Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlockerNG-devel v3.1.0_0

    Scheduled Pinned Locked Moved pfBlockerNG
    22 Posts 12 Posters 13.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • BBcan177B
      BBcan177 Moderator
      last edited by

      A Pull Request has been submitted to the pfSense devs for review and approval.

      https://www.patreon.com/posts/55919257

      As per the pfSense Devs, it is available to be installed for the following pfSense versions:

      • CE 2.6.0 and 2.5.2

      • Plus 21.09 and 21.05.1

      Note: For Unbound Python mode - Drive space issue:

      There are two choices to have the new code take effect -

      1. Disable DNSBL, Save, Force Update, Followed by re-enable of DNSBL, Save, Force Update
        or
      2. Reboot

      Then check drive space with

       df -hm
      

      "Experience is something you don't get until just after you need it."

      Website: http://pfBlockerNG.com
      Twitter: @BBcan177  #pfBlockerNG
      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

      keyserK S L L 4 Replies Last reply Reply Quote 22
      • BBcan177B BBcan177 pinned this topic on
      • Cool_CoronaC
        Cool_Corona
        last edited by

        @BBcan177 You are doing a great job for the community. Thank you.

        fireodoF 1 Reply Last reply Reply Quote 3
        • fireodoF
          fireodo @Cool_Corona
          last edited by

          @BBcan177
          Thank you very much!

          Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
          SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
          pfsense 2.8.0 CE
          Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

          1 Reply Last reply Reply Quote 0
          • keyserK
            keyser Rebel Alliance @BBcan177
            last edited by

            @bbcan177 Thank you so much for your work and dedication to this project and your pfBlockerNG package.

            pfBlockerNG is what brings pfSense to the next level in my book :-)

            Love the no fuss of using the official appliances :-)

            1 Reply Last reply Reply Quote 2
            • S
              Surreallo @BBcan177
              last edited by

              @bbcan177

              thanks for the update! your package is the main reason I use pfsense!

              1 Reply Last reply Reply Quote 2
              • L
                longhorn @BBcan177
                last edited by longhorn

                @bbcan177 I logged in just to say THANK YOU to you and Ronaldo Botelho.

                The issue fixed in his pull request was driving me nuts the last 6+ months as I could not figure out why I kept getting IPv6 addr log errors. Any changes I made to config files were wiped out on reboot, and it was a very frustrating experience to get hundreds of notifications every day for a non-issue.

                I am very thankful to this community and its members who work tirelessly to improve IT Sec for everyone! Kudos to you both!

                https://redmine.pfsense.org/issues/12330

                1 Reply Last reply Reply Quote 0
                • P
                  p32spaceblaster
                  last edited by

                  Is anyone else having issues upgrading? I get the following:
                  Confirmation Required to upgrade package pfSense-pkg-pfBlockerNG-devel from 3.0.0_16 to 3.1.0.

                  Then this

                  Upgrading pfSense-pkg-pfBlockerNG-devel...
                  Updating pfSense-core repository catalogue...
                  pfSense-core repository is up to date.
                  Updating pfSense repository catalogue...
                  pfSense repository is up to date.
                  All repositories are up to date.
                  Failed

                  1 Reply Last reply Reply Quote 0
                  • L
                    ltolbert @BBcan177
                    last edited by

                    This post is deleted!
                    1 Reply Last reply Reply Quote 0
                    • M
                      miquim
                      last edited by

                      I can not update the UT1 & ShallaList categories.

                      my log is allways this:

                      UPDATE PROCESS START [ v3.1.0 ] [ 10/26/21 16:25:00 ]
                      
                      ===[  DNSBL Process  ]================================================
                      
                      Clearing all DNSBL Feeds
                      
                      TLD Analysis not required.
                      Stopping Unbound Resolver
                      Unbound stopped in 1 sec.
                      Additional mounts (DNSBL python):
                        No changes required.
                      Starting Unbound Resolver... completed
                      Restarting DNSBL Service (DNSBL python)
                      DNSBL update [ 0 | PASSED  ]... completed [ 10/26/21 16:25:01 ]
                      ------------------------------------------------------------------------
                      
                      ===[  GeoIP Process  ]============================================
                      
                      
                      ===[  Aliastables / Rules  ]==========================================
                      
                      No changes to Firewall rules, skipping Filter Reload
                      No Changes to Aliases, Skipping pfctl Update
                      
                       UPDATE PROCESS ENDED
                      
                      

                      any one can help me?

