Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    pfBlockerNG-devel v3.1.0_19/10

    pfBlockerNG
    15
    52
    1444
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • BBcan177
      BBcan177 Moderator @smoke_a_J last edited by

      @smoke_a_j said in pfBlockerNG-devel v3.1.0_19/10:

      DNSBL Source Definitions, Line 1: Invalid URL or Hostname not resolvable!

      Either DNS isn't working on your box or something is blocking those urls.

      "Experience is something you don't get until just after you need it."

      Website: http://pfBlockerNG.com
      Twitter: @BBcan177  #pfBlockerNG
      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

      S 1 Reply Last reply Reply Quote 0
      • BBcan177
        BBcan177 Moderator @yorke last edited by

        @yorke I would backup you config and install a fresh copy of pfSense. Followed by a restore of the config.

        "Experience is something you don't get until just after you need it."

        Website: http://pfBlockerNG.com
        Twitter: @BBcan177  #pfBlockerNG
        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

        Y 1 Reply Last reply Reply Quote 0
        • S
          smoke_a_J @BBcan177 last edited by

          @bbcan177 Gracias, at first I thought it was seeming similar to the inbound permit saving issue. Regardless of having most of these feeds already whitelisted, tracked it down to about 1500 some lines of regex I had came across and added a while back, most of which seemed to not be populating any alerts but invisibly blocking at random until matching the suffix/prefix portions of the code to match known alerting lines started populating the rest. I trimmed out 1300 lines to whats working, I then realized the entire 1500 lines I found were basically a reflection of the DNSBL TLD Group 1 & 2 lists. Went back to just my first 680 lines of regex and no more ghosted double filtering and running smooth

          BBcan177 1 Reply Last reply Reply Quote 0
          • BBcan177
            BBcan177 Moderator @smoke_a_J last edited by

            @smoke_a_j If you can pm or email that regex list, I can check it out to see if there is some code improvement required.

            "Experience is something you don't get until just after you need it."

            Website: http://pfBlockerNG.com
            Twitter: @BBcan177  #pfBlockerNG
            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

            1 Reply Last reply Reply Quote 0
            • N
              nimrod @yorke last edited by

              @yorke said in pfBlockerNG-devel v3.1.0_19/10:

              @bbcan177

              pfBlockerNG-devel 3.1.0_11 |ERROR| python module 'maxminddb
              Pfsense 2.6.0-RELEASE
              I upgraded pfBlockerNG-devel to 3.1.0_11 and got some issue before i upgraded everyting was work but now after the upgrade I am geting the errors listed below,
              2023-01-20 18:16:12,627|ERROR| [pfBlockerNG]: Failed to load python module 'maxminddb': No module named 'maxminddb'
              2023-01-20 18:16:12,627|ERROR| [pfBlockerNG]: Failed to load python module 'sqlite3': No module named '_sqlite3'

              I got the same error on pfSense v2.6.0 since the upgrade to pfBlockerNG v3.1.0_11. I have cleared the error in py_error.log. Lets see if it comes back.

              The report tab showns traffic being pass/block
              the dashboard for DNSBL the packets stay at 0 the counter do not move, but the ip counter works

              Same issue with IP Counter. It shows number of blocked IPs for a while, but when you refresh the page, counter goes to 0. This issue happens if you apply this patch via system patches package.

              ba6d96ea-1a8f-448b-be68-285c6e8d6a4d-image.png

              More details here.

              If you revert this change, counter starts working as it should and it doesnt reset to 0 after some time.

              1 Reply Last reply Reply Quote 0
              • D
                Draco @BBcan177 last edited by Draco

                @bbcan177 said in pfBlockerNG-devel v3.1.0_19/10:

                Add "application/json" to list of allowed file download mime-types

                I had hoped this might let pfBlocker directly download a JSON list like the one found at Microsoft Azure IPs. This is a file I manually download and then use pfSense's GUI CMD interface to upload for pfBlocker (I set the format to AUTO). Ran this on 3.1.0_11 just now.

                It didn't work. So what JSON-related things were enabled with this change?

                Thanks!

                N BBcan177 2 Replies Last reply Reply Quote 0
                • N
                  nimrod @Draco last edited by

                  It happened again after after update.

