• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

pfblockerNG - Do not Block on specific specific Interface

Scheduled Pinned Locked Moved pfBlockerNG
7 Posts 3 Posters 3.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    soltesandrew
    last edited by Sep 27, 2018, 3:45 PM

    Hi I've setup pfsense and successfully installed pfblockerng-devel and it's working blocking ads using pi hole list. but I experience some kind of problem, I have 5 VLAN interface and I want some interface to NOT participate in the blocking I want the interface to access everything. how to do this? I saw this option in dnsbl but still all interface is participating in the blocking
    0_1538063104823_65f6e0ae-1e03-47ec-adf7-2c10b85920d2-image.png

    1 Reply Last reply Reply Quote 0
    • B
      BBcan177 Moderator
      last edited by Sep 27, 2018, 3:50 PM

      The permit Firewall rule is not designed to bypass DNSBL... Its only needed to create a firewall rule so that the vlans can access the DNSBL webserver without the browser timing out...

      See the following to configure an Unbound "views" manual option:
      https://forum.netgate.com/topic/129365/bypassing-dnsbl-for-specific-ips

      "Experience is something you don't get until just after you need it."

      Website: http://pfBlockerNG.com
      Twitter: @BBcan177  #pfBlockerNG
      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

      1 Reply Last reply Reply Quote 0
      • S
        soltesandrew
        last edited by Sep 27, 2018, 4:00 PM

        Hi BBcan177,

        Can you please share where to manually configure the unbound rules? so that I can manually bypass dnsbl for the specific IP range. thanks.

        B 1 Reply Last reply Sep 27, 2018, 4:05 PM Reply Quote 0
        • B
          BBcan177 Moderator @soltesandrew
          last edited by Sep 27, 2018, 4:05 PM

          @soltesandrew said in pfblockerNG - Do not Block on specific specific Interface:

          Can you please share where to manually configure the unbound rules? so that I can manually bypass dnsbl for the specific IP range. thanks.

          In pfSense > Services > DNS Resolver > Custom options

          "Experience is something you don't get until just after you need it."

          Website: http://pfBlockerNG.com
          Twitter: @BBcan177  #pfBlockerNG
          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

          R 1 Reply Last reply Oct 29, 2018, 9:31 PM Reply Quote 1
          • S
            soltesandrew
            last edited by Sep 27, 2018, 4:07 PM

            Hi BBcan177,

            Found it, I will try to manually bypass DNSBL. and Thank you so much for your hard work in pfblockerNG :)

            1 Reply Last reply Reply Quote 0
            • R
              rmalla @BBcan177
              last edited by Oct 29, 2018, 9:31 PM

              @bbcan177 Dear BB, first of all, thanks for creating this great package. I've been playing with it for a couple of days but can't seem to find the correct config for me.

              I have a kind of specific situation. I have my WAN (which fails regularly), so I have setup a USB Drive from my local cellphone company (which is very reliable, but I only have 5 GB per month quota). I have them setup as a Failover Wan, meaning, when WAN goes offline the USB goes online automatically.

              The problem I've had the last couple of months is that my WAN goes offline (we don't even notice when its offline) and my family keeps on using the internet as usual (youtube, netflix, facebook etc etc) so the USB drive runs out in a matter of days.

              So I would like to only block all the high bandwith services on the USB Drive (opt1 inteface), so when my wan is offline, everybody is able to use the internet, but not use the high bandwith services.

              Is this possible with the current version of Pfblocker?

              My bottom line is that I would like to apply the PFBlocker to the opt1, but not to the WAN interface.

              R 1 Reply Last reply Nov 2, 2018, 7:41 AM Reply Quote 0
              • R
                rmalla @rmalla
                last edited by Nov 2, 2018, 7:41 AM

                @rmalla said in pfblockerNG - Do not Block on specific specific Interface:

                @bbcan177 Dear BB, first of all, thanks for creating this great package. I've been playing with it for a couple of days but can't seem to find the correct config for me.

                I have a kind of specific situation. I have my WAN (which fails regularly), so I have setup a USB Drive from my local cellphone company (which is very reliable, but I only have 5 GB per month quota). I have them setup as a Failover Wan, meaning, when WAN goes offline the USB goes online automatically.

                The problem I've had the last couple of months is that my WAN goes offline (we don't even notice when its offline) and my family keeps on using the internet as usual (youtube, netflix, facebook etc etc) so the USB drive runs out in a matter of days.

                So I would like to only block all the high bandwith services on the USB Drive (opt1 inteface), so when my wan is offline, everybody is able to use the internet, but not use the high bandwith services.

                Is this possible with the current version of Pfblocker?

                My bottom line is that I would like to apply the PFBlocker to the opt1, but not to the WAN interface.

                Hello All,

                Any news on this?

                1 Reply Last reply Reply Quote 1
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                  This community forum collects and processes your personal information.
                  consent.not_received