Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlocker not logging after 2.5.2 pfSense upgrade

    Scheduled Pinned Locked Moved pfBlockerNG
    53 Posts 17 Posters 10.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cefleet
      last edited by

      Hi,

      I upgraded pfSense to 2.5.2 and pfBlocker 3.0.0_16 has stopped logging blocked IPs. As you can see, it is only showing 1 blocked under teh DS_Basic in teh image below. It is still blocking everything, and logging is turned on. However, it is not working. It worked fine with pfSense 2.5.1. I've uninstalled and reinstalled pfBlocker, with no luck. Any thoughts?

      415e408e-176b-456c-836d-920d450bcac6-image.png

      Thanks,

      -cefleet

      1 Reply Last reply Reply Quote 6
      • D
        dpseattle
        last edited by

        same. i replied in a different thread: https://forum.netgate.com/topic/164252/pfblockerng-devel-dnsbl-not-working-after-21-05-upgrade

        RonpfSR 1 Reply Last reply Reply Quote 3
        • RonpfSR
          RonpfS @dpseattle
          last edited by

          @dpseattle said in pfBlocker not logging after 2.5.2 pfSense upgrade:

          https://forum.netgate.com/topic/164252/pfblockerng-devel-dnsbl-not-working-after-21-05-upgrade

          Disable pfblockerNG
          Review and Save settings in General, IP & DNSBL tab.
          Enable pfblockerNG, Force Update, Force Reload All, see if things improve.

          2.4.5-RELEASE-p1 (amd64)
          Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
          Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

          D 1 Reply Last reply Reply Quote 2
          • D
            dpseattle @RonpfS
            last edited by

            @ronpfs followed suggestion. same outcome.

            62dcd88c-ec08-4dbe-a52a-b178509a0175-image.png

            RonpfSR 1 Reply Last reply Reply Quote 1
            • RonpfSR
              RonpfS @dpseattle
              last edited by

              @dpseattle Time to inspect the log files and check if new blocks are logged.

              2.4.5-RELEASE-p1 (amd64)
              Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
              Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

              C D 2 Replies Last reply Reply Quote 2
              • C
                cefleet @RonpfS
                last edited by

                @ronpfs Thanks for your help. I did what you recommended, with no luck. Here is a screenshot of the log file. It is only logging pixel.wp.com blocks. Though it is blocking the other stuff as well.

                48172734-4066-4eb0-a67d-6529d8139eeb-image.png

                Thanks,

                -cefleet

                1 Reply Last reply Reply Quote 2
                • badprocessB
                  badprocess
                  last edited by

                  Same here. Blocking seems to work but no logging

                  fireodoF 1 Reply Last reply Reply Quote 1
                  • fireodoF
                    fireodo @badprocess
                    last edited by

                    @badprocess

                    What if you deactivate pfblocker, go to pfblocker logs and delete:
                    dnsbl.log
                    unified.log
                    ip_block.log
                    and after that reactivate pfblocker? Just a idea ;-)

                    B 1 Reply Last reply Reply Quote 0
                    • B
                      berthis1958 @fireodo
                      last edited by berthis1958

                      @fireodo said in pfBlocker not logging after 2.5.2 pfSense upgrade:

                      @badprocess

                      What if you deactivate pfblocker, go to pfblocker logs and delete:
                      dnsbl.log
                      unified.log
                      ip_block.log
                      and after that reactivate pfblocker? Just a idea ;-)

                      Not working for me

                      fireodoF badprocessB 2 Replies Last reply Reply Quote 1
                      • fireodoF
                        fireodo @berthis1958
                        last edited by fireodo

                        This post is deleted!
                        1 Reply Last reply Reply Quote 0
                        • badprocessB
                          badprocess @berthis1958
                          last edited by

                          @berthis1958 not working for me too

                          1 Reply Last reply Reply Quote 1
                          • badprocessB
                            badprocess
                            last edited by

                            It’s strange: for example if I try to access http://device-metrics-us.amazon.com (which is normally called by the Amazon Echo Show 5 periodically) via a browser the entry is logged in (and blocked of course). On the other hand, the Echo Show has these blocked requests (they were well logged until 2.5.1) but they are no longer logged

                            1 Reply Last reply Reply Quote 0
                            • C
                              cefleet
                              last edited by

                              You can clearly see where I upgraded to 2.5.2 in the screenshot. It is of the dnsbl.log file.

                              bfe0d4d8-8bb3-47ed-bcc1-f62008f13ad1-image.png

                              RonpfSR 1 Reply Last reply Reply Quote 0
                              • RonpfSR
                                RonpfS @cefleet
                                last edited by RonpfS

                                @cefleet When you hover the cursor over the DNSBL / IP numbers, what is the Clear date? Maybe you can clear the counters using the Widget Garbage Icon ?

                                2.4.5-RELEASE-p1 (amd64)
                                Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                1 Reply Last reply Reply Quote 0
                                • B
                                  bs09
                                  last edited by

                                  I have this same issue. When on 2.5.1 dashboard was working fine. Showed thousands of requests and counters would keep incrementing ever second due to smart devices.

                                  After upgrading to 2.5.2 dashboard was all 0. I reinstalled PfBlockerNG 3.0.0_16. But that didn't change anything. Looking in dbsbl.log after the upgrade it was all old stuff, nothing new. I did a force reload and didn't change anything. I verified it was in fact blocking ads but just nothing showing up in the logs and therefore not the dashboard or reports.

                                  What is strange is this morning there are now a few things in log and dashboard shows 99 things blocked. But even now, logs have stuff from late last night, nothing from today. So not sure what broke w/ the 2.5.2 update.

