Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfBlockerng 3.1.0.9 error - does not save Custom DST Port alias

    Scheduled Pinned Locked Moved pfBlockerNG
    22 Posts 8 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cjbujold
      last edited by

      Not using "Any" using TCP only and Alias will not stay.

      BBcan177B 1 Reply Last reply Reply Quote 2
      • BBcan177B
        BBcan177 Moderator @cjbujold
        last edited by

        @cjbujold ok I will check it out. Thanks.

        "Experience is something you don't get until just after you need it."

        Website: http://pfBlockerNG.com
        Twitter: @BBcan177  #pfBlockerNG
        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

        1 Reply Last reply Reply Quote 1
        • C
          cjbujold
          last edited by

          Rebooted PFsense and getting this error if this can help.

          There were error(s) loading the rules: /tmp/rules.debug:299: macro 'pfB_WhiteList_v4' not defined - The line in question reads [299]: block log quick on { igb0 } inet proto tcp from $pfB_WhiteList_v4 to any ridentifier 1770009684 flags S/SA label "USER_RULE: pfB_WhiteList_v4 auto rule" label "id:1770009684"
          @ 2022-12-28 10:57:44

          1 Reply Last reply Reply Quote 0
          • Bob.DigB
            Bob.Dig LAYER 8
            last edited by Bob.Dig

            Today I also hit this. No port is saved and that is kinda problematic. I will have to turn off logging for that rule to not get flooded.


            Screenshot 2023-01-01 at 12-07-10 pfSense.home.arpa - Firewall pfBlockerNG IP IPv4.png

            BBcan177B Bob.DigB 2 Replies Last reply Reply Quote 0
            • BBcan177B
              BBcan177 Moderator @Bob.Dig
              last edited by

              @bob-dig @cjbujold

              See the patch here and report back pls.

              From the Shell or pfSense GUI > Diagnostics > Command Prompt > Execute Shell Command, run this command to download the patch.

              curl -o /usr/local/www/pfblockerng/pfblockerng_category_edit.php "https://gist.githubusercontent.com/BBcan177/1a33c42d0a61f3ddd9c2f1b1d514ed83/raw"

              "Experience is something you don't get until just after you need it."

              Website: http://pfBlockerNG.com
              Twitter: @BBcan177  #pfBlockerNG
              Reddit: https://www.reddit.com/r/pfBlockerNG/new/

              Bob.DigB 1 Reply Last reply Reply Quote 4
              • Bob.DigB
                Bob.Dig LAYER 8 @BBcan177
                last edited by

                @bbcan177 said in PfBlockerng 3.1.0.9 error - does not save Custom DST Port alias:

                See the patch here and report back pls.

                Thanks @BBcan177 , that has fixed it for me!

                1 Reply Last reply Reply Quote 0
                • T
                  tman222
                  last edited by

                  Happy to report as well that the patch above resolved the issue with the Custom DST Port entry not saving under Advanced Inbound Firewall Rule Settings. Thanks @BBcan177 for the quick fix.

                  1 Reply Last reply Reply Quote 0
                  • A
                    aumuelle
                    last edited by

                    patch fixed it for entries in ipv4 - but not for geoip
                    anyone else seeing this?

                    BBcan177B 1 Reply Last reply Reply Quote 0
                    • BBcan177B
                      BBcan177 Moderator @aumuelle
                      last edited by

                      @aumuelle I will address that also. Ran out of time today

                      "Experience is something you don't get until just after you need it."

                      Website: http://pfBlockerNG.com
                      Twitter: @BBcan177  #pfBlockerNG
                      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                      B 1 Reply Last reply Reply Quote 3
                      • T
                        Tzvia
                        last edited by

                        @bbcan177 said in PfBlockerng 3.1.0.9 error - does not save Custom DST Port alias:

                        curl -o /usr/local/www/pfblockerng/pfblockerng_category_edit.php "https://gist.githubusercontent.com/BBcan177/1a33c42d0a61f3ddd9c2f1b1d514ed83/raw"

                        Working here- input my port-alias and the setting stuck- and the REPORTS/ALERTS calmed down and I am only seeing inbound alerts on the ports listed in my alias.