                  39063a17-dfca-4dcd-a76c-2419e8b11441-image.png

                  This is the content of py_error.log

                  2023-01-24 16:36:57,206|ERROR| [pfBlockerNG]: Failed to load python module 'maxminddb': No module named 'maxminddb'
                  2023-01-24 16:36:57,206|ERROR| [pfBlockerNG]: Failed to load python module 'sqlite3': No module named '_sqlite3'
                  

                  Despite these errors, everything is working fine.

                  cmcdonald 1 Reply Last reply Reply Quote 0
                  • cmcdonald
                    cmcdonald Netgate Developer @nimrod last edited by cmcdonald

                    @nimrod

                    What is the output of:

                    pkg info py* unbound

                    Need help fast? https://www.netgate.com/support

                    R 1 Reply Last reply Reply Quote 0
                    • R
                      renegade @cmcdonald last edited by

                      @cmcdonald
                      Same problem on my side.

                      [22.05-RELEASE][admin@firewall.home]/root: pkg info py* unbound
                      pkg: No match.

                      cmcdonald 1 Reply Last reply Reply Quote 0
                      • cmcdonald
                        cmcdonald Netgate Developer @renegade last edited by

                        @renegade

                        Sorry, try this:

                        pkg info "py*" unbound

                        Need help fast? https://www.netgate.com/support

                        N 1 Reply Last reply Reply Quote 0
                        • N
                          nimrod @cmcdonald last edited by

                          @cmcdonald said in pfBlockerNG-devel v3.1.0_19/10:

                          @renegade

                          Sorry, try this:

                          pkg info "py*" unbound

                          Here it is:

                          [2.6.0-RELEASE][admin@pfSense.home.arpa]/root: pkg info "py*" unbound
                          py38-ply-3.11
                          py38-setuptools-57.0.0
                          py39-maxminddb-2.0.3
                          py39-setuptools-57.0.0
                          py39-sqlite3-3.9.9_7
                          python38-3.8.12_1
                          python39-3.9.9
                          unbound-1.13.2
                          
                          
                          cmcdonald 2 Replies Last reply Reply Quote 0
                          • cmcdonald
                            cmcdonald Netgate Developer @nimrod last edited by

                            @nimrod Thanks. I see the problem. Testing a fix. Standby

                            Need help fast? https://www.netgate.com/support

                            1 Reply Last reply Reply Quote 2
                            • cmcdonald
                              cmcdonald Netgate Developer @nimrod last edited by

                              @nimrod can you also share pkg info unbound ?

                              Need help fast? https://www.netgate.com/support

                              N 1 Reply Last reply Reply Quote 0
                              • N
                                nimrod @cmcdonald last edited by

                                @cmcdonald said in pfBlockerNG-devel v3.1.0_19/10:

                                @nimrod can you also share pkg info unbound ?

                                Of course. Here it is:

                                [2.6.0-RELEASE][admin@pfSense.home.arpa]/root: pkg info unbound
                                unbound-1.13.2
                                Name           : unbound
                                Version        : 1.13.2
                                Installed on   : Mon Jan 31 21:24:27 2022 CET
                                Origin         : dns/unbound
                                Architecture   : FreeBSD:12:amd64
                                Prefix         : /usr/local
                                Categories     : dns
                                Licenses       : BSD3CLAUSE
                                Maintainer     : jaap@NLnetLabs.nl
                                WWW            : https://www.nlnetlabs.nl/projects/unbound
                                Comment        : Validating, recursive, and caching DNS resolver
                                Options        :
                                	DEP-RSA1024    : off
                                	DNSCRYPT       : off
                                	DNSTAP         : off
                                	DOCS           : off
                                	DOH            : on
                                	ECDSA          : on
                                	EVAPI          : off
                                	FILTER_AAAA    : off
                                	GOST           : on
                                	HIREDIS        : off
                                	LIBEVENT       : on
                                	MUNIN_PLUGIN   : off
                                	PYTHON         : on
                                	SUBNET         : off
                                	TFOCL          : off
                                	TFOSE          : off
                                	THREADS        : on
                                Shared Libs required:
                                	libexpat.so.1
                                	libnghttp2.so.14
                                	libpython3.8.so.1.0
                                	libevent-2.1.so.7
                                Shared Libs provided:
                                	libunbound.so.8
                                Annotations    :
                                	FreeBSD_version: 1203500
                                	build_timestamp: 2022-01-12T15:27:10+0000
                                	built_by       : poudriere-git-3.3.99.20211130
                                	cpe            : cpe:2.3:a:nlnetlabs:unbound:1.13.2:::::freebsd12:x64
                                	port_checkout_unclean: no
                                	port_git_hash  : 8df9544dcbab
                                	ports_top_checkout_unclean: yes
                                	ports_top_git_hash: 7046b65c0d41
                                	repo_type      : binary
                                	repository     : pfSense
                                Flat size      : 7.99MiB
                                Description    :
                                Unbound is designed as a set of modular components, so that also
                                DNSSEC (secure DNS) validation and stub-resolvers (that do not run as
                                a server, but are linked into an application) are easily possible.
                                
