Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    What is the current status of pfBlockerNG-devel?

    Scheduled Pinned Locked Moved pfBlockerNG
    21 Posts 10 Posters 3.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      guardian Rebel Alliance
      last edited by

      I noticed that @BBcan177 hasn't been around the forum for several months -- does this mean that development/maintenance has ceased?

      If you find my post useful, please give it a thumbs up!
      pfSense 2.7.2-RELEASE

      GertjanG J 2 Replies Last reply Reply Quote 0
      • GertjanG
        Gertjan @guardian
        last edited by

        @guardian

        I guess he takes a break. That's what it takes to keep being motivated.
        IMHO, and as far as I know, there are no 'urgent matters' to deal with right now.
        I do presume he's surveying, and will pop up if urgent matters turn up.

        Version 3.0 was very promising when it came out, but still needed 15 other sub version to iron out a boat load of small issues, where some solution created others issues ;)

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        G 1 Reply Last reply Reply Quote 1
        • G
          guardian Rebel Alliance @Gertjan
          last edited by

          @gertjan said in What is the current status of pfBlockerNG-devel?:

          @guardian

          I guess he takes a break. That's what it takes to keep being motivated.
          IMHO, and as far as I know, there are no 'urgent matters' to deal with right now.
          I do presume he's surveying, and will pop up if urgent matters turn up.

          Version 3.0 was very promising when it came out, but still needed 15 other sub version to iron out a boat load of small issues, where some solution created others issues ;)

          I agree it seems to be working very well. I just upgraded yesterday, and have been going through the feeds cleaning up what I had in version 2 and looking at the candidates provided to see if I should add anything.

          If you find my post useful, please give it a thumbs up!
          pfSense 2.7.2-RELEASE

          A 1 Reply Last reply Reply Quote 0
          • A
            azdeltawye @guardian
            last edited by

            Does anyone know when Python mode will promoted to production? Currently Python unbound mode is listed as 'Beta'..

            GertjanG 1 Reply Last reply Reply Quote 0
            • GertjanG
              Gertjan @azdeltawye
              last edited by

              @azdeltawye

              Python mode was introduced in pfSense version 2.4.5, introduced in March 2020.
              This badge could probably be removed.
              If it was me, de "-devel" suffix could also be removed.

              I'm using Python mode since last year. It's rock solid.

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              keyserK 1 Reply Last reply Reply Quote 1
              • keyserK
                keyser Rebel Alliance @Gertjan
                last edited by

                @gertjan Rock solid yes, but I have uncovered that it causes sustained write I/O til disk when running in python mode. Not a huge number - for my tests on a SG1100, SG2100 and SG5100 only about 100 - 400Kb/s sustained.

                But for the small boxes with only a built in 8Gb eMMC, that will burn through the drive write endurance in about a years time.

                So we might se a lot of SG-1100/SG-2100/SG-3100 with failed SSD drives in less than a year from now if this issue is not fixed.

                Love the no fuss of using the official appliances :-)

                GertjanG 1 Reply Last reply Reply Quote 0
                • GertjanG
                  Gertjan @keyser
                  last edited by

                  @keyser said in What is the current status of pfBlockerNG-devel?:

                  but I have uncovered that it causes sustained write I/O til disk when running in python mode

                  You discovered that people wanted charts, details and graphs 😊

                  3b1d0f24-5d29-4c7a-80b6-ae27b8233365-image.png
                  .

                  No "help me" PM's please. Use the forum, the community will thank you.
                  Edit : and where are the logs ??

                  keyserK 1 Reply Last reply Reply Quote 0
                  • keyserK
                    keyser Rebel Alliance @Gertjan
                    last edited by

                    @gertjan Maybe, but it also happens even though no users are connected and no DNS resolutions are made (appart from what the pfSense box does on its own).
                    So I doubt it is related to this - please remember I have tried disabling all logging on DNSBL and lists and, and …..

                    Love the no fuss of using the official appliances :-)

                    GertjanG 1 Reply Last reply Reply Quote 0
                    • J
                      jdeloach @guardian
                      last edited by jdeloach

                      @guardian said in What is the current status of pfBlockerNG-devel?:

                      I noticed that @BBcan177 hasn't been around the forum for several months -- does this mean that development/maintenance has ceased?

                      @BBcan177 appears to be very active on reddit.com working/testing issues that folks are reporting here on the netgate forum.

                      A quick google search would tell you what he is doing/finding with issues folks have reported here. Don't worry, he hasn't abandoned pfblockerNG-devel.

                      1 Reply Last reply Reply Quote 0
                      • GertjanG
                        Gertjan @keyser
                        last edited by

                        @keyser

                        Set this :

                        17df846f-dece-4565-a2e2-dfd4a018a63b-image.png

                        save and reload.

                        Now you can see what happens - what unbound does - in real time :

                        tail -f /var/log/resolver.log
                        

                        To reduce the DNS activity, remove devices from your LAN's.

                        Don't forget to lower the log setting ;)

                        No "help me" PM's please. Use the forum, the community will thank you.
                        Edit : and where are the logs ??

                        1 Reply Last reply Reply Quote 1
                        • J
                          jc1976
                          last edited by

                          Does anyone know the timeline of when pfBlockerNG will be taken down and fully replaced with -devel?

