Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfblockerng using feeds

    Scheduled Pinned Locked Moved pfBlockerNG
    16 Posts 5 Posters 2.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      freefall
      last edited by

      Hello hope someone can help me figure this out.

      Ok I enable a feed an try to figure out how to remove auto rules which didn't bring all to much luck, an I don't see how to disable a feed.. so maybe the dev team could maybe place a button to do this?.. anyways I try to add another feed but some reason it won't take not sure why unless I broke it try to disable this other feed.. now I got this red check mark

      Thanks

      IMG_20201122_095735267~2.jpg

      1 Reply Last reply Reply Quote 0
      • provelsP
        provels
        last edited by

        If you hover over the checkmark, it will tell you which where it is used. Then remove it from the IP or DNSBL group.
        deba6f4e-402e-42ee-9d3f-afbe72235bd5-image.png

        Peder

        MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
        BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

        1 Reply Last reply Reply Quote 0
        • F
          freefall
          last edited by freefall

          i have check the ip, dnsbl groups and Firewall Aliases IP.. only places i find anything of it after i enable it is in the images, other wise when i delete the entry then all it say is where ip3 should be and it disable..

          find 1.png

          find 2.png

          1 Reply Last reply Reply Quote 0
          • RonpfSR
            RonpfS
            last edited by RonpfS

            Malware Domain List is part of DNSBL Group. DNSBL Groups don't create Firewall Rules, they operate on the DNS Server database.

            2.4.5-RELEASE-p1 (amd64)
            Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
            Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

            F 1 Reply Last reply Reply Quote 0
            • F
              freefall @RonpfS
              last edited by

              @RonpfS so how do I remove it or shut it off seen it link goes to a blank file on there site and hasn't block anything?

              Screenshot_20201122-180201.png

              1 Reply Last reply Reply Quote 0
              • RonpfSR
                RonpfS
                last edited by

                That shows that no DNSBL group has been enabled. Maybe you already deleted it .

                2.4.5-RELEASE-p1 (amd64)
                Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                F 1 Reply Last reply Reply Quote 0
                • F
                  freefall @RonpfS
                  last edited by

                  @RonpfS nope it say it to be active...

                  Screenshot_20201122-184107.png

                  Screenshot_20201122-184345.png

                  1 Reply Last reply Reply Quote 0
                  • RonpfSR
                    RonpfS
                    last edited by RonpfS

                    Ok let's forget about the DNSBL thing. Your first pics wasn't detailed enough.

                    If you want to remove an URL for PRI3, go to Firewall / pfBlockerNG/ IP / IPv4, open the PRI3, turn the State to OFF, Save IPV4 Settings, go to Update tab and do a Force Reload IP.

                    If you want to disable the PRI3 group, change the Action to Disabled, Save IPV4 Settings, go to Update tab and do a Force Reload IP.

                    2.4.5-RELEASE-p1 (amd64)
                    Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                    Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                    F 1 Reply Last reply Reply Quote 0
                    • F
                      freefall @RonpfS
                      last edited by

                      @RonpfS

                      I would if I could. An I'd make the picture more detail if I could but there a 200k picture limit..

                      Screenshot_20201122-190712.png

                      1 Reply Last reply Reply Quote 0
                      • RonpfSR
                        RonpfS
                        last edited by

                        Detailled as in your first picture didn't show the PRI3 header ....
                        What version of pfblocker and pfsense version are you using.

                        Did you ran any Update or Cron update since ?

                        As it is a new pfblockerNG installation, why don't you start over.
                        Disable pfblockerNG, disable Keep settings. Remove the package and install it again.

                        2.4.5-RELEASE-p1 (amd64)
                        Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                        Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                        F 1 Reply Last reply Reply Quote 0
                        • F
                          freefall @RonpfS
                          last edited by

                          @RonpfS the latest version. An it only been running for a week or so. I had thought of uninstall blocker an do it again, it but figured later on after I got it all set up working right then decide to tinker an break it rather not redo it all over again. I know there a back up option also..

                          1 Reply Last reply Reply Quote 0
                          • RonpfSR
                            RonpfS
                            last edited by

                            Can you add a new IPV4 group ? Maybe PRI3 will show up.

                            Search the forum for similar issue, it has been seen before.
                            Look at the config.xml, maybe you have empty config statement

                               	</pfblockerng>
                            ...
                               	<pfblockernglistsv4>
                            ...
                               			<config>
                               			</config>
                            ....
                            

                            2.4.5-RELEASE-p1 (amd64)
                            Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                            Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                            F 1 Reply Last reply Reply Quote 0
                            • F
                              freefall @RonpfS
                              last edited by freefall

                              @RonpfS just to let you know the reinstall fix it. It seems the dev version has some list auto include to download an install.. don't remember see those before. But in the dnsbl I see where I can remove them. It could of happen when I switch from non dev to dev without disabling it not sure

                              So thanks you all who comment on my post for helping me

                              RonpfSR 1 Reply Last reply Reply Quote 0
                              • RonpfSR
                                RonpfS @freefall
                                last edited by

                                @freefall said in Pfblockerng using feeds:

                                It could of happen when I switch from non dev to dev without disabling it not sure

                                It better to disable a package before updating /removing/re installing it.

                                Glad to see your found a cure :D

                                2.4.5-RELEASE-p1 (amd64)
                                Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                1 Reply Last reply Reply Quote 0
                                • B
                                  Bambos
                                  last edited by Bambos

                                  hello everyone,

                                  sorry that i bring this post back after long time, i have search the forum before decide making a new thread, so this post seems suitable to me.

                                  I'm scrolling all those feeds in pfblocker ng 3 and i don't know what to do, what to import and why...

                                  Is it bad to import all ?? what do you suggest ?

                                  and if someone wants to import all feeds, is there any faster way ? i do feeds, hit the + icon, enable all button to make options on, click save below... add the next one. after i do an update for all together. Any better option to enable ?

                                  U 1 Reply Last reply Reply Quote 0
                                  • U
                                    Uglybrian @Bambos
                                    last edited by Uglybrian

                                    @bambos Hi, I would suggest you start with the set up wizard for pfBlocker-NG-devel.
                                    The learning curve for pf bocker can be steep, so go slow and read everything......twice.
                                    In addition, go to the help on your pfSense dashboard, then click pf Sense book and navagate to pf blocker package and read up. just type pf blocker in the search of the book.This will give you a good start and basic understanding.Screenshot from 2022-02-22 08-46-26.pngScreenshot from 2022-02-22 09-10-59.png

                                    1 Reply Last reply Reply Quote 1
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.