Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlockerNG-devel v3.0.0_10

    Scheduled Pinned Locked Moved pfBlockerNG
    26 Posts 6 Posters 3.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • BBcan177B
      BBcan177 Moderator
      last edited by BBcan177

      A Pull Request has been submitted to the pfSense devs for review and approval:

      https://github.com/pfsense/FreeBSD-ports/pull/1039

      CHANGE LOG:

      • Add doh.dns.apple.com to DoH Block list (SafeSearch page)
      • Add RR_TYPE_SIG, RR_TYPE64, RR_TYPE65 to Unbound Python mode DNSBL validation.
      • Remove deprecated SafeSearch pfb_dnsbl.firefoxdoh.conf file
      • Fix regression with "+" icon Add IP to Whitelist Alias (Reports Tab)
      • Add pfSense Uniq_id string to the Curl User Agent String (Should improve BGPView issues for IP Blocked events ASN Reporting.)
      • Under the hood improvements to the Widget
      • Upgrade DNSBL Unbound mode parser for Lighttpd changes (pfSense 2.5 only)
      • Remove AutoShun Feeds
      • Unbound Python mode - Improve Log events for potential file permission errors.
      • Fix ASN Cache clearing of old ASN Entries, add a "1 Week" ASN Cache option

      Continue to follow in the pfSense forum and on Twitter [ u/BBcan177 ], and on Reddit [ r/pfBlockerNG ] and Patreon ( https://www.patreon.com/pfBlockerNG ) for pfBlockerNG news and support.

      Thank you for the Continued Support!

      "Experience is something you don't get until just after you need it."

      Website: http://pfBlockerNG.com
      Twitter: @BBcan177  #pfBlockerNG
      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

      J 1 Reply Last reply Reply Quote 10
      • J
        jdeloach @BBcan177
        last edited by

        @bbcan177

        I upgraded to pfBlockerNG-devel v3.0.0_10 this morning with no issues.

        Thank you for all your hard work in creating this great package for pfSense.

        1 Reply Last reply Reply Quote 1
        • L
          LabDog
          last edited by

          Install after a half hour still at this point and does not finish.
          Tried rebooting and starting again same result.
          latest ver, pfsense
          Package Reinstallation

          Upgrading pfSense-pkg-pfBlockerNG-devel...
          Updating pfSense-core repository catalogue...
          pfSense-core repository is up to date.
          Updating pfSense repository catalogue...
          pfSense repository is up to date.
          All repositories are up to date.
          Checking integrity... done (0 conflicting)
          The following 1 package(s) will be affected (of 0 checked):

          Installed packages to be UPGRADED:
          pfSense-pkg-pfBlockerNG-devel: 3.0.0_9 -> 3.0.0_10 [pfSense]

          Number of packages to be upgraded: 1
          [1/1] Upgrading pfSense-pkg-pfBlockerNG-devel from 3.0.0_9 to 3.0.0_10...
          [1/1] Extracting pfSense-pkg-pfBlockerNG-devel-3.0.0_10: .......... done
          Removing pfBlockerNG-devel components...
          Menu items... done.
          Services... done.
          Loading package instructions...
          Removing pfBlockerNG...grep: /var/unbound/pfb_dnsbl.conf: No such file or directory
          All customizations/data will be retained... done.

          BBcan177B 1 Reply Last reply Reply Quote 0
          • BBcan177B
            BBcan177 Moderator @LabDog
            last edited by

            @labdog
            See the following redmine:
            https://redmine.pfsense.org/issues/11398

            "Experience is something you don't get until just after you need it."

            Website: http://pfBlockerNG.com
            Twitter: @BBcan177  #pfBlockerNG
            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

            1 Reply Last reply Reply Quote 0
            • S
              Smoothrunnings
              last edited by

              Seeing these errors in my alert logs.

