Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlockerNG-devel v3.1.0_1 - Not able to download Talos Feeds

    Scheduled Pinned Locked Moved pfBlockerNG
    5 Posts 5 Posters 776 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      bdorr1105
      last edited by

      I just upgraded to pfSense version 2.6.0-RELEASE and when I went to update my feeds, I noticed that I get a 403 Forbidden error. I have seen this come up a few times in the forum, once for the curl agent and the other issue was because the user was not using the devel version. He was instructed to do that as the error or issue had already been addressed. Please see my screenshot. Thanks

      Talos.png

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @bdorr1105
        last edited by

        @bdorr1105

        bf8909b9-7fc2-42d9-9825-bcfa3a73c14e-image.png

        That's the one ?

        can you download it in a bowser.
        I've no troubles loading it.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        1 Reply Last reply Reply Quote 0
        • provelsP
          provels
          last edited by

          The Talos_BLlist

          https://talosintelligence.com/documents/ip-blacklist

          redirects to

          https://snort-org-site.s3.amazonaws.com/production/document_files/files/000/013/074/original/ip_filter.blf?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAU7AK5ITMGOEV4EFM%2F20220301%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20220301T120615Z&X-Amz-Expires=3600&X-Amz-SignedHeaders=host&X-Amz-Signature=b8e9271d7186545c7c3c2c4fed0a8124033fd1e6cf618b1b232be010bafbb074

          So maybe you're blocking amazonaws.com...?

          Peder

          MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
          BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

          JeGrJ 1 Reply Last reply Reply Quote 0
          • JeGrJ
            JeGr LAYER 8 Moderator @provels
            last edited by JeGr

            @provels Nah, don't think he actually is blocked by Amazon but we had multiple occurences of such things with lists hosted via AWS. Mostly the seem to intercept or tamper with downloads that have a "bot-like" useragent like e.g. curl.

            I have multiple devices running with different WAN lines and all of them seem to have trouble currently with that one blocklist for the last few days. Today they seem fine again, so pretty sure that is AWS tinkering with botfiltering again.

            Or it's the old Talos feed that now throws a 1020 error with cloudflare: https://www.talosintelligence.com/feeds/ip-filter.blf
            Then the fix is easy :)

            Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

            If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

            1 Reply Last reply Reply Quote 0
            • lohphatL
              lohphat
              last edited by

              I was seeing this too but now it's downloading it again.

              SG-3100 24.11-RELEASE (arm) | Avahi (2.2_6) | ntopng (5.6.0_1) | openvpn-client-export (1.9.5) | pfBlockerNG-devel (3.2.1_20) | System_Patches (2.2.20_5)

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.