<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Peculiar pfblockerng &#x2F; tld blocklist &amp; whitelist behavior]]></title><description><![CDATA[<p dir="auto">I have been running pfsense for a while and am quite happy with the setup. I am testing TLD blacklist/whitelist and running into a setup issue.</p>
<p dir="auto">Summary of post = TLD blacklist: io &amp;&amp; TLD whitelist: mkdocs.github.io does not work. WAI?</p>
<p dir="auto">pfsense: 2.4.5-RELEASE, pfblockerng: pfBlockerNG-devel 2.2.5_30<br />
DSNBL: enable<br />
TLD: enable<br />
All IP and DSNBL lists disabled<br />
TLD blacklist: io<br />
TLD whitelist: tried both github.io and mkdocs.github.io</p>
<p dir="auto">Expected result: I thought mkdocs.github.io/mkdocs/ would work for one of the whitelist combinations. It does not.</p>
<p dir="auto">Workaround = If I add github.io to the blocklist with io it works.<br />
Workaround 2 = I could add pi-hole which supports regex based exclude and include patterns.</p>
<ul>
<li>Question 1 - is this working as intended? Note, github.io and mkdocs.github.io resolve to the same addresses</li>
<li>Question 2 - is there a way to block an entire domain while permitting a wildcarded subdomain like *.github.io and <em>.</em>.github.io. Is there a different way that doesn't require force reload for every whitelist change.</li>
</ul>
<p dir="auto">Thank you for your help.</p>
]]></description><link>https://forum.netgate.com/topic/153087/peculiar-pfblockerng-tld-blocklist-whitelist-behavior</link><generator>RSS for Node</generator><lastBuildDate>Fri, 10 Apr 2026 23:44:06 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/153087.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 30 Apr 2020 01:41:14 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Peculiar pfblockerng &#x2F; tld blocklist &amp; whitelist behavior on Sun, 10 May 2020 20:14:28 GMT]]></title><description><![CDATA[<p dir="auto">In the end I disabled tld blocking since it led to many issues allowing certain sites with their own subdomains. I am maintaining a blocklist of individual sites. This is more effort but more reliable for use.</p>
]]></description><link>https://forum.netgate.com/post/911233</link><guid isPermaLink="true">https://forum.netgate.com/post/911233</guid><dc:creator><![CDATA[im_not_a_robot]]></dc:creator><pubDate>Sun, 10 May 2020 20:14:28 GMT</pubDate></item><item><title><![CDATA[Reply to Peculiar pfblockerng &#x2F; tld blocklist &amp; whitelist behavior on Sat, 02 May 2020 15:09:45 GMT]]></title><description><![CDATA[<p dir="auto">Another example for the *.io domain. I can't find any combination of rules that enables access to <strong>ix.cnn.io</strong>. Even with the workaround attempt adding cnn.io to the blacklist I get a DNSBL_TLD entry in the alerts.</p>
<p dir="auto">Does this issue sound familiar to others?</p>
]]></description><link>https://forum.netgate.com/post/909558</link><guid isPermaLink="true">https://forum.netgate.com/post/909558</guid><dc:creator><![CDATA[im_not_a_robot]]></dc:creator><pubDate>Sat, 02 May 2020 15:09:45 GMT</pubDate></item></channel></rss>