http://pfBlockerNG.com
                        Twitter: @BBcan177  #pfBlockerNG
                        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                        X 2 Replies Last reply Reply Quote 0
                        • X
                          xerno @BBcan177
                          last edited by

                          @bbcan17 said in DNSBL not working with vpn:

                          AN/VLANS that need access to

                          Those settings are already there

                          1 Reply Last reply Reply Quote 0
                          • X
                            xerno @BBcan177
                            last edited by

                            @bbcan17 I did some digging in the log files.
                            for example this
                            local-data: "adaway.org/hosts.txt 60 IN A 10.10.10.1"
                            when I ping one of the addresses in that site it does not use 10.10.10.1
                            however I do have this local-data: "jujuads.com 60 IN A 10.10.10.1" and that will ping with response 10.10.10.1

                            1 Reply Last reply Reply Quote 0
                            • BBcan177B
                              BBcan177 Moderator
                              last edited by

                              @xerno said in DNSBL not working with vpn:

                              local-data: "adaway.org/hosts.txt 60 IN A 10.10.10.1"

                              Something is wrong with this line as it shouldn't contain the "/hosts.txt".. What URL are you using... Compare that to the URL in the link I posted above.

                              After reviewing the URL, remove the previous feed in the Log Browser > DNSBL Files > Adaway.txt, by selecting the "Delete Icon"... Follow that with a Force Reload - DNSBL.

                              "Experience is something you don't get until just after you need it."

                              Website: http://pfBlockerNG.com
                              Twitter: @BBcan177  #pfBlockerNG
                              Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                              X 2 Replies Last reply Reply Quote 0
                              • X
                                xerno @BBcan177
                                last edited by

                                @bbcan17 I found the problem, in the DNSBL Feeds I didnt put unique headers. they where all named the same. after reloading it now blocks ads.
                                However is the blocking correct? The ads just show up as grey and after about 5-10 seconds they dissapear.

                                1 Reply Last reply Reply Quote 0
                                • X
                                  xerno @BBcan177
                                  last edited by

                                  @bbcan17 I still cant acess 10.10.10.1 in my browser.

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.