Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfBlockerng Dlevel

    Scheduled Pinned Locked Moved pfBlockerNG
    12 Posts 6 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      abidkhanhk
      last edited by

      Finally got it working after i installed the older version on top on the new version then uninstalled the old and installed new version again... I know very confusing.

      Anyway I have a Chinese Brand Android TV which is very fond of showing me a ton of ads for every single click it receives... Is there anyway to somehow block those ads and how,
      Just need brief guidance and I'll Google it to completion!

      Thanks 😊

      1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad
        last edited by

        Enable DNSBL:-

        Screenshot 2019-10-24 at 13.37.37.png

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        A 1 Reply Last reply Reply Quote 0
        • A
          abidkhanhk @NogBadTheBad
          last edited by

          @NogBadTheBad
          Yep that's already done, it's just that the DNSBL is not picking up those specific ads.
          So maybe there's a specific URL that needs to be blacklisted ,
          I was wondering if there's someway to monitor the TV ips traffic and then watch the URLs that it accesses a d then Black list those accordingly?
          Thanks

          1 Reply Last reply Reply Quote 0
          • NogBadTheBadN
            NogBadTheBad
            last edited by NogBadTheBad

            @abidkhanhk said in PfBlockerng Dlevel:

            was wondering if there's someway to monitor the TV ips traffic and then watch t

            You maybe could use GEOIP to block China via an alias if all the ads are coming from China:-

            Screenshot 2019-10-24 at 13.57.10.png

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            A 2 Replies Last reply Reply Quote 0
            • A
              abidkhanhk @NogBadTheBad
              last edited by

              @NogBadTheBad
              Thanks
              Let me give that a try
              Cheers

              1 Reply Last reply Reply Quote 0
              • A
                abidkhanhk @NogBadTheBad
                last edited by

                @NogBadTheBad
                Hi, did the GeoIP block and it seems chinese IPs are not being blocked, apart from this i noticed that the logs mentioned something like

                [ DNSBL_Malicious - ISC_SDL ] Download Fail [ 10/23/19 23:43:44 ]
                Firewall and/or IDS (Legacy mode only) are not blocking download.
                . unknown http status code | 0

                [ DNSBL_Malicious - Spam404 ] Download Fail [ 10/27/19 00:03:59 ]
                [ raw.githubusercontent.com ] Domain listed in DNSBL

                these 2 lists fail every time, i have set them to update every day 12 hours interval.

                1 Reply Last reply Reply Quote 0
                • NogBadTheBadN
                  NogBadTheBad
                  last edited by NogBadTheBad

                  Looks like they are back working, sometimes the feed maintainer does something that causes the feeds to fail.

                  Easiest thing to do is see if you can download them manually.

                  Go into the Malicious collection and then copy the URL and paste it into another web browser tab.

                  https://raw.githubusercontent.com/Dawsey21/Lists/master/main-blacklist.txt

                  https://isc.sans.edu/feeds/suspiciousdomains_High.txt

                  Andy

                  1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                  A 1 Reply Last reply Reply Quote 0
                  • A
                    abidkhanhk @NogBadTheBad
                    last edited by

                    @NogBadTheBad Thanks, I will try that today.
                    Cheers

                    1 Reply Last reply Reply Quote 0
                    • D
                      durianbusuk
                      last edited by durianbusuk

                      Try these blocklists for Chinese ad servers:

                      https://raw.githubusercontent.com/vokins/yhosts/master/hosts.txt
                      http://tools.yiclear.com/ChinaList2.0.txt

                      alternately go to filterlists.com and search for some Chinese blocklists.

                      Chinese ad servers are named very differently compared to others so you need specific blocklists.

                      or, if you're after one size fits most solution, use: https://dbl.oisd.nl/

                      personal experience has very no false positives on the sites I visit, lots of false positives in Chinese blogging sites but it'll work well in your use case.

                      Wanna take it a step further? add those lists above and turn on TLD. For some strange reason, this speeds up pfblocker too (for me anyway), HP T620 plus with 16GB ram.

                      C 1 Reply Last reply Reply Quote 0
                      • C
                        chrisgtl @durianbusuk
                        last edited by

                        @durianbusuk

                        How do I add https://dbl.oisd.nl/ ?

                        After I add it and update my lists it doesn't appear on the log.

                        1 Reply Last reply Reply Quote 0
                        • GertjanG
                          Gertjan
                          last edited by Gertjan

                          Be careful with this list.
                          It contains 870 thousand domain names. It's huge.

                          That will put a load on any router, even when it's driven a "the latest and greatest AMD/Intel" CPU.
                          8 or even 16 Gbytes of memory becomes a bare minimum.
                          If you use DNSBL => TLD, see minimum memory constraints .
                          The resolver, unbound, has to maintaine a huge internal DNS cache ..... and every DNS request will get compared with this list.
                          Do NOT try to download this list every 10 minutes or so ....

                          Btw : it might be advisable not to visit chinese sites, or visit sites that link back to these sites, and: you won't be needing this list.

                          No "help me" PM's please. Use the forum, the community will thank you.
                          Edit : and where are the logs ??

                          1 Reply Last reply Reply Quote 0
                          • RicoR
                            Rico LAYER 8 Rebel Alliance
                            last edited by

                            Here is the OISD light version: https://dbl.oisd.nl/light/

                            -Rico

                            1 Reply Last reply Reply Quote 1
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.