Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfBlockerNG blocks my entire network

    Scheduled Pinned Locked Moved pfBlockerNG
    19 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      JHODZ
      last edited by

      I cant reach my Firewall or access internet after enabling pfblocker services.
      It works for a while and all my interfaces stops working I have to restart the firewall which works for a short period to disable it before everything works normally. Please help me with your experience.

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @JHODZ
        last edited by

        @JHODZ said in pfBlockerNG blocks my entire network:

        I have to restart the firewall which works for a short period to disable it before everything works normally

        When you disable (uncheck the Enable box) pfBlockerng, everything works fine ?

        9b45023a-1f3f-4f75-af39-630e9b7ab32f-image.png

        If so, what are your pfBlockerng settings ?

        What happens when you enable pfBlockerng,
        and : NOnoe of the IP settings :

        0d27fd3b-d3fa-4bf0-b747-d50fe54496e9-image.png

        and no DNSBL settings (no feeds, no options)

        does "it work" (without pfBlockerng doing anything).

        When exactly this issue happens ?

        On the main Firewall > pfBlockerNG > IP page, do you ask to create firewall rules ? What settings ?

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        1 Reply Last reply Reply Quote 0
        • J
          JHODZ
          last edited by

          Let me try that and give you the feedback and to answer your first question, when i disable it everything works just fine.

          GertjanG J 2 Replies Last reply Reply Quote 0
          • GertjanG
            Gertjan @JHODZ
            last edited by

            @JHODZ

            When you installed pfBlockerNG, and activate it - without doing anything else - it does .... nothing.
            As there are no IP feeds loaded, and no DNSBL (I actually cant' recall if it is pre loaded with one small DNSBL).
            DNSBL feeds are not used by pfBlockerNG, they are fed to the local resolver, so it knows what host names not to resolve, and just return "127.0.0.1" or "0.0.0.0" as this indicated to the requesting device : "No A record found - host does not exist".

            Btw : You use pfSense 2.7.2 or pfSense 23.09.1, as any other, lower versions can/will produce major issues.

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            1 Reply Last reply Reply Quote 0
            • J
              JHODZ @JHODZ
              last edited by JHODZ

              @JHODZ I tried disabling IP and Putting no feed into the DSBL yet i cant access the internet and communication between interfaces becomes very slow (Non-responsive). Also my pf plus version is 23.09.1-RELEASE

              GertjanG 1 Reply Last reply Reply Quote 0
              • GertjanG
                Gertjan @JHODZ
                last edited by

                @JHODZ

                Just a wild guess : under Firewall > pfBlockerNG > DNSBL

                e1b432a0-79fa-4cb1-8e46-d29a1fb27590-image.png

                This IP doesn't conflict with any of your interfaces ?

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                J 1 Reply Last reply Reply Quote 0
                • J
                  JHODZ @Gertjan
                  last edited by

                  @Gertjan No Please. I have even changed it Screenshot 2024-02-22 091644.png

                  GertjanG johnpozJ 2 Replies Last reply Reply Quote 0
                  • GertjanG
                    Gertjan @JHODZ
                    last edited by

                    @JHODZ

                    Are you allowed to use 12.10.100.1 ??
                    As stated : use an IPv4 that is RFC1918.

                    Example :

                    [23.09.1-RELEASE][root@pfSense.bhf.tld]/root: ping 12.10.100.1
                    PING 12.10.100.1 (12.10.100.1): 56 data bytes
                    64 bytes from 12.10.100.1: icmp_seq=0 ttl=236 time=123.601 ms
                    64 bytes from 12.10.100.1: icmp_seq=1 ttl=236 time=123.248 ms
                    ^C
                    --- 12.10.100.1 ping statistics ---
                    3 packets transmitted, 2 packets received, 33.3% packet loss
                    round-trip min/avg/max/stddev = 123.248/123.425/123.601/0.176 ms
                    

                    You have a huge security issue
                    Or
                    You are using an IP that you do not own [ I vote for this one ].

                    The latter can/will create routing problems.

