• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

pfB_PRI1_v4 - blocking common websites

Scheduled Pinned Locked Moved Firewalling
7 Posts 4 Posters 2.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    MrFrenchFry
    last edited by MrFrenchFry Mar 3, 2021, 5:37 PM Mar 3, 2021, 5:36 PM

    Hi,

    I've noticed the PFSense FW has started blocking some common websites, one in particular is:

    https://www.slamcity.com/ (there are others)

    After trying to locate the issue I tried disabling the pfB_PRI1_v4 rule on the LAN, when I disable the rule the site works.

    • How do I find out why this site is being blocked and then add it to a whitelist?

    • Also, how will I know what other innocent sites are being blocked?

    The packet shows the handshake being reset (I think)- Flags: 0x014 (RST, ACK). So maybe something else is going on here?

    Thanks For your help,
    Andy

    R 1 Reply Last reply Mar 3, 2021, 7:21 PM Reply Quote 0
    • R
      RonpfS @MrFrenchFry
      last edited by RonpfS Mar 3, 2021, 7:22 PM Mar 3, 2021, 7:21 PM

      @mrfrenchfry You can inspect blocking with the Reports/Alerts tab. From there you can whitelist/suppress Domains or IPs.
      Click on all icons to get detailed information on settings.

      2.4.5-RELEASE-p1 (amd64)
      Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
      Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

      C M 2 Replies Last reply Mar 3, 2021, 7:25 PM Reply Quote 1
      • C
        Cool_Corona @RonpfS
        last edited by Mar 3, 2021, 7:25 PM

        I would imagine that this could contribute to the fact that you cant use Firefox default page as a search engine here and have to use local google domains to get the search engine going...

        1 Reply Last reply Reply Quote 0
        • M
          MrFrenchFry @RonpfS
          last edited by Mar 4, 2021, 12:20 PM

          @ronpfs Thanks, i checked the alerts and can't see any entries for the IP or domain being blocked.

          However when checking the blocked IP URL Tables for PRI1_V4 i can see the entry for 23.227.38.65

          This is an IP for Shopify and hosts many webshops, including the one that is blocked above www.slamcity.com

          Firstly, should PFSenese alerts show this entry when i try to resolve the IP or web address? I don't see it in the alerts and nothing filters for those addresses. Surely when i try and access that site and its blocked it should be visible in the reporting and alerts?

          Second, i have added that site to the DNS WL but it still doesn't work. How can i add an IP to a whitelist?

          Thanks for your help!

          G 1 Reply Last reply Mar 4, 2021, 2:28 PM Reply Quote 0
          • G
            Gertjan @MrFrenchFry
            last edited by Mar 4, 2021, 2:28 PM

            @mrfrenchfry said in pfB_PRI1_v4 - blocking common websites:

            However when checking the blocked IP URL Tables for PRI1_V4 i can see the entry for 23.227.38.65

            Which one ?

            2bf3e1b2-1200-41eb-bc41-743b88ef79f1-image.png

            @mrfrenchfry said in pfB_PRI1_v4 - blocking common websites:

            Firstly, should PFSenese alerts show this entry when i try to resolve the IP or web address?

            Only host names can be resolved (to IP).
            IP's can't be resolved to IP's as they are already IP's.

            @mrfrenchfry said in pfB_PRI1_v4 - blocking common websites:

            Surely when i try and access that site and its blocked it should be visible in the reporting and alerts?

            Be aware : there is this option that adds the IP to an IP list (firewall alais) that blocks any further references to this domain.
            The alerts page will not mention the domain name any more, as any traffic hits the firewall, and is blocked. Making firewalls log can be done, but be warned for HUGE log files which will overflow very rapidly.

            @mrfrenchfry said in pfB_PRI1_v4 - blocking common websites:

            How can i add an IP to a whitelist?

            Like this :

            I have these DNSBL feeds :

            956ab3ed-168e-4c98-af5c-d6e61646a1d9-image.png

            Let's take the BBcan177 as an example.

