Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNSBL not working, even with Resolver active

    pfBlockerNG
    3
    5
    2.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      themadsalvi
      last edited by

      As stated in the title, the DNSBL service is not blocking any domains at all anymore. The only major change was the upgrade of Pfsense to the new p3 version. It worked fine right up until the upgrade was finished. The DNS resolver is working properly, and unbound service is also working correctly. Pfblocker also correctly blocks IPs correctly, and so far, there are no huge glaring errors in the logs(unless you consider the UT1 not downloading). I will place the log from the forced reload below. I have uninstalled pfblocker(making sure that the settings were not kept), re-installed pfblocker, and still no DNSBL blocks.

      1 Reply Last reply Reply Quote 1
      • T
        themadsalvi
        last edited by

        UPDATE PROCESS START [ 05/24/19 14:22:57 ]

        ===[ DNSBL Process ]================================================

        Loading DNSBL Statistics... completed
        Loading DNSBL Whitelist... completed

        Downloading Blacklist Database(s) [ ut1 (~8.5MB) ] ... Please wait ...
        UT1 ... Failed

        [ New ] Reload [ 05/24/19 14:25:15 ] . completed ..
        Whitelist: 127.demdex.net|zooplus.demdex.net|

        Orig. Unique # Dups # White # TOP1M Final

        1102379 1102379 0 1321 0 1101058

        Saving DNSBL database... completed


        Assembling DNSBL database... completed [ 05/24/19 14:27:57 ]
        Reloading Unbound Resolver..... completed [ 05/24/19 14:28:14 ]
        DNSBL update [ 1647758 | PASSED ]... completed [ 05/24/19 14:28:15 ]

        1 Reply Last reply Reply Quote 0
        • E
          Emal510
          last edited by

          I'm also having this issue. Tried switching to devel build but DNSBL is still not filtering packets.

          1 Reply Last reply Reply Quote 0
          • JeGrJ
            JeGr LAYER 8 Moderator
            last edited by

            @Emal510 said in DNSBL not working, even with Resolver active:

            Tried switching to devel build but DNSBL is still not filtering packets.

            DNSBL will never filter packets. It filters DNS queries against pfSense' internal DNS resolver (unbound). If you don't use that, it will do nothing at all.

            Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

            If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

            E 1 Reply Last reply Reply Quote 0
            • E
              Emal510 @JeGr
              last edited by

              I did some troubleshooting and I honestly don't know exactly what the issue was but here is a list of steps I took to get it working again:

              • General Setup
                • Set loopback address on top followed by DNS IP(s) or leave everything blank if only using Unbound
                • DNS Server Override unchecked
                • Disable DNS Forwarder unchecked
              • DNS Resolver
                • Network Interfaces > only select local ints including LAN.
                • DNS Query Forwarding unchecked
                • DHCP Registration checked
                • Static DHCP checked
              • DHCP Server
                • set your DNS Server to the LAN's IP int
              • On each of your DHCP Clients
                • Renew lease or perform a network reset
              • On each of your Static Clients
                • Use the IP int as DNS address
              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.