                      GertjanG 1 Reply Last reply Reply Quote 0
                      • GertjanG
                        Gertjan @miquim
                        last edited by

                        @miquim said in pfBlockerNG-devel v3.1.0_0:

                        any one can help me?

                        Looks like this :

                        703c3537-0198-44b4-a151-da4ca11a6bac-image.png

                        isn't checked, right ?

                        The message "Clearing all DNSBL Feeds" is showed under one condition :

                        // When DNSBL is enabled and no Aliases are defined, or all Aliases are Disabled
                        

                        as in that case there is nothing to do.

                        No "help me" PM's please. Use the forum, the community will thank you.
                        Edit : and where are the logs ??

                        M 1 Reply Last reply Reply Quote 0
                        • M
                          miquim @Gertjan
                          last edited by

                          @gertjan said in pfBlockerNG-devel v3.1.0_0:

                          @miquim said in pfBlockerNG-devel v3.1.0_0:

                          any one can help me?

                          Looks like this :

                          703c3537-0198-44b4-a151-da4ca11a6bac-image.png

                          isn't checked, right ?

                          The message "Clearing all DNSBL Feeds" is showed under one condition :

                          // When DNSBL is enabled and no Aliases are defined, or all Aliases are Disabled
                          

                          as in that case there is nothing to do.

                          no, it is enable, I make a fresh install of pfsense pfSense-CE-2.5.2-RELEASE-amd64, than install the pfBlockerNG-devel version 3.1.0.

                          1a9b26c6-ee6e-4917-a305-4ed4c8bc4861-image.png
                          5492d7a2-a226-4839-a431-8048c9277d7c-image.png

                          and get same error

                          dd8ded49-4d16-436e-b862-93b9c5e4d891-image.png

                          M 1 Reply Last reply Reply Quote 0
                          • M
                            miquim @miquim
                            last edited by

                            @miquim said in pfBlockerNG-devel v3.1.0_0:

                            @gertjan said in pfBlockerNG-devel v3.1.0_0:

                            @miquim said in pfBlockerNG-devel v3.1.0_0:

                            any one can help me?

                            Looks like this :

                            703c3537-0198-44b4-a151-da4ca11a6bac-image.png

                            isn't checked, right ?

                            The message "Clearing all DNSBL Feeds" is showed under one condition :

                            // When DNSBL is enabled and no Aliases are defined, or all Aliases are Disabled
                            

                            as in that case there is nothing to do.

                            no, it is enable, I make a fresh install of pfsense pfSense-CE-2.5.2-RELEASE-amd64, than install the pfBlockerNG-devel version 3.1.0.

                            1a9b26c6-ee6e-4917-a305-4ed4c8bc4861-image.png
                            5492d7a2-a226-4839-a431-8048c9277d7c-image.png

                            and get same error

                            dd8ded49-4d16-436e-b862-93b9c5e4d891-image.png

                            i found the problem, I need to create this dnsbl group like this and it worked.
                            660a965d-7030-4fa7-b23d-3683946216d7-image.png

                            1 Reply Last reply Reply Quote 1
                            • R
                              rjamesm
                              last edited by

                              Any word on safe search allowing duckduckgo? It appears it doesn't work.

                              1 Reply Last reply Reply Quote 1
                              • K
                                ksh
                                last edited by

                                Hi
                                I have some challanges with pfBlockerNG on version 22.05.
                                I have 2 pfSense were i have a custom IPv4 source defination.
                                On one of my pfSense it does not update the entire list on my other it does.
                                They are sync the settings to eachother so it has the same configuration.
                                Any idea why this might go bad?
                                It seems that pfSense 1 is just stuck on some cache or some "obsolete" list

