<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[First run pfBlockerNG - false positive?]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I just installed pfBlockerNG, and almost immediately my firewall caught my media player which tried to reach 10.10.10.1:443, which is the pfBlockerNG's DNSBL Webserver Virtual IP Address...</p>
<p dir="auto">Destination seems to have been <code>app-measurement.com</code> Whatever that may be...</p>
<p dir="auto">I probably get this wrong, but could this make sense?</p>
<ul>
<li>media player tried to go to <code>app-measurement.com</code> and pfBlockerNG caught that and wanted to dispose of the attempt</li>
<li>but as I block anything I don't accept, it failed?</li>
</ul>
<p dir="auto">So what would the correct action here be? Should I allow anything to this Virtual IP (guess used as a a sinkhole?)?</p>
<p dir="auto">Thanks</p>
]]></description><link>https://forum.netgate.com/topic/178318/first-run-pfblockerng-false-positive</link><generator>RSS for Node</generator><lastBuildDate>Tue, 14 Apr 2026 18:44:13 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/178318.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 26 Feb 2023 17:17:52 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to First run pfBlockerNG - false positive? on Mon, 27 Feb 2023 15:36:59 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>gertjan</bdi></a> said in <a href="/post/1090778">First run pfBlockerNG - false positive?</a>:</p>
<blockquote>
<p dir="auto">But you, as the admin, have added dnsbl feeds (or IP feeds) to pfBlockerng.<br />
Hostnames (or IP's) in these feeds will get blocked.<br />
Did you have a look at these lists ? ;)</p>
</blockquote>
<p dir="auto">Thank you for a nice and informative answer! I will try with the address you suggest, and no... I have not looked at the lists in detail, but looks like a good idea to get a better understandning of this... :)</p>
]]></description><link>https://forum.netgate.com/post/1090894</link><guid isPermaLink="true">https://forum.netgate.com/post/1090894</guid><dc:creator><![CDATA[furom]]></dc:creator><pubDate>Mon, 27 Feb 2023 15:36:59 GMT</pubDate></item><item><title><![CDATA[Reply to First run pfBlockerNG - false positive? on Mon, 27 Feb 2023 07:43:31 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/furom">@<bdi>furom</bdi></a> said in <a href="/post/1090625">First run pfBlockerNG - false positive?</a>:</p>
<blockquote>
<p dir="auto">media player tried to go to app-measurement.com and pfBlockerNG caught that and wanted to dispose of the attempt</p>
</blockquote>
<p dir="auto">Exact.</p>
<p dir="auto">Disable pfBlockerng, and then 'ask' what IPv4 'app-measurement.com' has.<br />
You'll see, it exists.</p>
<p dir="auto">When I ask what 'app-measurement.com' I get a solid :</p>
<pre><code>[23.01-RELEASE][admin@pfSense.closetome.tld]/root: host app-measurement.com
app-measurement.com has address 0.0.0.0
Host app-measurement.com not found: 2(SERVFAIL)
</code></pre>
<p dir="auto">This means that 'app-measurement.com' was on some list/feed that I let pfBlockerng use.</p>
<p dir="auto">Btw 0.0.0.0 a dn not 10.10.10.1 because the virtual IP coupled with a web browser telling you that the site you try to visit just don't work.<br />
Ok, it works ... but only for http:// visist, and who does http:// these day ? Nobody.<br />
https:// visits with a web browser will show a browser depending page telling the browser user that a very complicated error has arrived. And certainly <strong>not</strong> the pfBlocker web server page telling the suer the URL/jhostname in question has been blocked;<br />
So, my advise, select "0.0.0.0 = null logging" everywhere, don't bother using this one :</p>
<p dir="auto"><img src="/assets/uploads/files/1677483660476-9da398a3-b5c8-4f1a-9a99-9ec0a9942d5d-image.png" alt="9da398a3-b5c8-4f1a-9a99-9ec0a9942d5d-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/furom">@<bdi>furom</bdi></a> said in <a href="/post/1090625">First run pfBlockerNG - false positive?</a>:</p>
<blockquote>
<p dir="auto">but as I block anything I don't accept, it failed?</p>
</blockquote>
<p dir="auto">You, and pfBlockerng, did nothing.<br />
But you, as the admin, have added dnsbl feeds (or IP feeds) to pfBlockerng.<br />
Hostnames (or IP's) in these feeds will get blocked.<br />
Did you have a look at these lists ? ;)</p>
]]></description><link>https://forum.netgate.com/post/1090778</link><guid isPermaLink="true">https://forum.netgate.com/post/1090778</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Mon, 27 Feb 2023 07:43:31 GMT</pubDate></item><item><title><![CDATA[Reply to First run pfBlockerNG - false positive? on Sun, 26 Feb 2023 18:56:37 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/furom">@<bdi>furom</bdi></a> Up to you, if you want users to see that warning page.</p>
]]></description><link>https://forum.netgate.com/post/1090651</link><guid isPermaLink="true">https://forum.netgate.com/post/1090651</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Sun, 26 Feb 2023 18:56:37 GMT</pubDate></item><item><title><![CDATA[Reply to First run pfBlockerNG - false positive? on Sun, 26 Feb 2023 18:07:19 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/steveits">@<bdi>steveits</bdi></a> said in <a href="/post/1090636">First run pfBlockerNG - false positive?</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/furom">@<bdi>furom</bdi></a> the  pfBlocker IP shows an error/info page for http (or a cert error for https). I believe you can turn that off and have it go nowhere if you want.</p>
</blockquote>
<p dir="auto">I actually got no such thing. I guess because I am not permitting the Vitual IP...? So should I let it connect to the virtual ip or not?</p>
]]></description><link>https://forum.netgate.com/post/1090640</link><guid isPermaLink="true">https://forum.netgate.com/post/1090640</guid><dc:creator><![CDATA[furom]]></dc:creator><pubDate>Sun, 26 Feb 2023 18:07:19 GMT</pubDate></item><item><title><![CDATA[Reply to First run pfBlockerNG - false positive? on Sun, 26 Feb 2023 17:58:13 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/furom">@<bdi>furom</bdi></a> the  pfBlocker IP shows an error/info page for http (or a cert error for https). I believe you can turn that off and have it go nowhere if you want.</p>
]]></description><link>https://forum.netgate.com/post/1090636</link><guid isPermaLink="true">https://forum.netgate.com/post/1090636</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Sun, 26 Feb 2023 17:58:13 GMT</pubDate></item></channel></rss>