Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNSBL stopped

    Scheduled Pinned Locked Moved General pfSense Questions
    10 Posts 3 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mrjoli021
      last edited by

      I have upgrade to version 2.6.0 and after the upgrade PFBlockerNG DNSBL has stopped working. I get the error:
      (Python mode) is disabled with errors!
      review py_error.log

      When I look at that log file it is empty. Not sure where to go from here. Please help.

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Your other post showed you're using the DNS Forwarder (dnsmasq) but DNS-BL is only compatible with the DNS resolver (Unbound).
        Since this was working before can I assume you're actually running the resolver? Is this the same firewall?

        Is anything shown in the DNS logs?

        Steve

        M 1 Reply Last reply Reply Quote 0
        • M
          mrjoli021 @stephenw10
          last edited by

          @stephenw10
          Yes, Sorry I am running resolver not forwarder. The resolver is the one giving me the issue as well as the DSN-BL. The logs are emtpy no issues found, but I am getting the python mode error on the DNS-BL.

          GertjanG 1 Reply Last reply Reply Quote 0
          • stephenw10S stephenw10 referenced this topic on
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            Ok I'll close the other ticket, let's continue here.

            So does Unbound stop if you disable DNS-BL?

            Do you see any errors if you run an update in pfBlocker?

            Steve

            1 Reply Last reply Reply Quote 0
            • GertjanG
              Gertjan @mrjoli021
              last edited by

              @mrjoli021 said in DNSBL stopped:

              . The logs are emtpy no issues found, but I am getting the python mode error on the DNS-BL.

              is not the same as

              @mrjoli021 said in DNSBL stopped:

              review py_error.log
              When I look at that log file it is empty.

              can you Diagnostics > Command Prompt: :

              ls -al /var/log/pfblockerng/py_error.log
              

              2bdad3b9-4cc2-4efa-b285-e783b435ab89-image.png

              You did a Firewall > pfBlockerNG > Update
              Reload : All

              ?

              Show an image of the error ?

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              1 Reply Last reply Reply Quote 0
              • M
                mrjoli021
                last edited by mrjoli021

                @gertjan said in DNSBL stopped:

                ls -al /var/log/pfblockerng/py_error.log

                Hello,

                I was able to cat the file and this is the output.

                04198e7d-b324-4f3e-a5b2-a480cc80fe90-image.jpeg

                I have checked and I dont have DHCP options enabled. I did at one point, but since have restarted the firewall, updated the pfBlockerNG and reloaded it. I have also restarted the resolver multiple times (every time it crashes).

                cf1a9652-d6f8-4f0e-a26d-34acf588bf25-image.jpeg

                GertjanG 1 Reply Last reply Reply Quote 0
                • GertjanG
                  Gertjan @mrjoli021
                  last edited by

                  @mrjoli021 said in DNSBL stopped:

                  I was able to cat the file and this is the output.

                  Then empty it :

                  eddd0e95-df6a-4aac-9fe8-d3ac37b2e790-image.png

                  Ok to use the forward mode (but why ?) :

                  6f14491d-dd59-47ad-a9a7-0ae8fdfe1b20-image.png

                  If you want to use forward mode with TLS, it uses port 853 on the remote DNS servers, you have to set up these services correctly.
                  And just must be sure that the DNS server you forward to support DNS over TLS.

                  For example :

                  f4dd835b-74b1-46ee-8aed-894c52bad0df-image.png

                  "one.one.one.one" is the host name of 1.1.1.1 - one.one.one.one is one of the CN present in the certificate of 1.1.1.1, remember, this is TLS.
                  Likewise, "dns.google" is the host name of 8.8.8.8

                  @mrjoli021 said in DNSBL stopped:

                  (every time it crashes)

                  Strange. Unbound, the resolver never crashes on me.
                  I'm using the default settings, I'm not forwarding (why should I ?) maybe that helps ;)

                  No "help me" PM's please. Use the forum, the community will thank you.
                  Edit : and where are the logs ??

                  1 Reply Last reply Reply Quote 0
                  • GertjanG Gertjan referenced this topic on
                  • GertjanG Gertjan referenced this topic on
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    There's pretty much no point enabling DNSSec in forwarding mode. But that wouldn't cause it to stop.
                    What's in the Resolver logs?

                    M 1 Reply Last reply Reply Quote 0
                    • M
                      mrjoli021 @stephenw10
                      last edited by

                      @stephenw10
                      This is what is in the resolver logs. I am using quad9 as my DNS.

                      df262bf5-e4b0-4202-8509-410070c44844-image.jpeg

                      M 1 Reply Last reply Reply Quote 0
                      • M
                        mrjoli021 @mrjoli021
                        last edited by

                        @mrjoli021

                        Issue has been resolved. Once I removed the DNSSec setting PfBlockerNG started up and so far Resolver has not crashed.

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.