Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    dnsbl is not working properly

    Scheduled Pinned Locked Moved pfBlockerNG
    5 Posts 3 Posters 697 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      hajun29011
      last edited by

      I have configured it according to the guide in this link https://www.zenarmor.com/docs/network-security-tutorials/pfblockerng. However, the dnsbl of pfblocker does not seem to work properly. I added the list to the custom list, but the blocking page does not appear. I have added the pictures below, so if you have any questions, please ask.

      스크린샷 2025-03-18 141625.png 스크린샷 2025-03-18 141609.png 스크린샷 2025-03-18 141555.png 스크린샷 2025-03-18 141523.png 스크린샷 2025-03-18 141429.png 스크린샷 2025-03-18 141358.png 스크린샷 2025-03-18 141331.png 스크린샷 2025-03-18 141315.png 스크린샷 2025-03-18 141258.png 스크린샷 2025-03-18 141237.png

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @hajun29011
        last edited by

        I edited one of my DNSBL groups :

        c32c8394-4a11-4916-b7f9-4fca099b6f91-image.png

        and I've added, like you :

        55f65d56-e053-456b-9da9-f9f02605ef18-image.png

        I reload everything :

        6617f34e-5132-4aa5-859b-b2a6adff3b65-image.png


        On my test PC (192.168.1.6), I flushed my PC's DNS cache - just to be sure.
        Now, the test :

        a1406ebb-f5e4-47fc-86b7-c5abf21fb1a5-image.png

        for the domain dnsbltest.com : same result.
        My browser was unable to resolve both never.com and dnsbltest.com.

        It's normal that an "browser error" is shown, and not the :

        183d3533-fd19-4d9e-85d3-42c1b8f88bee-image.png

        because "10.10.10.1" would only work for non TLS (non https) web access.
        10.10.10.1 could not intercept https requests.

        Looking at the pfBlockerng Alerts page shows that both DNS request were blocked :

        1a072383-05a4-47cb-82f9-0c3b964347f0-image.png

        @hajun29011 said in dnsbl is not working properly:

        https://www.zenarmor.com/docs/network-security-tutorials/pfblockerng

        zenarmor ? Who is that ?
        Why not using the official docs and/or video's ??
        This is a bit vague :

        a44524f0-ab7a-4842-abef-e3c13fab6834-image.png

        Here : https://www.youtube.com/@NetgateOfficial/videos

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        H 1 Reply Last reply Reply Quote 0
        • H
          hajun29011 @Gertjan
          last edited by

          @Gertjan Thanks for the answer. But I have a problem. Even though I don't see the page that appears on 10.10.10.1, my system doesn't block sites by default. I definitely added naver.com to the custom list, but when I access it, it connects normally. There is no blocking log either.

          GertjanG 1 Reply Last reply Reply Quote 0
          • U
            Uglybrian
            last edited by

            After you make changes, are you updating PF blocker? When you make a change, you need to go to the bottom of the page press save. Then go to the updates and hit run. You also may need to reset the state table and clear the cash in your browser. Just a reminder as @ Gertjan has pointed out. You will only get the DNSBL web server page with http not https. For this reason, I set the global logging mode to Null Block (logging).

            1 Reply Last reply Reply Quote 0
            • GertjanG
              Gertjan @hajun29011
              last edited by Gertjan

              @hajun29011 said in dnsbl is not working properly:

              I definitely added naver.com to the custom list, but when I access it, it connects normally. There is no blocking log either.

              When I do not (!) add never.com here :

              57b628ad-ba2c-4d34-9b0b-777ae5ee91f4-image.png

              and I visit never.com in a browser, it will get listed here, on the Unified tab :

              7d291f7a-cfb3-4a3c-8b3a-ea55b8a531a8-image.png

              here it is :

              8eb442b1-0ffd-42d6-8bd6-aa53a2acef16-image.png

              When I add "never.com" to the (a) "DNSBL Custom_List" it will be blocked and shown on the Alerts tab :
              4c6dd8ab-f6d7-4266-8da2-9e7c115f56f3-image.png

              If nothings shows up no where, then you have to double check if your device is using pFsense, the resolver, as the DNS server.

              If the device you are testing is using some other DNS server, like 8.8.8.8 then the resolver and pfBlockerng will never see the DNS request, and pfBlockerng couldn't block the request.

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.