                                pfSense 1 log
                                Alias table IP Counts

                                18754 total
                                16397 /var/db/aliastables/pfB_PRI1_v4.txt
                                1178 /var/db/aliastables/pfB_Allow_Hosting_Gateway_v4.txt
                                1178 /var/db/aliastables/pfB_Allow_Hosting_Customers_v4.txt
                                1 /var/db/aliastables/pfB_3CX_ServerPublic_v4.txt

                                pfSense 2 log
                                Alias table IP Counts

                                19042 total
                                16635 /var/db/aliastables/pfB_PRI1_v4.txt
                                1203 /var/db/aliastables/pfB_Allow_Hosting_Gateway_v4.txt
                                1203 /var/db/aliastables/pfB_Allow_Hosting_Customers_v4.txt
                                1 /var/db/aliastables/pfB_3CX_ServerPublic_v4.txt

                                GertjanG 1 Reply Last reply Reply Quote 0
                                • GertjanG
                                  Gertjan @ksh
                                  last edited by Gertjan

                                  @ksh

                                  Do a Force reload, and look at what the log, at the bottom of the page, produces.
                                  Even when I asked a

                                  8c459bc3-a537-4a27-a56e-2f5ad7bd3246-image.png

                                  the files didn't get reloaded again :

                                  ...
                                  ====================[ DNSBL Last Updated List Summary ]==============
                                  
                                  Oct 3	00:00	DNSBL_174618
                                  Dec 5	00:00	UT1_gambling
                                  Dec 5	00:00	UT1_games
                                  Dec 5	00:00	UT1_phishing
                                  Dec 5	00:00	UT1_warez
                                  Dec 5	00:00	StevenBlack_ADs
                                  ===============================================================
                                  ...
                                  

                                  Note : where I live, its December 7.
                                  So, it might be possible that files on your two pfSense are not 100 % identical.
                                  This behaviour is normal. List don't get reloaded every hours or so as this (xx thousands of pfBlockerng-devel are running out there) would destroy the web servers that hosts these files.

                                  Btw : I've demanded to update my one and only DNSBL list Weekly, as these lists do not get updated massively every hour or day and I don't bother missing one or two.

                                  3959bffc-400b-4776-a1f0-f44808105c40-image.png

                                  No "help me" PM's please. Use the forum, the community will thank you.
                                  Edit : and where are the logs ??

                                  K 1 Reply Last reply Reply Quote 0
                                  • K
                                    ksh @Gertjan
                                    last edited by

                                    @gertjan
                                    My custom list needs to be adjusted more than once an hour :)

                                    Bottom of the log file:
                                    ====================[ DNSBL Last Updated List Summary ]==============

                                    Nov 29 00:00 StevenBlack_ADs

                                    Database Sanity check [ PASSED ]

                                    Masterfile/Deny folder uniq check
                                    Deny folder/Masterfile uniq check

                                    Sync check (Pass=No IPs reported)

                                    Alias table IP Counts

                                    18754 total
                                    16397 /var/db/aliastables/pfB_PRI1_v4.txt
                                    1178 /var/db/aliastables/pfB_Allow_Hosting_Gateway_v4.txt
                                    1178 /var/db/aliastables/pfB_Allow_Hosting_Customers_v4.txt
                                    1 /var/db/aliastables/pfB_3CX_ServerPublic_v4.txt

                                    pfSense Table Stats

                                    table-entries hard limit 400000
                                    Table Usage Count 159353

                                    UPDATE PROCESS ENDED [ 12/7/22 13:03:18 ]

                                    GertjanG 1 Reply Last reply Reply Quote 0
                                    • GertjanG
                                      Gertjan @ksh
                                      last edited by Gertjan

                                      @ksh

                                      You didn't show what I've showed you.
                                      The part with the dates and hour.

                                      I've tricked my pfblockerng-devel by forcing it to download the lists again.
                                      I've deleted all the files in /var/db/pfblockerng/dnsblorig/
                                      Then I did a force reload.
                                      It showed :

                                      ====================[ DNSBL Last Updated List Summary ]==============
                                      
                                      Dec 7	13:37	UT1_gambling
                                      Dec 7	13:37	UT1_games
                                      Dec 7	13:37	UT1_phishing
                                      Dec 7	13:37	UT1_warez
                                      Dec 7	13:37	StevenBlack_ADs
                                      ===============================================================
                                      

                                      Done ;)

                                      No "help me" PM's please. Use the forum, the community will thank you.
                                      Edit : and where are the logs ??