              There were error(s) loading the rules: /tmp/rules.debug:19: cannot define table bogonsv6: Cannot allocate memory - The line in question reads [19]: table <bogonsv6> persist file "/etc/bogonsv6"

              Not sure if its related to me being on 2.4.5 previously? I just upgraded to 2.5.0

              S 1 Reply Last reply Reply Quote 0
              • S
                SteveITS Galactic Empire @Smoothrunnings
                last edited by

                @smoothrunnings said in pfBlockerNG-devel v3.0.0_10:

                There were error(s) loading the rules: /tmp/rules.debug:19: cannot define table bogonsv6: Cannot allocate memory - The line in question reads [19]: table <bogonsv6> persist file "/etc/bogonsv6"

                What are your Firewall Maximum Table Entries set to in System/Advanced/Firewall & NAT? I believe the recommendation is double the default, minimum 2 million.

                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                Upvote 👍 helpful posts!

                S 1 Reply Last reply Reply Quote 0
                • S
                  Smoothrunnings @SteveITS
                  last edited by

                  @teamits 400,000 (without the comma)

                  RonpfSR 1 Reply Last reply Reply Quote 0
                  • RonpfSR
                    RonpfS @Smoothrunnings
                    last edited by RonpfS

                    @smoothrunnings https://forum.netgate.com/topic/149418/cannot-allocate-memor-after-adding-geo-ip/6

                    2.4.5-RELEASE-p1 (amd64)
                    Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                    Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                    S 1 Reply Last reply Reply Quote 0
                    • S
                      Smoothrunnings @RonpfS
                      last edited by

                      @RonpfS

                      I running NTopng, HAProxy, plus the pfBlockerNG. And today my firewall has been rebooting every hour or so. After it reboots the haproxy, ntopng, and the pfb_dnsbl and pfb_filter services are not running, as soon as I start them the firewall will reboot upto an update from the time of start.

                      The Firewall Maximum Table has been set to 2000000 and it sell reboots.

                      (sigh)...looks like I am going to have to rip out pfBlocker. :(

                      RonpfSR 1 Reply Last reply Reply Quote 0
                      • RonpfSR
                        RonpfS @Smoothrunnings
                        last edited by

                        @smoothrunnings said in pfBlockerNG-devel v3.0.0_10:

                        The Firewall Maximum Table has been set to 2000000 and it sell reboots.

                        Double that.

                        2.4.5-RELEASE-p1 (amd64)
                        Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                        Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                        S 1 Reply Last reply Reply Quote 0
                        • S
                          Smoothrunnings @RonpfS
                          last edited by

                          @ronpfs said in pfBlockerNG-devel v3.0.0_10:

                          @smoothrunnings said in pfBlockerNG-devel v3.0.0_10:

                          The Firewall Maximum Table has been set to 2000000 and it sell reboots.

                          Double that.

                          Ok it's double now. Let's see how it goes. Fingers crossed.

                          RonpfSR 1 Reply Last reply Reply Quote 0
                          • RonpfSR
                            RonpfS @Smoothrunnings
                            last edited by RonpfS

                            @smoothrunnings From what I read double it until the rules load.

                            2.4.5-RELEASE-p1 (amd64)
                            Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                            Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                            J S 2 Replies Last reply Reply Quote 0
                            • J
                              jdeloach @RonpfS
                              last edited by jdeloach

                              @ronpfs said in pfBlockerNG-devel v3.0.0_10:

                              @smoothrunnings From what I read double until the rules load.

                              For what it's worth, on my system it is showing 4000000 as the default for the Firewall Maximum Table Entries. I thought it was set 2000000. I am not having any issues with any problems.

                              S 1 Reply Last reply Reply Quote 0
                              • S
                                Smoothrunnings @RonpfS
                                last edited by

                                @ronpfs

                                pfSense keeps rebooting. I am up to 8000000, just about to double it again. so that will be 16000000.

                                Looks like there is a problem with pfBlockerNG.

                                1 Reply Last reply Reply Quote 0
                                • S
                                  SteveITS Galactic Empire
                                  last edited by

                                  I'm going to post here only because it's the version I installed today. :) I can shorten the description significantly just by saying that if pfBlockerNG has its Enable box unchecked, and I go to the Update tab and click Run, the page scrolls up an inch or two then snaps back to the top of the page and nothing happens.