                                Goals:
                                    * A validating recursive DNS resolver.
                                    * Code diversity in the DNS resolver monoculture.
                                    * Drop-in replacement for BIND apart from config.
                                    * DNSSEC support.
                                    * Fully RFC compliant.
                                    * High performance, even with validation enabled.
                                    * Used as: stub resolver, full caching name server, resolver library.
                                    * Elegant design of validator, resolver, cache modules.
                                          o provide the ability to pick and choose modules.
                                    * Robust.
                                    * In C, open source: The BSD license.
                                    * Smallest as possible component that does the job.
                                    * Stub-zones can be configured (local data or AS112 zones).
                                
                                Non-goals:
                                    * An authoritative name server.
                                    * Too many Features.
                                
                                WWW: https://www.nlnetlabs.nl/projects/unbound
                                
                                
                                cmcdonald 1 Reply Last reply Reply Quote 1
                                • cmcdonald
                                  cmcdonald Netgate Developer @nimrod last edited by

                                  @nimrod Can you now try reinstalling pfBlockerNG-devel on 22.05/2.6, and repeat the above command pkg info "py*" unbound

                                  Need help fast? https://www.netgate.com/support

                                  N 1 Reply Last reply Reply Quote 0
                                  • N
                                    nimrod @cmcdonald last edited by

                                    @cmcdonald said in pfBlockerNG-devel v3.1.0_19/10:

                                    @nimrod Can you now try reinstalling pfBlockerNG-devel on 22.05/2.6, and repeat the above command pkg info "py*" unbound

                                    I reinstalled it and here is the output:

                                    [2.6.0-RELEASE][admin@pfSense.home.arpa]/root: pkg info "py*" unbound
                                    py38-maxminddb-2.0.3
                                    py38-ply-3.11
                                    py38-setuptools-57.0.0
                                    py38-sqlite3-3.8.12_7
                                    py39-maxminddb-2.0.3
                                    py39-setuptools-57.0.0
                                    py39-sqlite3-3.9.9_7
                                    python38-3.8.12_1
                                    python39-3.9.9
                                    unbound-1.13.2
                                    
                                    
                                    cmcdonald 1 Reply Last reply Reply Quote 0
                                    • cmcdonald
                                      cmcdonald Netgate Developer @nimrod last edited by

                                      @nimrod That should be correct now. Clear the unbound errors and try again.

                                      Need help fast? https://www.netgate.com/support

                                      N 1 Reply Last reply Reply Quote 2
                                      • N
                                        nimrod @cmcdonald last edited by

                                        @cmcdonald said in pfBlockerNG-devel v3.1.0_19/10:

                                        @nimrod That should be correct now. Clear the unbound errors and try again.

                                        Yup. That fixed it. Thank you sir.

                                        12cce7f0-7c98-4539-a20f-05db798050ae-image.png

                                        1 Reply Last reply Reply Quote 1
                                        • BBcan177
                                          BBcan177 Moderator @Draco last edited by

                                          @draco said in pfBlockerNG-devel v3.1.0_19/10:

                                          I had hoped this might let pfBlocker directly download a JSON list like the one found at Microsoft Azure IPs. This is a file I manually download and then use pfSense's GUI CMD interface to upload for pfBlocker (I set the format to AUTO). Ran this on 3.1.0_11 just now.

                                          The Link you posted is the HTML page. You need to use the direct link:

                                          https://download.microsoft.com/download/7/1/D/71D86715-5596-4529-9B13-DA13A5DE5B63/ServiceTags_Public_20230123.json

                                          Keep in mind that this will parse all IPs in the json file. You could also create a new shell script to parse this JSON and get more refinement on which IPs to pull ( "Advanced Tunables - Post-Script Script" feature.)

                                          "Experience is something you don't get until just after you need it."

                                          Website: http://pfBlockerNG.com
                                          Twitter: @BBcan177  #pfBlockerNG
                                          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                                          1 Reply Last reply Reply Quote 0
                                          • Y
                                            yorke @BBcan177 last edited by

                                            @bbcan177

                                            I figure out why i was getting those errors some package/feature on pfsense needed to be update (ie unbound and about 4 others ) once I ran the update and reboot and reinstall
                                            PfblockerNG work, no more errors.
                                            Thanks BBcan177

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post