Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfblocker pfb_dnsbl service not starting

    Scheduled Pinned Locked Moved pfBlockerNG
    21 Posts 2 Posters 786 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • GertjanG Offline
      Gertjan @popeel-SSH
      last edited by Gertjan

      @popeel-SSH said in pfblocker pfb_dnsbl service not starting:

      I don't want to run any files outside the box as it's in productions.

      Outside ? What do you mean ?


      My turn :
      I deleted /var/unbound/dnsbl_cert.pem
      Now, like you :

      [25.07.1-RELEASE][root@pfSense.bhf.tld]/var/unbound: ll /var/unbound/dnsbl_cert.pem
      ls: /var/unbound/dnsbl_cert.pem: No such file or directory
      

      I did a full reload (and scrolled trough the resulting log) :

      dc294e4d-7a48-4401-a7c7-a9a918e10eb1-image.png

      You see what happened (green ^^).

      And the file was there again :

      [25.07.1-RELEASE][root@pfSense.bhf.tld]/var/unbound: ll /var/unbound/dnsbl_cert.pem
      -rw-r--r--  1 root unbound 3359 Oct  8 15:51 /var/unbound/dnsbl_cert.pem
      

      For some reasons, your 'pfSense' can't create a cert ? Or it can create the cert, but can't save it at the /var/unbound/ destination..... Hummm.
      I'll take this one @home, study it somewhat to find out the reason what can be the reason.

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      P 1 Reply Last reply Reply Quote 0
      • P Offline
        popeel-SSH @Gertjan
        last edited by

        @Gertjan

        Yes. It's not the only file that cannot create. There is a SSL certificate file needs to be in the same location and mine it is not.

        Please let me know if you find anything.

        I will wait couple of days and maybe rebuild the firewall and see if that does anything.

        Thanks for your time.

        GertjanG 1 Reply Last reply Reply Quote 0
        • GertjanG Offline
          Gertjan @popeel-SSH
          last edited by Gertjan

          @popeel-SSH said in pfblocker pfb_dnsbl service not starting:

          Yes. It's not the only file that cannot create. There is a SSL certificate file needs to be in the same location and mine it is not.

          The "dnsbl_cert.pem" is the web servers (lighttpd) certificate file.
          Other files are missing ?

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          P 2 Replies Last reply Reply Quote 0
          • P Offline
            popeel-SSH @Gertjan
            last edited by

            @Gertjan Yes. As you can see my screenshot of the unbound directory.

            I am planning to rebuild the pfsense and try that. I will update you.

            Thanks

            1 Reply Last reply Reply Quote 0
            • P Offline
              popeel-SSH @Gertjan
              last edited by

              @Gertjan

              I have reinstall the firewall from the fresh and installed pfBlocker with minimal settings, and it is functioning properly.

              After that, I performed a factory reset on the firewall, restore our config.xml, and installed pfBlocker NG with the same minimal settings, but I encountered the same error, and the certificate was not created.

              Not sure what is in my config should stop this ??

              These are the files in my /var/unbound

              5e36cfd8-a6ce-49bb-a7ea-b7c05b54c60d-image.png

              GertjanG 1 Reply Last reply Reply Quote 0
              • GertjanG Offline
                Gertjan @popeel-SSH
                last edited by

                This :

                @popeel-SSH said in pfblocker pfb_dnsbl service not starting:

                performed a factory reset on the firewall, restore our config.xml

                is a null operation.
                Your "pfSense" as installed, is always the same.

                When you discard your own setup, and go to the default setup, and re assign interface, and make it work again (LAN+WAN), and then import your previous config file, your back at square zero.

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                P 1 Reply Last reply Reply Quote 0
                • P Offline
                  popeel-SSH @Gertjan
                  last edited by

                  @Gertjan

                  I tried that too.

                  PFSence factry default> setup the firewall basic (without any of our config)> Install pfblockerNG run the wizard with only WAN and LAN > both pfblocker and DNSBL service runs fine and start up okay.

                  When I restore the config to the firewall it's then stop working.

                  It's something in our config causing this to stop.

                  Let's see pfblocker support can help on this.

                  I will keep updating.

                  Thanks

                  P 1 Reply Last reply Reply Quote 0
                  • P Offline
                    popeel-SSH @popeel-SSH
                    last edited by

                    @BBcan177

                    Will find a solution for this sooner.

                    Thanks in advance. :)

                    P 1 Reply Last reply Reply Quote 0
                    • P Offline
                      popeel-SSH @popeel-SSH
                      last edited by

                      If anyone have any solution for this please let me know.

                      I have had no luck with anything.

                      Thanks

                      1 Reply Last reply Reply Quote 0
                      • P Offline
                        popeel-SSH
                        last edited by

                        It's an issue with VIP creation code in PFBlockerNG.

                        PFblockerNG support is working to remove the VIP creation code in pfBlockerNG and leaving that to pfSense to handle. Stay tuned.

                        https://github.com/pfsense/FreeBSD-ports/pull/1427

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.