<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[DNS Resolver fails after enabling pfBlockerNG (DNSBL)]]></title><description><![CDATA[<p dir="auto">Does anyone have any idea why the DNS Resolver doesn't work after enabling DNSBL? I tried doing some diagnostics <em>(Diagnostic -&gt; DNS Lookup)</em>, but unfortunately, 127.0.0.1 returns "<strong>No response</strong>".</p>
]]></description><link>https://forum.netgate.com/topic/195352/dns-resolver-fails-after-enabling-pfblockerng-dnsbl</link><generator>RSS for Node</generator><lastBuildDate>Sun, 19 Apr 2026 09:17:30 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/195352.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 27 Nov 2024 06:48:17 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to DNS Resolver fails after enabling pfBlockerNG (DNSBL) on Thu, 28 Nov 2024 16:16:47 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/beluclark">@<bdi>beluclark</bdi></a> said in <a href="/post/1197201">DNS Resolver fails after enabling pfBlockerNG (DNSBL)</a>:</p>
<blockquote>
<p dir="auto">Unfortunately</p>
</blockquote>
<p dir="auto">Is it ? The image you've shown is like mine : the unbound answer is correct, The host couldn't be resolved.</p>
<p dir="auto">Way better as the GUI : the command line (not the GUI command line of course).<br />
SSH will do just fine, menu option 8.</p>
<p dir="auto">Ask unbound to resolve "google.com", using 127.0.0.1, as unbound listens on 127.0.0.1 :</p>
<pre><code>dig @127.0.0.1 google.com
</code></pre>
<p dir="auto">or even</p>
<pre><code>dig @127.0.0.1 google.com +trace
</code></pre>
]]></description><link>https://forum.netgate.com/post/1197509</link><guid isPermaLink="true">https://forum.netgate.com/post/1197509</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Thu, 28 Nov 2024 16:16:47 GMT</pubDate></item><item><title><![CDATA[Reply to DNS Resolver fails after enabling pfBlockerNG (DNSBL) on Wed, 27 Nov 2024 08:04:47 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a> Unfortunately,</p>
<p dir="auto"><img src="/assets/uploads/files/1732694677742-f3c0fd4a-8f12-4c62-897d-d95fcb47ee61-image.png" alt="f3c0fd4a-8f12-4c62-897d-d95fcb47ee61-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/1197201</link><guid isPermaLink="true">https://forum.netgate.com/post/1197201</guid><dc:creator><![CDATA[beluclark]]></dc:creator><pubDate>Wed, 27 Nov 2024 08:04:47 GMT</pubDate></item><item><title><![CDATA[Reply to DNS Resolver fails after enabling pfBlockerNG (DNSBL) on Wed, 27 Nov 2024 08:02:02 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/beluclark">@<bdi>beluclark</bdi></a> said in <a href="/post/1197196">DNS Resolver fails after enabling pfBlockerNG (DNSBL)</a>:</p>
<blockquote>
<p dir="auto">Unbound was still running and listening to 127.0.0.1:53 (*:53).</p>
</blockquote>
<p dir="auto">The, even when you ask it utterly BS? it should reply :</p>
<p dir="auto"><img src="/assets/uploads/files/1732694438863-7e9d18ca-374b-4307-aec2-9826ea193e8e-image.png" alt="7e9d18ca-374b-4307-aec2-9826ea193e8e-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">with no answer as there isn't an answer.<br />
This is better :</p>
<p dir="auto"><img src="/assets/uploads/files/1732694499670-adfdb7d5-c47c-4326-8c9f-732400986c3c-image.png" alt="adfdb7d5-c47c-4326-8c9f-732400986c3c-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/1197200</link><guid isPermaLink="true">https://forum.netgate.com/post/1197200</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Wed, 27 Nov 2024 08:02:02 GMT</pubDate></item><item><title><![CDATA[Reply to DNS Resolver fails after enabling pfBlockerNG (DNSBL) on Wed, 27 Nov 2024 07:54:00 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a> said in <a href="/post/1197194">DNS Resolver fails after enabling pfBlockerNG (DNSBL)</a>:</p>
<blockquote>
<p dir="auto">I saw this :</p>
<p dir="auto">ea0bf9de-36a9-4ef1-8d32-5024b67c8fdb-image.png</p>
</blockquote>
<p dir="auto">Yes, I have the same logs..</p>
<p dir="auto">Unbound was still running and listening to 127.0.0.1:53 (*:53).</p>
]]></description><link>https://forum.netgate.com/post/1197196</link><guid isPermaLink="true">https://forum.netgate.com/post/1197196</guid><dc:creator><![CDATA[beluclark]]></dc:creator><pubDate>Wed, 27 Nov 2024 07:54:00 GMT</pubDate></item><item><title><![CDATA[Reply to DNS Resolver fails after enabling pfBlockerNG (DNSBL) on Wed, 27 Nov 2024 07:38:17 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/beluclark">@<bdi>beluclark</bdi></a></p>
<p dir="auto">Look at the pfblockerng.log file : go to the bottom, and from theer on, go up and find the latest unbound restart : you should find :</p>
<p dir="auto"><img src="/assets/uploads/files/1732693080728-4e207bc1-083e-4c36-9989-7771046d0626-image.png" alt="4e207bc1-083e-4c36-9989-7771046d0626-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">I saw this :</p>
<p dir="auto"><img src="/assets/uploads/files/1732692890309-ea0bf9de-36a9-4ef1-8d32-5024b67c8fdb-image.png" alt="ea0bf9de-36a9-4ef1-8d32-5024b67c8fdb-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Next step : very first test / check : is unbound still running ?</p>
<p dir="auto">(SSH or console command line !!)</p>
<pre><code>[24.03-RELEASE][root@pfSense.bhf.tld]/root: ps aux | grep 'unbound.conf'
unbound 47572   0.0  3.3 155348 132220  -  Ss   15:36      6:02.13 /usr/local/sbin/unbound -c /var/unbound/unbound.conf
</code></pre>
<p dir="auto">Is unbound listing on '127.0.0.1' ?</p>
<pre><code>[24.03-RELEASE][root@pfSense.bhf.tld]/root: sockstat | grep 'unbound'
unbound  unbound    47572 3   udp6   *:53                  *:*
unbound  unbound    47572 4   tcp6   *:53                  *:*
unbound  unbound    47572 5   udp4   *:53                  *:*
unbound  unbound    47572 6   tcp4   *:53                  *:*
unbound  unbound    47572 8   tcp4   127.0.0.1:953         *:*
</code></pre>
<p dir="auto">This shows me that u bound is listening on all ( ! ) existing interfaces, using port 53 ( of course ) using TCP and UDP, IPv4 and IPv6.</p>
]]></description><link>https://forum.netgate.com/post/1197194</link><guid isPermaLink="true">https://forum.netgate.com/post/1197194</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Wed, 27 Nov 2024 07:38:17 GMT</pubDate></item></channel></rss>