<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[DNSBL (DEV) Stopped working after 2.4.4 upgrade]]></title><description><![CDATA[<p dir="auto">Hello!<br />
Just did an update to our HA to 2.4.4 (from 2.4.3) running PFblokerNG_dev<br />
After the update, PFblocker IP list seem to be working, but no DNS filtering is being done.<br />
Resolver Seems to be working as I can see requested being made to the DNS forwarder external IP’s.  (Forwarder is using TLS to the external DNS IP’s if that helps, but had this set prior to the upgrade)<br />
There are no DNS alerts in the firewall (either) and testing a DNS entry in one of the list will load in the browser.<br />
PFBlocker was uninstalled and reinstalled on both systems. Services look fine<br />
Thanks in advance!</p>
]]></description><link>https://forum.netgate.com/topic/136185/dnsbl-dev-stopped-working-after-2-4-4-upgrade</link><generator>RSS for Node</generator><lastBuildDate>Mon, 20 Apr 2026 15:39:37 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/136185.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 30 Sep 2018 17:49:48 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to DNSBL (DEV) Stopped working after 2.4.4 upgrade on Mon, 01 Oct 2018 10:29:11 GMT]]></title><description><![CDATA[<p dir="auto">I was able to get DNS resolver errors above corrected with this post<br />
https://forum.netgate.com/topic/106011/solved-pfblockerng-reloading-unbound-fails/11</p>
<p dir="auto">After the above, resting Resolver settings (just clearing all setting then adding back the same settings) and a reboot it appears to be working again.</p>
<p dir="auto">Thanks for the help!</p>
]]></description><link>https://forum.netgate.com/post/793485</link><guid isPermaLink="true">https://forum.netgate.com/post/793485</guid><dc:creator><![CDATA[vito]]></dc:creator><pubDate>Mon, 01 Oct 2018 10:29:11 GMT</pubDate></item><item><title><![CDATA[Reply to DNSBL (DEV) Stopped working after 2.4.4 upgrade on Sun, 30 Sep 2018 19:06:44 GMT]]></title><description><![CDATA[<p dir="auto">The dnsbl.log seems to be empty<br />
(log file  empty or does not exist)<br />
dnsbl parsed _error log is current</p>
]]></description><link>https://forum.netgate.com/post/793349</link><guid isPermaLink="true">https://forum.netgate.com/post/793349</guid><dc:creator><![CDATA[vito]]></dc:creator><pubDate>Sun, 30 Sep 2018 19:06:44 GMT</pubDate></item><item><title><![CDATA[Reply to DNSBL (DEV) Stopped working after 2.4.4 upgrade on Sun, 30 Sep 2018 19:02:54 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/bbcan177">@<bdi>bbcan177</bdi></a></p>
<p dir="auto">Thanks for the reply<br />
A reload is downloading list, no errors besides some list downloads (had them before)<br />
Devices are pointing to PF. No other device / network changes made other than 2.4.4 update.</p>
<p dir="auto">Yeah, testing was on a test machine...noted ;)</p>
<p dir="auto">In resolver logs at this time</p>
<p dir="auto">Sep 30 14:46:45	unbound	55165:0	notice: failed connection from 127.0.0.1 port 26470<br />
Sep 30 14:46:45	unbound	55165:0	error: remote control failed ssl crypto error:14094412:SSL routines:ssl3_read_bytes:sslv3 alert bad certificate<br />
Sep 30 14:46:50	unbound	55165:0	error: remote control connection closed prematurely</p>
<p dir="auto">The cert error: for testing i removed any TLS settings and still get this<br />
Local host error may be new from what i can see</p>
<p dir="auto">Thanks!!</p>
]]></description><link>https://forum.netgate.com/post/793347</link><guid isPermaLink="true">https://forum.netgate.com/post/793347</guid><dc:creator><![CDATA[vito]]></dc:creator><pubDate>Sun, 30 Sep 2018 19:02:54 GMT</pubDate></item><item><title><![CDATA[Reply to DNSBL (DEV) Stopped working after 2.4.4 upgrade on Sun, 30 Sep 2018 18:27:19 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/vito">@<bdi>vito</bdi></a></p>
<p dir="auto">If you run a <code>Force Reload - All</code>, do you get any errors?</p>
<p dir="auto">Check the pfSense system/resolver logs for any other clues.</p>
<p dir="auto">Also make sure that your Lan devices are pointing their DNS settings to pfSense only.</p>
<p dir="auto">It's not a good idea to load these domains in a browser, just in case you load a malicious one. Best to run a ping or host command. If it replies back with the DNSBL VIP, then it's being blocked.</p>
<pre><code>host - t A example.com
</code></pre>
]]></description><link>https://forum.netgate.com/post/793341</link><guid isPermaLink="true">https://forum.netgate.com/post/793341</guid><dc:creator><![CDATA[BBcan177]]></dc:creator><pubDate>Sun, 30 Sep 2018 18:27:19 GMT</pubDate></item></channel></rss>