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    J 1 Reply Last reply Reply Quote 0
                    • J
                      JHODZ @Gertjan
                      last edited by

                      @Gertjan noted am reviewing this will give you the feedback but also if I may ask I changed my web interface port can it also cause any issue with pfblocker

                      J 1 Reply Last reply Reply Quote 0
                      • J
                        JHODZ @JHODZ
                        last edited by

                        @JHODZ I also checked from my logs and got this error
                        [1708589241] unbound[97875:0] error: bind: address already in use
                        [1708589241] unbound[97875:0] fatal error: could not open ports

                        GertjanG 1 Reply Last reply Reply Quote 0
                        • GertjanG
                          Gertjan @JHODZ
                          last edited by

                          @JHODZ said in pfBlockerNG blocks my entire network:

                          [1708589241] unbound[97875:0] error: bind: address already in use
                          [1708589241] unbound[97875:0] fatal error: could not open ports

                          That means that unbound was told to stop, but didn't (in time). then it get restarted, but it can't, as the previous instance is still shutting down, or even dead.
                          Solution : console or SSH, option 8, and :

                          ps ax | grep 'unbound'
                          

                          and kill all the lines like these :

                          17516  -  Ss     16:07.53 /usr/local/sbin/unbound -c /var/unbound/unbound.conf
                          

                          so

                          kill 17516
                          

                          and when done, start unbound in GUI.

                          @JHODZ said in pfBlockerNG blocks my entire network:

                          ask I changed my web interface port

                          Like :

                          48e10614-8735-4e42-9640-6bad7c384c39-image.png

                          why not.
                          ( as long as it isn't used by another process ^^ )

                          No "help me" PM's please. Use the forum, the community will thank you.
                          Edit : and where are the logs ??

                          J 1 Reply Last reply Reply Quote 1
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator @JHODZ
                            last edited by

                            @JHODZ said in pfBlockerNG blocks my entire network:

                            No Please. I have even changed it

                            You didn't change it, but it lists 12.10.100.1 as its vip? That sure looks like it was changed to me.. Where it would it come up with such an address?

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                            1 Reply Last reply Reply Quote 0
                            • J
                              JHODZ @Gertjan
                              last edited by

                              @Gertjan yes i dd changed it

                              johnpozJ 1 Reply Last reply Reply Quote 0
                              • johnpozJ
                                johnpoz LAYER 8 Global Moderator @JHODZ
                                last edited by

                                @JHODZ yeah my bad, couldn't read this morning I guess.. but 12.something would be a really bad choice.. And points out it should be rfc1918..

                                An intelligent man is sometimes forced to be drunk to spend time with his fools
                                If you get confused: Listen to the Music Play
                                Please don't Chat/PM me for help, unless mod related
                                SG-4860 24.11 | Lab VMs 2.8, 24.11

                                1 Reply Last reply Reply Quote 0
                                • J
                                  JHODZ
                                  last edited by

                                  Hi all, I got it to work by changing some of the ports, but I can't run DNSBL in python mode allthough unbound mode works fine. Please is there anything else am missing.

                                  johnpozJ GertjanG 2 Replies Last reply Reply Quote 0
                                  • johnpozJ
                                    johnpoz LAYER 8 Global Moderator @JHODZ
                                    last edited by

                                    @JHODZ said in pfBlockerNG blocks my entire network:

                                    Please is there anything else am missing.

                                    Missing what - you have given no info on how your setup..

                                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                                    If you get confused: Listen to the Music Play
                                    Please don't Chat/PM me for help, unless mod related
                                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                                    1 Reply Last reply Reply Quote 0
                                    • GertjanG
                                      Gertjan @JHODZ
                                      last edited by Gertjan

                                      @JHODZ said in pfBlockerNG blocks my entire network:

                                      but I can't run DNSBL in python mode

                                      Because ?
                                      You don't want to ?
                                      Some other reason ?

                                      edit :
                                      "Python mode" is what the unbound authors advice to use when you want, for example, add dnsbkl type files. This 'mode' speeds up drastically the start and restart of unbound.

                                      No "help me" PM's please. Use the forum, the community will thank you.
                                      Edit : and where are the logs ??

                                      J 1 Reply Last reply Reply Quote 0
                                      • J
                                        JHODZ @Gertjan
                                        last edited by

                                        @Gertjan I meant I am unable to run dnsbl in Python mode. Webpages takes long time to load

                                        GertjanG 1 Reply Last reply Reply Quote 0
                                        • GertjanG
                                          Gertjan @JHODZ
                                          last edited by

                                          @JHODZ

                                          How much DNSBL feeds do you have :

                                          820408bc-f8f1-4dc7-9aa2-1d50b23a47f3-image.png

                                          c306e0a5-a521-40a4-9a23-c8464307fefa-image.png

                                          What does this log show you when you reload pfBlockerng like this :

                                          dee28981-7849-47e1-926e-58f7d2187797-image.png

                                          Do the test both in unbound and Python mode.

                                          No "help me" PM's please. Use the forum, the community will thank you.
                                          Edit : and where are the logs ??

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.