Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    adult content

    Scheduled Pinned Locked Moved pfBlockerNG
    24 Posts 5 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      reynold
      last edited by

      Hi, i would like to block adult content with UT1.
      It warns me that it's large list and it warns me to check memory resource.
      I have 4 GB RAM installed.
      Is that enough?
      I read that some people freezed appliance with that huge list.
      But other people says thay had no problem.
      I'm a little bit confused.
      I did not found memory required for list

      R S 2 Replies Last reply Reply Quote 0
      • R
        rcoleman-netgate Netgate @reynold
        last edited by

        @reynold You're probably hitting a different resource limit.

        Check System > Advanced and click on "Firewall & NAT" and look at your "Firewall Maximum Table Entries" value. Mine is set to 2000000

        Ryan
        Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
        Requesting firmware for your Netgate device? https://go.netgate.com
        Switching: Mikrotik, Netgear, Extreme
        Wireless: Aruba, Ubiquiti

        R 1 Reply Last reply Reply Quote 0
        • S
          SteveITS Galactic Empire @reynold
          last edited by

          @reynold You can download the file from pfBlocker’s feed page. I know it takes over 1 GB disk space for pfSense to extract, but I don’t know the actual disk or RAM usage.

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote 👍 helpful posts!

          1 Reply Last reply Reply Quote 0
          • R
            reynold @rcoleman-netgate
            last edited by

            @rcoleman-netgate
            Mine is set also to 2000000

            R 1 Reply Last reply Reply Quote 0
            • R
              reynold @reynold
              last edited by

              I'm using steven black lists.
              It seems working.
              But I'm not able to block pornhub.
              Could you help me?
              I have already tried with custom blacklist but it did not work

              provelsP 1 Reply Last reply Reply Quote 0
              • provelsP
                provels @reynold
                last edited by provels

                @reynold
                FWIW, I use the UT1 adult list and that doesn't block Pornhub either, so it's not the answer. But if you want to try it, I would disable your other lists, start with the UT1 adult list and see how memory looks, then start adding other UT1 categories and other you want and note the effects on memory, That said I run UT1, the old Shallalist and quite a few others and my memory shows only 7% of 16GB.

                Peder

                MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
                BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

                R 1 Reply Last reply Reply Quote 0
                • R
                  reynold @provels
                  last edited by

                  @provels ok. I will try.
                  But is there a way to block pornhub?
                  Why is that not blocked?

                  R S 2 Replies Last reply Reply Quote 0
                  • R
                    rcoleman-netgate Netgate @reynold
                    last edited by

                    @reynold said in adult content:

                    But is there a way to block pornhub?

                    Block ASNs.

                    https://www.peeringdb.com/asn/55222 that is the parent company's ASN. Aylo, née MindGeek.

                    Ryan
                    Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                    Requesting firmware for your Netgate device? https://go.netgate.com
                    Switching: Mikrotik, Netgear, Extreme
                    Wireless: Aruba, Ubiquiti

                    R 1 Reply Last reply Reply Quote 0
                    • S
                      SteveITS Galactic Empire @reynold
                      last edited by

                      @reynold said in adult content:

                      block pornhub

                      Alternately, create hostname overrides for pornhub.com, www.pornhub.com, etc. pointing to 127.0.0.1 or some nonexistent IP.

                      Test with dig or nslookup.

                      Keep in mind any DNS based blocking assumes DNS over HTTPS is not being used. Here is a writeup of how to block DoH, in the pfSense PDF:
                      https://github.com/jpgpi250/piholemanual

                      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                      Upvote 👍 helpful posts!

                      M 1 Reply Last reply Reply Quote 0
                      • M
                        mcury @SteveITS
                        last edited by mcury

                        These lists are pretty good:

                        https://github.com/StevenBlack/hosts

                        d24fcc0f-b67a-4e4b-81e0-80ce8bf9f3cc-image.png

                        You can select only porn if you want.

                        dead on arrival, nowhere to be found.

                        R 1 Reply Last reply Reply Quote 0
                        • R
                          reynold @mcury
                          last edited by

                          @mcury
                          I'm using that lists but i can not block pornhub

                          M provelsP 2 Replies Last reply Reply Quote 0
                          • M
                            mcury @reynold
                            last edited by

                            @reynold said in adult content:

                            I'm using that lists but i can not block pornhub

                            hm, that is weird because I can see pornhub in that list..

                            Are you sure sure that the hosts in your network are using Pfsense's DNS server?
                            Nothing using DOT or DOH to bypass the DNS server?

                            dead on arrival, nowhere to be found.

                            R 1 Reply Last reply Reply Quote 0
                            • R
                              reynold @rcoleman-netgate
                              last edited by

                              @rcoleman-netgate
                              It can be a solution but ASN blocking isn't dangerous?.
                              Unless its an ASN wholly owned by the public entity (facebook,google,nextlix) I could blackholing lots of sites

                              R 1 Reply Last reply Reply Quote 0
                              • R
                                reynold @mcury
                                last edited by

                                @mcury
                                I'm sure
                                I'm trying myself from lan
                                I can block many porn sites but pornhub seems to be impossible
                                Nslookup shows thar pornhub.com is correctly resolved.
                                If i try to resolve youporn it gives me 10.10.10.1 and that's ok. In fact it's blocked

                                M 1 Reply Last reply Reply Quote 0
                                • R
                                  rcoleman-netgate Netgate @reynold
                                  last edited by

                                  @reynold In this case... Aylo's ONLY business is PornHub. Blocking their ASN should be "safe"

                                  Ryan
                                  Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                                  Requesting firmware for your Netgate device? https://go.netgate.com
                                  Switching: Mikrotik, Netgear, Extreme
                                  Wireless: Aruba, Ubiquiti

                                  1 Reply Last reply Reply Quote 0
                                  • M
                                    mcury @reynold
                                    last edited by

                                    @reynold said in adult content:

                                    I can block many porn sites but pornhub seems to be impossible

                                    If you are on Windows, try this: ipconfig /flushdns and test again, just to make sure that cache is not the problem.

                                    If the problem persists after that, you could create a custom list to include along with the others you already have.
                                    As far as I remember, you can create that list in a .txt file and put somewhere.
                                    The downside of this is that you would probably need to enable TLD which increases the memory usage by a lot..

                                    dead on arrival, nowhere to be found.

                                    R 1 Reply Last reply Reply Quote 0
                                    • R
                                      reynold @mcury
                                      last edited by

                                      @mcury cache is not the problem and i enabled tld already.
                                      I do not know how to create custom txt list and where to puts

                                      M 1 Reply Last reply Reply Quote 0
                                      • M
                                        mcury @reynold
                                        last edited by

                                        @reynold

                                        It seems that you don't need to create a .txt file, try like this:
                                        https://forum.netgate.com/post/834813

                                        dead on arrival, nowhere to be found.

                                        R 1 Reply Last reply Reply Quote 0
                                        • R
                                          reynold @mcury
                                          last edited by

                                          @mcury
                                          I can not find that GUI, i think it's an older version

                                          R M 2 Replies Last reply Reply Quote 0
                                          • R
                                            rcoleman-netgate Netgate @reynold
                                            last edited by

                                            @reynold said in adult content:

                                            I can not find that GUI, i think it's an older version

                                            if you are running an older release of pfBlocker you should update to current.

                                            Ryan
                                            Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                                            Requesting firmware for your Netgate device? https://go.netgate.com
                                            Switching: Mikrotik, Netgear, Extreme
                                            Wireless: Aruba, Ubiquiti

                                            R 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.