                                  IOW the update process only runs if the Enable box is checked. That's logical, I suppose, for automatic updates, but I figured I would get everything ready before enabling it...and there is no error or notice that it won't run. The log has no output. Perhaps some sort of output that "pfBlocker is disabled, why did you click to update, you knucklehead?"

                                  @jdeloach said in pfBlockerNG-devel v3.0.0_10:

                                  showing 4000000 as the default for the Firewall Maximum Table Entries

                                  The default varies based on RAM, IIRC. Interestingly the SG-2100 I was setting up came with 2.4.5, we upgraded to 21.02, and it was showing as 400000. But after I changed it to 2m I noticed it says the default is 2m. So perhaps it increased in 21.02?

                                  @smoothrunnings said in pfBlockerNG-devel v3.0.0_10:

                                  pfSense keeps rebooting

                                  The out of memory error can't really cause a reboot AFAIK. I think those are two different symptoms. You only need a table size big enough to handle the table entries you're loading.

                                  Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                  When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                                  Upvote 👍 helpful posts!

                                  RonpfSR S 2 Replies Last reply Reply Quote 0
                                  • S
                                    Smoothrunnings @jdeloach
                                    last edited by

                                    @jdeloach

                                    You likely aren't running the extra stuff I have such as haproxy, and ntopng. I also have my guest WiFi connection going through my pfSense from Unifi. It wasn't crashing before I installed pfBlockerNG, after that's been nothing but issues. :(

                                    1 Reply Last reply Reply Quote 0
                                    • RonpfSR
                                      RonpfS @SteveITS
                                      last edited by

                                      @teamits said in pfBlockerNG-devel v3.0.0_10:

                                      So perhaps it increased in 21.02?

                                      Nope, it just take your number as default. :)

                                      2.4.5-RELEASE-p1 (amd64)
                                      Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                      Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                      S 2 Replies Last reply Reply Quote 0
                                      • S
                                        SteveITS Galactic Empire @RonpfS
                                        last edited by

                                        @ronpfs said in pfBlockerNG-devel v3.0.0_10:

                                        Nope, it just take your number as default. :)

                                        You're right. That's dumb. 2.4.5 does that too.

                                        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                                        Upvote 👍 helpful posts!

                                        1 Reply Last reply Reply Quote 0
                                        • S
                                          Smoothrunnings @SteveITS
                                          last edited by

                                          @teamits said in pfBlockerNG-devel v3.0.0_10:

                                          @smoothrunnings said in pfBlockerNG-devel v3.0.0_10:

                                          pfSense keeps rebooting

                                          The out of memory error can't really cause a reboot AFAIK. I think those are two different symptoms. You only need a table size big enough to handle the table entries you're loading.

                                          So provide me with the tool/instructions to verify that instead of just stating it.

                                          What I am stating and will continue to state is I am running this on a WatchGuard M400 with an intel i5-4750, 8GB of RAM, and 250GB SSD.

                                          Since last week I have been running my M400 with DHCP services for my WiFi Guest network, along with haproxy and ntopng for about a year without any issues, at the time I installed pfBlockerNG 3.0 Devel I was running on 2.4.5 and was getting the random reboots of pfSense on 2.4.5 which why I rolled over to 2.5.0.

                                          Looking at my pfSense this morning its uptime is 55 minutes right now, meaning through the night its rebooted.

                                          I think at this point someone needs to give me a hand looking through the logs to see why the pfsense keeps rebooting. Maybe it's coincidence that it started happening after pfBlockerNG was installed, but maybe it's it not, no one will really know until I get some help (the firewall just rebooted again), looks like its this time it hit about 6764 blocked IPs and rebooted. As I was saying the answer will likely be in the logs, but I don't know what to look for, so instead of just pointing fingers or saying "its working here" help.

                                          Thanks,

                                          RonpfSR 1 Reply Last reply Reply Quote 0
                                          • RonpfSR
                                            RonpfS @Smoothrunnings
                                            last edited by

                                            @smoothrunnings Maybe start a new forum post with Settings info and logs.

                                            2.4.5-RELEASE-p1 (amd64)
                                            Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                            Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                            S 1 Reply Last reply Reply Quote 1
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.