Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlockerNG uninstalled and sites still blocked. Safe to delete remaining files?

    Scheduled Pinned Locked Moved pfBlockerNG
    8 Posts 2 Posters 619 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      booshwa
      last edited by

      I'm currently experiencing Google domain(s) and random tech sites being blocked on my network. As a last resort (after whitelisting and disabling dnsbl didn't revive the sites) I've uninstalled pfBlockerNG completely, however a few traces remain. I'm not familiar with BSD beyond the pfsense gui so wanted to confirm if the below files are safe to delete before doing so.

      /usr/local/www contains a pfblockerng folder with geoip files
      c7fd3c35-2a16-47d5-acde-2c885b8f9f01-image.png
      15fd5643-bec9-41b2-8e64-51100523000f-image.png

      The nested www folder contains what I'm guessing is the webpage.php thats supposed to be served when you've reached a blacklisted page
      525586d9-8772-4f64-bf28-2a60fb31a307-image.png

      There were also alias and cron stuff left over but doubt has play here and I removed via gui
      879fdb27-1bd3-4b83-b6a6-b9a41e2d5ebc-image.png
      8af1e21d-49f7-4738-b4cf-5a9eed1e1bb0-image.png

      As for the errors, Google/Youtube/etc are pingable and traceroute from wan makes 3 hops out before dying. ExpressVPN failing with an oddball 0.0.0.1. The sites are hit or miss depending on the vlan (direct ethernet connection to switch) I'm on. 2 being routed through WAN/spectrum, other 2 being through vpn gateway.
      04d011e8-81d6-4861-acee-93d66fa24d48-image.png
      03efa575-55db-42a8-aa16-e4f0c6ec33a2-image.png

      I tried looking for a dnsbl certificate on my mac but keychain is clear, safari doesn't give a certificate and chrome provides the below
      01065f30-e300-4a9d-a4c5-4e686b2bc2bf-image.png
      a4a7ea86-a09f-4294-8817-250e50ead0a0-image.png
      0829efb0-9e80-43a6-910e-56ecc54f722b-image.png

      S 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @booshwa
        last edited by

        @booshwa pfBlocker blocks by either firewall rules (visible in GUI) or DNS (nslookup). There is a checkbox to keep or remove pfB settings when uninstalling, which defaults to keep. You might reinstall then set that to remove everything.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote 👍 helpful posts!

        B 1 Reply Last reply Reply Quote 0
        • B
          booshwa @SteveITS
          last edited by

          @SteveITS Thanks for that, I originally unchecked the 'keep settings' checkbox which left the above. Reinstalling then uninstalling after unchecking the box still leaves /usr/local/www/pfsense and contents
          d1e2e41c-900c-46cd-a1a9-c60095922f8f-image.png
          7d629b9d-70d9-4aac-8ca6-6062c7835e86-image.png
          5764ebf3-62c7-4a82-9342-ec0018c7c4ea-image.png

          As for rules, they are more or less the same across the network with respect to gateways
          09954cbe-d5a5-4f22-a5b5-72ea27d7186a-image.png
          579ca7ac-63a6-43e1-a44b-ff2845664af7-image.png
          9d5be16c-b44e-4ca4-9946-88bff946e211-image.png
          176b501d-0d64-4f2e-9807-c4cb1e6126fd-image.png

          Unfortunately Google and others are still blocked after clearing cache and restarting DNS Resolver, though nslookup resolves and traceroute moves further up the chain when going from firewall
          5a217ab1-83d8-40f9-96c1-72b5cefea795-image.png
          0842c116-b565-4e03-b53d-369468d10357-image.png
          ee588493-06de-4ff7-b4da-027433c76631-image.png
          03b2a9ed-e7f3-4a3a-92b1-2b45db6df022-image.png
          2e80b62a-6db2-4676-b519-391eb823b6fb-image.png

          from a computer on VLAN10_HOME
          be590552-c27d-400a-b13f-1df0db530ad3-image.png

          I didn't mention my setup in the original post so doing that now
          Device: Netgate SG-5100
          OS: 23.05-RELEASE (amd64)
          pfBlockerNG-Devel version: 3.2.0_5

          • Also installed/uninstalled pfBlockerNG 3.2.0_5 separately but removed immediately with Keep Settings unchecked

          I upgraded from 23.01 last week in an attempt to install the newer pfBlockerNG and resolve these lingering problems

          S 1 Reply Last reply Reply Quote 0
          • S
            SteveITS Galactic Empire @booshwa
            last edited by

            @booshwa if it’s resolving to a correct IP and traffic exits your router it seems unlikely your firewall is blocking anything…?

            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
            Upvote 👍 helpful posts!

            B 1 Reply Last reply Reply Quote 0
            • B
              booshwa @SteveITS
              last edited by

              @SteveITS you are correct and admittedly this steps into areas of troubleshooting where I'm not familiar beyond clearing local cache.

              My next step for verifying cache problems on my mac was to restart DNS Resolver and start up a blank windows vm on a different vlan. After about 8 minutes the site finally loaded in the windows vm. My mac on VLAN10_HOME still not loading. Both gateways through ExpressVPN
              4769b8d1-b092-46ec-a125-0112f1e681f5-image.png

              Thanks for giving me some of your time! I'll keep plugging away

              S 1 Reply Last reply Reply Quote 0
              • S
                SteveITS Galactic Empire @booshwa
                last edited by

                @booshwa Loading after 8 minutes sounds like packet loss or routing problems to me. Try without the VPN?

                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                Upvote 👍 helpful posts!

                B 1 Reply Last reply Reply Quote 0
                • B
                  booshwa @SteveITS
                  last edited by

                  @SteveITS Thanks for that tip, without vpn the sites would hang until it timed out. Changing dns resolver's outgoing interface to wan allowed the site to load. Somewhere the upstream dns was failing, so I shut down the box for 30 minutes to get a new gateway ip and virtual address.

                  The sites seem to be loading consistently now

                  B 1 Reply Last reply Reply Quote 0
                  • B
                    booshwa @booshwa
                    last edited by

                    As soon as I post that it goes back down..

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.