            From here :

            0845a410-c2f2-43e0-9847-b9253cb59172-image.png

            I have a reference of the original data file.

            Let's check :

            bbca24e3-579d-4ff6-b724-3260a1b853f3-image.png

            Let's take "tl9pb.pheikmajide.com" as an example.

            When I open a browser and paste that URL, I get .....

            e88aa618-cc2b-43c5-9df1-eaf605f40d20-image.png

            Ok, pfB works;

            Now, have a look at the alert page :

            There it is :

            32a30a8d-1e27-46b5-b892-88facd291cba-image.png

            I'm going to white list this URL, by clicking on the + - Yes, Yes for wild card - Yes for adding a comment, and yes.

            Note that I saw a message when the adding (white listing) was done :

            65e26d58-e21b-4790-8d46-634ed673a338-image.png

            No big deal, I do what I was told to do :

            f5ecbd21-d0cf-4371-a902-0c08986662ae-image.png

            I opened a new browser (browser also cache URL's) and ....

            Bad luck : the site URL was already non-responsive / already taken down.

            dafe4d16-e90e-4fdf-b5ac-85702e25c2f8-image.png

            You saw the ERR_NAME_NOT_RESOLVED message ?

            Btw :
            Meanwhile, in the list with DNSBLs that are white listed :

            4d0d2cae-cbba-42d8-b1a6-4482d1a2a283-image.png

            so, "http://tl9pb.pheikmajide.com/" is white listed as from now.


            I did a second test :

            This one :

            f342fc0a-8433-441a-9c67-84ec268f06c0-image.png

            So I got :

            fbcf1da9-ad4c-41b0-b09a-e7ef6f972744-image.png

            I white listed the thing :

            c3e69ca3-4cc5-4cec-81ae-f796b00f8575-image.png

            Did the local DNS flush and a quick DNS test :

            461f3a6a-cb98-4878-8954-77144de26227-image.png

            Promessing, this one resolves now to an IP.

            And bingo : white listed : we got a pure BS site :

            7da1f20b-483a-428e-a297-4608b676e381-image.png

            As you can see, prissypreps.com forxards us to relaystor.xyz.

            Now, what is your issue ?

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            M 1 Reply Last reply Mar 4, 2021, 5:01 PM Reply Quote 1
            • M
              MrFrenchFry @Gertjan
              last edited by Mar 4, 2021, 5:01 PM

              @gertjan said in pfB_PRI1_v4 - blocking common websites:

              @mrfrenchfry said in pfB_PRI1_v4 - blocking common websites:

              However when checking the blocked IP URL Tables for PRI1_V4 i can see the entry for 23.227.38.65

              Which one ?

              This one

              PRI1_v4 Table.JPG

              Now, what is your issue ?

              I want to remove that IP from the table.

              G 1 Reply Last reply Mar 4, 2021, 7:18 PM Reply Quote 0
              • G
                Gertjan @MrFrenchFry
                last edited by Gertjan Mar 4, 2021, 7:19 PM Mar 4, 2021, 7:18 PM

                @mrfrenchfry said in pfB_PRI1_v4 - blocking common websites:

                I want to remove that IP from the table.

                Go here :

                5af41702-c0ba-4bc9-9979-a06ed6aceab3-image.png

                Go downwards.

                You'll find :

                7de04c99-d3b5-4e54-afd1-52b2124b88bf-image.png

                Click on the + sign on the right.

                b80b5db2-c2a0-47bd-941d-732cd1d14e1a-image.png

                Add your IP and mask.

                Save with the blue button at the bottem of the page.

                Update > Reload > All.

                Done. The IP is removed from the Alias table.

                Btw : the IP is listed by some IP feeds that you included yourself.

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                1 Reply Last reply Reply Quote 1
                1 out of 7
                • First post
                  1/7
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                  This community forum collects and processes your personal information.
                  consent.not_received