                          with each new -devel release, are we required to uninstall the old '-devel' first?

                          will @BBcan177 ever hand over the reins to the community for further development of pfBlocker instead of taking it all on himself?
                          I imagine he's gotta be a bit burnt out at this point.. and if he should ever decide to quit, what a crime..

                          S 1 Reply Last reply Reply Quote 0
                          • S
                            SteveITS Galactic Empire @jc1976
                            last edited by

                            @jc1976 said in What is the current status of pfBlockerNG-devel?:

                            Does anyone know the timeline of when pfBlockerNG will be taken down and fully replaced with -devel?

                            Haven't seen one. It's been a few years.

                            with each new -devel release, are we required to uninstall the old '-devel' first?

                            No. There's a button to upgrade existing packages (in place of the checkmark for "up to date"). Generally, Netgate suggests uninstalling packages before pfSense version upgrades and reinstalling after.

                            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                            Upvote šŸ‘ helpful posts!

                            1 Reply Last reply Reply Quote 0
                            • E
                              emikaadeo
                              last edited by emikaadeo

                              pfBlockerNG-devel 3.1.0 is coming https://github.com/pfsense/FreeBSD-ports/pull/1106

                              keyserK fireodoF 2 Replies Last reply Reply Quote 1
                              • keyserK
                                keyser Rebel Alliance @emikaadeo
                                last edited by

                                @emikaadeo said in What is the current status of pfBlockerNG-devel?:

                                pfBlockerNG-devel 3.1.0 is coming https://github.com/pfsense/FreeBSD-ports/pull/1106

                                Yay - Hail @BBcan177 for his EXCELLENCT workšŸ™

                                Love the no fuss of using the official appliances :-)

                                1 Reply Last reply Reply Quote 1
                                • fireodoF
                                  fireodo @emikaadeo
                                  last edited by fireodo

                                  @emikaadeo said in What is the current status of pfBlockerNG-devel?:

                                  pfBlockerNG-devel 3.1.0 is coming https://github.com/pfsense/FreeBSD-ports/pull/1106

                                  So glad to see BBcan177 back! 😊

                                  Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                                  SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                                  pfsense 2.8.0 CE
                                  Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                                  keyserK 1 Reply Last reply Reply Quote 0
                                  • keyserK
                                    keyser Rebel Alliance @fireodo
                                    last edited by keyser

                                    @fireodo
                                    And… It’s released :-)

                                    Upgrading now. Will report back with status regarding fixes to the issues at hand (filling disk and missing https logging/widget count stopping)

                                    Update: It upgraded without issues and so far works as expected.
                                    It also returned the currently ā€œlostā€ drive space (as stopping/starting pfBlockerNG-devel did)

                                    Love the no fuss of using the official appliances :-)

                                    1 Reply Last reply Reply Quote 0
                                    • E
                                      emikaadeo
                                      last edited by emikaadeo

                                      Upgrade from 3.0.0_16 to 3.1.0 doesn't went smoothly for me on CE 2.5.2
                                      (Unbound Python mode)

                                      1/ Unbound fails to start (have to be restarted manually)
                                      2/ DNSBL 'tick' on widget was yellow, no DNSBL aliases were showing
                                      3/ have to 'Force Reload' DNSBL
                                      4/ lost DNSBL packet count on Dashboard Widget

                                      Basically all the symptoms like here https://www.reddit.com/r/pfBlockerNG/comments/mmzy7f/dnsbl_packet_count_cleared_on_upgrade

                                      PS. I didn't disable pfBlockerNG before upgrade.

                                      keyserK 1 Reply Last reply Reply Quote 0
                                      • keyserK
                                        keyser Rebel Alliance @emikaadeo
                                        last edited by keyser

                                        @emikaadeo
                                        Didi you follow the short guide on what to do/expect during upgrade?

                                        After install you need to disable pfBlockerNG, save, force update, and then you can enable pfBlockerNG, save and yet another Force Update.

                                        Only after that can you expect the new code to be active and things ā€œback to normalā€

                                        Love the no fuss of using the official appliances :-)

                                        V E keyserK 3 Replies Last reply Reply Quote 0
                                        • V
                                          vjizzle @keyser
                                          last edited by

                                          @keyser said in What is the current status of pfBlockerNG-devel?:

                                          @emikaadeo
                                          Didi you follow the short guide on what to do/expect during upgrade?

                                          After install you need to disable pfBlockerNG, save, force update, and then you can enable pfBlockerNG, save and yet another Force Update.

                                          Only after that can you expect the new code to be active and things ā€œback to normalā€

                                          Or just reboot. I did that and everything is working fine.

                                          1 Reply Last reply Reply Quote 0
                                          • E
                                            emikaadeo @keyser
                                            last edited by

                                            @keyser said in What is the current status of pfBlockerNG-devel?:

                                            @emikaadeo
                                            Didi you follow the short guide on what to do/expect during upgrade?

                                            It’s not like I didn’t know what to do to deal with this issues ;)
                                            It was first pfBlocker upgrade since CE 2.5.0 or 2.5.1 and I thought this issuses was resolved since then.
                                            But it looks like bug https://redmine.pfsense.org/issues/11398 is still with us.
                                            Anyway, pfBlocker and Unbound are up and running.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.