                                  B 1 Reply Last reply Reply Quote 2
                                  • B
                                    berthis1958 @bs09
                                    last edited by

                                    @bs09 Exactly the same thing happened to me and I tried much the same things as you ... I continue to investigate for a possible solution ...

                                    1 Reply Last reply Reply Quote 1
                                    • D
                                      dpseattle @RonpfS
                                      last edited by dpseattle

                                      @ronpfs after letting it run for 12hrs. the widget count is 0 for blocked packets (but confirm ads are being blocked). here is the dnsbl log that only shows a handful from yesterday.

                                      1e078ff1-9549-4d11-a0d6-ef72397e9016-image.png

                                      RonpfSR 1 Reply Last reply Reply Quote 0
                                      • RonpfSR
                                        RonpfS @dpseattle
                                        last edited by

                                        @dpseattle Maybe the .sqlite files have the wrong ownership ?

                                        ls -al /var/unbound/
                                        
                                        total 42831
                                        drwxr-xr-x   7 unbound  unbound        39 Jul  9 12:26 .
                                        drwxr-xr-x  27 root     wheel          27 Jun  2  2020 ..
                                        -rw-r--r--   1 root     unbound       176 Jul  5 04:24 access_lists.conf
                                        drwxr-xr-x   2 unbound  unbound         2 Jun  2  2020 conf.d
                                        dr-xr-xr-x   8 root     wheel         512 Jul  5 08:20 dev
                                        -rw-r--r--   1 root     unbound         0 Jul  5 04:24 dhcpleases_entries.conf
                                        -rw-r--r--   1 root     unbound      3371 May  1 00:18 dnsbl_cert.pem
                                        -rw-r--r--   1 root     unbound         0 Jul  5 04:24 domainoverrides.conf
                                        -rw-r--r--   1 root     unbound      3816 Jul  5 04:24 host_entries.conf
                                        drwxr-xr-x   4 root     wheel          58 Oct  2  2020 lib
                                        -rw-r--r--   1 root     unbound      1697 Mar 22 22:01 pfb_dnsbl_lighty.conf
                                        -rw-r--r--   1 root     unbound         0 Jan  8 11:52 pfb_py_cache.dnsbl
                                        -rw-r--r--   1 unbound  unbound      8192 Jul  9 12:13 pfb_py_cache.sqlite
                                        -rw-r--r--   1 root     unbound         7 Jul  9 08:20 pfb_py_count
                                        -rw-r--r--   1 root     unbound  13071812 Jul  9 08:20 pfb_py_data.txt
                                        -rw-r--r--   1 unbound  unbound      8192 Jul  9 12:20 pfb_py_dnsbl.sqlite
                                        -rwxr-xr-x   1 root     wheel     1687428 Jun 28  2020 pfb_py_hsts.txt
                                        -rw-r--r--   1 root     unbound   1687428 Jun 28  2020 pfb_py_hsts.txt.pkgsave
                                        -rw-r--r--   1 root     unbound         0 Jan  8 11:52 pfb_py_resolver.dnsbl
                                        -rw-r--r--   1 unbound  unbound     16384 Jul  9 12:26 pfb_py_resolver.sqlite
                                        -rw-r--r--   1 root     unbound      3475 Apr 18 01:16 pfb_py_ss.txt
                                        -rw-r--r--   1 root     unbound      2793 Mar  2  2019 pfb_py_whitelist.json
                                        -rw-r--r--   1 root     unbound      2750 Mar 22 22:01 pfb_py_whitelist.txt
                                        -rw-r--r--   1 root     wheel    52420053 Jul  9 08:20 pfb_py_zone.txt
                                        -rw-r--r--   1 root     unbound       782 Feb 28 20:19 pfb_unbound.ini
                                        -rwxr-xr-x   1 root     wheel       66726 Apr  7 12:46 pfb_unbound.py
                                        -rw-r--r--   1 root     unbound     43906 Nov  1  2020 pfb_unbound.py.pkgsave
                                        -rwxr-xr-x   1 root     wheel        7077 Mar  6 11:44 pfb_unbound_include.inc
                                        -rw-r--r--   1 root     unbound      5454 Nov  1  2020 pfb_unbound_include.inc.pkgsave
                                        -rw-r--r--   1 root     unbound       300 Dec  8  2018 remotecontrol.conf
                                        -rw-r--r--   1 unbound  unbound       758 Jul  9 08:20 root.key
                                        -rw-r--r--   1 unbound  unbound      2141 Jul  5 04:24 unbound.conf
                                        -rw-r--r--   1 root     unbound      2140 Mar  4 08:19 unbound.conf.error
                                        -rw-r-----   1 unbound  unbound      2459 Dec  8  2018 unbound_control.key
                                        -rw-r-----   1 unbound  unbound      1330 Dec  8  2018 unbound_control.pem
                                        -rw-r-----   1 unbound  unbound      2459 Dec  8  2018 unbound_server.key
                                        -rw-r-----   1 unbound  unbound      1318 Dec  8  2018 unbound_server.pem
                                        drwxr-xr-x   3 root     unbound         3 Mar 22 22:01 usr
                                        drwxr-xr-x   3 root     unbound         3 Mar 22 22:03 var
                                        
                                        
                                        

                                        2.4.5-RELEASE-p1 (amd64)
                                        Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                                        Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                                        D C 2 Replies Last reply Reply Quote 0
                                        • D
                                          dpseattle @RonpfS
                                          last edited by

                                          @ronpfs looks like .sqlite are set to unbound:unbound/
                                          424f68de-48f5-4450-a125-455b8b8ba28b-image.png

                                          1 Reply Last reply Reply Quote 0
                                          • C
                                            cefleet @RonpfS
                                            last edited by

                                            @ronpfs Looks like the sqlite files are correct

                                            ad7d3904-3571-4c4c-b540-e54bbe520f78-image.png

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.