• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

oisd blocklist not working

Scheduled Pinned Locked Moved pfBlockerNG
7 Posts 3 Posters 1.7k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • R
    revengineer
    last edited by revengineer Apr 1, 2020, 9:59 PM Apr 1, 2020, 9:58 PM

    Hi,
    I am trying to use the oisd blck list found here. pfBlockerNG seems to process this fine, but unbound will not start afterward. Can anyone advise why this is? I cannot post the full log, as it is too long. Below is the final snippet.

    Thank you.

    ===[ FINAL Processing ]=====================================

    [ Original IP count ] [ 51967 ]

    ===[ Deny List IP Counts ]===========================

    49753 total
    18492 /var/db/pfblockerng/deny/pfB_Top_v4.txt
    16387 /var/db/pfblockerng/deny/FireHOL3_IPs.txt
    6052 /var/db/pfblockerng/deny/pfB_Top_v6.txt
    5789 /var/db/pfblockerng/deny/BD_IPs.txt
    2245 /var/db/pfblockerng/deny/ET_Block_IPs.txt
    788 /var/db/pfblockerng/deny/ET_Comp_IPs.txt

    ===[ DNSBL Domain/IP Counts ] ===================================

    431133 total
    371953 /var/db/pfblockerng/dnsbl/oisd.txt
    24262 /var/db/pfblockerng/dnsbl/MDS.txt
    16794 /var/db/pfblockerng/dnsbl/EasyList.txt
    6097 /var/db/pfblockerng/dnsbl/Cameleon.txt
    5381 /var/db/pfblockerng/dnsbl/PhishTank.txt
    3265 /var/db/pfblockerng/dnsbl/Adaway.txt
    1752 /var/db/pfblockerng/dnsbl/yoyo.txt
    751 /var/db/pfblockerng/dnsbl/MDL.txt
    713 /var/db/pfblockerng/dnsbl/OpenPhish.txt
    92 /var/db/pfblockerng/dnsbl/PhishTank.ip
    49 /var/db/pfblockerng/dnsbl/EasyList.ip
    16 /var/db/pfblockerng/dnsbl/OpenPhish.ip
    8 /var/db/pfblockerng/dnsbl/DNSBL_TLD.txt

    ====================[ Last Updated List Summary ]==============

    Mar 31 00:30 ET_Block_IPs
    Mar 31 00:30 ET_Comp_IPs
    Apr 1 07:04 FireHOL3_IPs
    Apr 1 16:31 BD_IPs
    Apr 1 17:49 pfB_Top_v4
    Apr 1 17:49 pfB_Top_v6

    IPv4 alias tables IP count

    43858

    IPv6 alias tables IP count

    6052

    Alias table IP Counts

    49910 total
    18492 /var/db/aliastables/pfB_Top_v4.txt
    16387 /var/db/aliastables/pfB_FireHOL3.txt
    6052 /var/db/aliastables/pfB_Top_v6.txt
    5789 /var/db/aliastables/pfB_BinaryDefense.txt
    3033 /var/db/aliastables/pfB_EmergingThreatsDShield.txt
    157 /var/db/aliastables/pfB_DNSBLIP.txt

    pfSense Table Stats

    table-entries hard limit 2000000
    Table Usage Count 161305

    UPDATE PROCESS ENDED [ 04/01/20 17:49:17 ]

    B 1 Reply Last reply Apr 2, 2020, 1:52 AM Reply Quote 0
    • R
      RonpfS
      last edited by Apr 1, 2020, 10:33 PM

      Check the pfblockerng.log, system log, resolver log, memory usage, maybe you hit the limit your system can handle going from 60000 DNSBL entries to 430000.

      2.4.5-RELEASE-p1 (amd64)
      Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
      Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

      1 Reply Last reply Reply Quote 0
      • R
        revengineer
        last edited by Apr 2, 2020, 12:24 AM

        @RonpfS Thank you for the pointer. The problem seems to be that the oisd black list contains one domain for which I also have a local host override. The dual override seems to result in the failed loading of unbound. I would like to keep the local override because I have no control of future changes to the blacklist. Is there a workaround?

        1 Reply Last reply Reply Quote 0
        • R
          RonpfS
          last edited by RonpfS Apr 2, 2020, 12:54 AM Apr 2, 2020, 12:52 AM

          Put that domain in the DNSBL Whitelist, you might also have to put it (or it's parent domain) in the TLD Exclude list to get better control over whitelisting.

          2.4.5-RELEASE-p1 (amd64)
          Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
          Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

          1 Reply Last reply Reply Quote 0
          • R
            revengineer
            last edited by revengineer Apr 2, 2020, 1:14 AM Apr 2, 2020, 1:14 AM

            @RonpfS Perfect, that worked! Adding the domain with subdomains (leading ".") was sufficient to fix the problem. It took me a while to figure it out because I did a "Force Update" which was insufficient. Once I did the "Force Reload" I was good to go. Thanks for the help!

            1 Reply Last reply Reply Quote 0
            • R
              RonpfS
              last edited by Apr 2, 2020, 1:30 AM

              Yeah sometimes you save time by clicking on the 😉

              2.4.5-RELEASE-p1 (amd64)
              Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
              Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

              1 Reply Last reply Reply Quote 0
              • B
                BBcan177 Moderator @revengineer
                last edited by Apr 2, 2020, 1:52 AM

                @revengineer
                The is a log snippet above that to show the processing of that feed and the restart of Unbound. Take a look at those two sections of the pfblockerng.log.

                "Experience is something you don't get until just after you need it."

                Website: http://pfBlockerNG.com
                Twitter: @BBcan177  #pfBlockerNG
                Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                1 Reply Last reply Reply Quote 0
                1 out of 7
                • First post
                  1/7
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                  This community forum collects and processes your personal information.
                  consent.not_received