Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlockerNG-devel DNSBL not working after 21.05 upgrade

    Scheduled Pinned Locked Moved pfBlockerNG
    10 Posts 7 Posters 2.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      azdeltawye
      last edited by azdeltawye

      Hello, I recently upgraded my SG-5100 from v21.02.2 to 21.05. Everything went smoothly except I noticed that the DNSBL count on the pfBlockerNG widget was not incrementing. Upon further investigation in: Firewall/pfBlockerNG/Alerts/DNSBL Block: there are 0 block entries logged since the time I upgraded (6/6 @ 09:13). I attempted to force a pfBlock reload & update but that didn't seem to help. I also uninstalled the package and re-installed but no change.

      My setup is pretty simple; Single WAN, one OpenVPN client and two OpenVPN servers, five VLANs, packages: Avahi, nut, pfBlockerNG-devel, Service_Watchdog, Snort, Status_Traffic_Totals.

      Here is a screenshot from the pfBlocker widget, normally I see about 5% of domains blocked vs. Unbound Resolver Queries.

      Any troubleshooting suggestions would be welcome.
      04e91bae-d078-45fe-9b89-a80ff6facd7d-image.png

      S 1 Reply Last reply Reply Quote 6
      • S
        Surreallo @azdeltawye
        last edited by

        I have the same issue.. but it still seems to block stuff? I uninstalled and clean reinstalled it but the issue remains.

        1 Reply Last reply Reply Quote 0
        • W
          whorfin
          last edited by

          I am seeing the same thing, seems to be related to https vs http
          This seems to imply it might be fixed
          https://www.reddit.com/r/pfBlockerNG/comments/lnczld/is_dnsbl_webserver_for_ssl_https_connections/
          but that is not what I observe

          W 1 Reply Last reply Reply Quote 0
          • D
            dpseattle
            last edited by

            same issue after upgrading to version:

            2.5.2-RELEASE (amd64)
            built on Fri Jul 02 15:33:00 EDT 2021
            FreeBSD 12.2-STABLE

            there 0 in the unified logs which may account for the counters not working on the widget. Here's screenshot of widget after uninstall (unchecked keep setting), reinstall package, complete wizard and then add 1 custom dnsbl list.

            4827daed-5b58-47c9-8c6d-934dae431208-image.png

            1 Reply Last reply Reply Quote 1
            • J
              jdeloach
              last edited by

              Seems to be working okay for me. I have not seen any issues since upgrading to pfSense 2.5.2.

              ff5aa778-e68a-486f-8572-c15ba44f4006-image.png

              A 1 Reply Last reply Reply Quote 0
              • A
                azdeltawye @jdeloach
                last edited by

                @jdeloach
                What DNSBL mode are you running?
                Unbound or Unbound Python

                J 1 Reply Last reply Reply Quote 0
                • J
                  jdeloach @azdeltawye
                  last edited by jdeloach

                  @azdeltawye said in pfBlockerNG-devel DNSBL not working after 21.05 upgrade:

                  What DNSBL mode are you running?

                  Unbound or Unbound Python

                  I'm running Unbound Python

                  1 Reply Last reply Reply Quote 0
                  • S
                    Stuart Pritchard
                    last edited by Stuart Pritchard

                    Hi
                    I am running Community edition 2.5.2 Release
                    PfblockerNG 3.0.0_16
                    I have the same issue running unbound python mode.
                    The DNSBL counters in the widget increment OK (25,110) but I have 0 entries in the IP section even though the logs are incrementing fine and Alerts are showing OK in the pfblockerNG alerts TAB..
                    Thks

                    1 Reply Last reply Reply Quote 0
                    • ilkevinliI
                      ilkevinli
                      last edited by ilkevinli

                      I am also seeing the same thing on the 2.5.2 CE release. I noticed that it seems to have stopped working some time around July 8 from looking at the DNSBL reports. I also uninstalled without the "keep settings" option and reinstalled and it still seems to be broken.

                      Does anyone have any suggestions ? Thank you.

                      alt text

                      1 Reply Last reply Reply Quote 0
                      • W
                        whorfin @whorfin
                        last edited by

                        Fixed in pfBlockerNG-devel v3.1.0_0

                        CHANGELOG:
                        ...
                        Fix Unbound Mode logging of HTTPS domains (lighttpd regression)
                        
                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.