Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Cron update disconnects internet access and VPN?

    Scheduled Pinned Locked Moved pfBlockerNG
    5 Posts 2 Posters 855 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • 8
      8468452315
      last edited by

      Hello,

      I'm running openvpn client on my pfSense and noticed that:

      • everytime pfBlocker runs daily update
      • vpn connection stops working
      • interfaces NOT using vpn also lose access to internet
      • restarting openvpn service fixes all the issues (until the next update)

      Seems like the openvpn service doesn't actually go down but DNS resolving no longer works.
      Any ideas?

      1 Reply Last reply Reply Quote 0
      • BBcan177B
        BBcan177 Moderator
        last edited by

        Check to see if the your VPN IPs are in a Feed and being blocked. Review the Alerts Tab.
        You can also try without the "State Killing" feature. Any IPs removed will also show in the pfblockerng.log

        "Experience is something you don't get until just after you need it."

        Website: http://pfBlockerNG.com
        Twitter: @BBcan177  #pfBlockerNG
        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

        1 Reply Last reply Reply Quote 0
        • 8
          8468452315
          last edited by 8468452315

          @BBcan17

          Thank you for the answer BBcan17. I found VPN IP (xx.xx.xx.0/24) in 2 feeds. One was my own so that's easily removed. Second one is in "/var/db/aliastables/pfB_Europe_v4.txt".

          I guess the best way would be to add that that address to whitelist, correct? With 'Permit Outbound'?

          8 1 Reply Last reply Reply Quote 0
          • 8
            8468452315 @8468452315
            last edited by

            This post is deleted!
            1 Reply Last reply Reply Quote 0
            • BBcan177B
              BBcan177 Moderator
              last edited by

              Yes make a Permit Outbound Alias and add the IPs to the customlist and ensure that this Permit rule is above the other block rules.

              "Experience is something you don't get until just after you need it."

              Website: http://pfBlockerNG.com
              Twitter: @BBcan177  #pfBlockerNG
              Reddit: https://www.reddit.com/r/pfBlockerNG/new/

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.