Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Issues using DNSBL and IP to block domains

    Scheduled Pinned Locked Moved pfBlockerNG
    26 Posts 4 Posters 2.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      Risfold @BBcan177
      last edited by

      @BBcan177 said in Issues using DNSBL and IP to block domains:

      Some more info here:
      https://www.reddit.com/r/pfBlockerNG/comments/d3p1gf/doh_server_blocklist/

      Hi BBcan177 Thanks for the reply. This post is where I got my domain list from. My issue is that I would like to use the DNSBL and block the IP of these addresses. However when the whois lookup occurs during the IP cron, pfblocker only returns the pfblocker VIP because the same list of domains are in the DNSBL.

      Can the whois lookup for an IP blocklist occur ignoring the DNSBL?

      1 Reply Last reply Reply Quote 0
      • R
        Risfold
        last edited by

        I hoped my explanations above were clear enough but in case not I have added the screenshots below. I appreciate the help with this issue!

        Domain list on DNSBL:
        dnsbl.png

        IP block list:
        ipv4 blocklist.png

        List of IPs from block list showing pfblocker VIP only since domains are listed on DNSBL already:
        ip list.png

        1 Reply Last reply Reply Quote 0
        • BBcan177B
          BBcan177 Moderator
          last edited by

          That Heuristics feed is for DNSBL only. Its not an IP list, so it can't be used in the IP tab.
          What is your IP Placeholder IP? Is it 10.10.10.1? That could interfere with DNSBL depending what you selected for the DNSBL VIP address.

          "Experience is something you don't get until just after you need it."

          Website: http://pfBlockerNG.com
          Twitter: @BBcan177  #pfBlockerNG
          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

          1 Reply Last reply Reply Quote 0
          • R
            Risfold
            last edited by

            I have the feed for Heuristics list in whois format so pfblocker should resolve these, no? That is the issue I'm referring to. When pfblocker uses dns resolver to resolve the list of domains for IP blocking, it uses itself (DNSBL) and only resolves the DNSBL IP (10.10.10.1) for each domain.

            abb550d2-515f-4b10-8e60-c5c5d16f8746-image.png

            The IP placeholder and DNSBL IP are default:
            b519d222-1915-4d90-a146-7f70b666b231-image.png

            0e4de4ad-c7ec-4580-84f2-fff5bac4223e-image.png

            BBcan177B 1 Reply Last reply Reply Quote 0
            • BBcan177B
              BBcan177 Moderator @Risfold
              last edited by

              @Risfold
              Dont think that duality is possible.

              "Experience is something you don't get until just after you need it."

              Website: http://pfBlockerNG.com
              Twitter: @BBcan177  #pfBlockerNG
              Reddit: https://www.reddit.com/r/pfBlockerNG/new/

              R 1 Reply Last reply Reply Quote 0
              • R
                Risfold @BBcan177
                last edited by

                @BBcan177
                I see. I was hoping there would be a way that I was just ignorant of. Thank you for taking the time to review this.

                If anyone else has a suggestion beyond manually resolving these domains externally and manually updating the lists, please let us know!

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.