                        Tzvia

                        Current build:
                        Hunsn/CWWK Pentium Gold 8505, 6x i226v 'micro firewall'
                        16 gigs ram
                        500gig WD Blue nvme
                        Using modded BIOS (enabled CSTATES)
                        PFSense 2.72-RELEASE
                        Enabled Intel SpeedShift
                        Snort
                        PFBlockerNG
                        LAN and 5 VLANS

                        1 Reply Last reply Reply Quote 0
                        • C
                          cjbujold
                          last edited by

                          That fixed the issue, Thanks

                          1 Reply Last reply Reply Quote 0
                          • L
                            lsarakinos
                            last edited by

                            Thank you @BBcan177
                            Patch fixed the problem

                            1 Reply Last reply Reply Quote 0
                            • Bob.DigB
                              Bob.Dig LAYER 8 @Bob.Dig
                              last edited by Bob.Dig

                              @bob-dig said in PfBlockerng 3.1.0.9 error - does not save Custom DST Port alias:

                              Today I also hit this. No port is saved and that is kinda problematic. I will have to turn off logging for that rule to not get flooded.


                              Screenshot 2023-01-01 at 12-07-10 pfSense.home.arpa - Firewall pfBlockerNG IP IPv4.png

                              @BBcan177 Today I had the impression that rsync downloads don't work. I switched to auto and gave a regular http-address and the list got updated again. I don't know where the problem lies, could be up to them (uceprotect) and is not related to the topic about ports at all! Just to let you know... Rsync doesn't seem to be that necessary anyways.

                              BBcan177B 1 Reply Last reply Reply Quote 0
                              • BBcan177B
                                BBcan177 Moderator @Bob.Dig
                                last edited by

                                @bob-dig what is the URL that you use for that feed?

                                "Experience is something you don't get until just after you need it."

                                Website: http://pfBlockerNG.com
                                Twitter: @BBcan177  #pfBlockerNG
                                Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                                Bob.DigB 1 Reply Last reply Reply Quote 0
                                • Bob.DigB
                                  Bob.Dig LAYER 8 @BBcan177
                                  last edited by Bob.Dig

                                  @bbcan177
                                  rsync-mirrors.uceprotect.net::RBLDNSD-ALL/dnsbl-1.uceprotect.net
                                  rsync-mirrors.uceprotect.net::RBLDNSD-ALL/dnsbl-2.uceprotect.net

                                  But with (auto) those did it:
                                  http://wget-mirrors.uceprotect.net/rbldnsd-all/dnsbl-1.uceprotect.net.gz
                                  http://wget-mirrors.uceprotect.net/rbldnsd-all/dnsbl-2.uceprotect.net.gz

                                  This IP was buggen me: 195.133.40.188

                                  BBcan177B 1 Reply Last reply Reply Quote 0
                                  • BBcan177B
                                    BBcan177 Moderator @Bob.Dig
                                    last edited by

                                    @bob-dig said in PfBlockerng 3.1.0.9 error - does not save Custom DST Port alias:

                                    rsync-mirrors.uceprotect.net::RBLDNSD-ALL/dnsbl-1.uceprotect.net
                                    rsync-mirrors.uceprotect.net::RBLDNSD-ALL/dnsbl-2.uceprotect.net

                                    They seem ok with my tests? Do you see any errors in the error.log? What happens when you ping rsync-mirrors.uceprotect.net?

                                    "Experience is something you don't get until just after you need it."

                                    Website: http://pfBlockerNG.com
                                    Twitter: @BBcan177  #pfBlockerNG
                                    Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                                    Bob.DigB 1 Reply Last reply Reply Quote 0
                                    • Bob.DigB
                                      Bob.Dig LAYER 8 @BBcan177
                                      last edited by

                                      @bbcan177 said in PfBlockerng 3.1.0.9 error - does not save Custom DST Port alias:

                                      Do you see any errors in the error.log? What happens when you ping rsync-mirrors.uceprotect.net?

                                      Sry, I don't even know where to look at what... I am a noob for the most part. I only know that it has worked before and, maybe, after the "patch" from here, rsync didn't worked anymore, presumably. Or it was just a coincidence.

                                      1 Reply Last reply Reply Quote 0
                                      • B
                                        bladezpro
                                        last edited by

                                        Hey the patch fixed the issue port alias not saving for IPv4 but not for the GeoIP rules. Anyone have luck with that?

                                        1 Reply Last reply Reply Quote 0
                                        • B
                                          bladezpro @BBcan177
                                          last edited by

                                          @bbcan177 Hey thanks for your efforts, any luck with the patch specific to saving port alias for Geo IP as well.

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.