                                      K 1 Reply Last reply Reply Quote 0
                                      • K
                                        ksh @Gertjan
                                        last edited by

                                        @gertjan
                                        So this one?
                                        ====================[ IPv4/6 Last Updated List Summary ]==============

                                        Nov 10 03:53 Spamhaus_eDrop_v4
                                        Nov 29 05:18 Spamhaus_Drop_v4
                                        Nov 29 06:30 ET_Block_v4
                                        Nov 29 23:16 ET_Comp_v4
                                        Nov 30 06:00 Talos_BL_v4
                                        Nov 30 12:50 ISC_Block_v4
                                        Nov 30 13:18 CINS_army_v4
                                        Nov 30 14:00 Abuse_SSLBL_v4
                                        Nov 30 14:00 Abuse_Feodo_C2_v4
                                        Nov 30 14:00 CompusoftCustomers_v4
                                        Dec 7 13:03 3CX_ServerPublic_custom_v4

                                        GertjanG 1 Reply Last reply Reply Quote 0
                                        • GertjanG
                                          Gertjan @ksh
                                          last edited by

                                          @ksh

                                          Yep.
                                          Rookie mode : Delete them all - and sync pfblocker
                                          Better be safe then sorry : copy them on a safe place and then delete them all, and sync pfblocker

                                          Btw : Dec 7 13:03 3CX_ServerPublic_custom_v4 (your own list ?) seems recent enough.

                                          Other lists : if they didn't changed, they won't get downloaded (I guess ?!)

                                          No "help me" PM's please. Use the forum, the community will thank you.
                                          Edit : and where are the logs ??

                                          K 1 Reply Last reply Reply Quote 0
                                          • K
                                            ksh @Gertjan
                                            last edited by ksh

                                            @gertjan
                                            I removed the list. And added it again. This works.
                                            But if i go and add an IP to the list an run the job it doesn't get updated :/

                                            There should be 1278 and 1276 in /var/db/aliastables/pfB_Allow_Hosting_Customers_v4.txt

                                            I can also see that it seems like it doesn't get updated from when i create it to i update it.
                                            But my 3CX_ServerPublic_custom_v4 seems to be updated everytime. This is an Alias Native. and not a list.

                                            ====================[ IPv4/6 Last Updated List Summary ]==============

                                            Nov 10 03:53 Spamhaus_eDrop_v4
                                            Nov 29 05:18 Spamhaus_Drop_v4
                                            Nov 29 06:30 ET_Block_v4
                                            Nov 29 23:16 ET_Comp_v4
                                            Nov 30 06:00 Talos_BL_v4
                                            Nov 30 12:50 ISC_Block_v4
                                            Nov 30 13:18 CINS_army_v4
                                            Nov 30 14:00 Abuse_SSLBL_v4
                                            Nov 30 14:00 Abuse_Feodo_C2_v4
                                            Dec 7 21:21 CustomersGateway_v4
                                            Dec 7 21:23 CompusoftCustomers_v4
                                            Dec 7 21:35 3CX_ServerPublic_custom_v4

                                            ====================[ DNSBL Last Updated List Summary ]==============

                                            Nov 29 00:00 StevenBlack_ADs

                                            Database Sanity check [ PASSED ]

                                            Masterfile/Deny folder uniq check
                                            Deny folder/Masterfile uniq check

                                            Sync check (Pass=No IPs reported)

                                            Alias table IP Counts

                                            20550 total
                                            17997 /var/db/aliastables/pfB_PRI1_v4.txt
                                            1276 /var/db/aliastables/pfB_Allow_Hosting_Gateway_v4.txt
                                            1276 /var/db/aliastables/pfB_Allow_Hosting_Customers_v4.txt
                                            1 /var/db/aliastables/pfB_3CX_ServerPublic_v4.txt

                                            pfSense Table Stats

                                            table-entries hard limit 400000
                                            Table Usage Count 161000

                                            UPDATE PROCESS ENDED [ 12/7/22 21:35:30 ]

                                            GertjanG 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.