Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Fresh install pfblockerNG on pfSense 25.11 RC a lot problems

    Scheduled Pinned Locked Moved pfBlockerNG
    22 Posts 4 Posters 235 Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      Antibiotic
      last edited by

      Fresh installation of pfblokerNG , WHEN SET TO UNBOUNT PYTHON MODE GET THIS ERROR:
      Saving new DNSBL web server configuration to port [ 8081 and 4443 ]
      Restarting DNSBL Service
      Stopping Unbound Resolver..
      Unbound stopped in 3 sec.
      Additional mounts (DNSBL python):
      No changes required.
      Starting Unbound Resolver.
      DNSBL enabled FAIL *** Fix error(s) and a Force Reload required! ***

      ====================

      [1763652679] unbound[55760:0] warning: setsockopt(..., SO_SNDBUF, ...) was not granted: No buffer space available
      [1763652679] unbound[55760:0] warning: so-sndbuf 4194304 was not granted. Got 57344. To fix: start with root permissions(linux) or sysctl bigger net.core.wmem_max(linux) or kern.ipc.maxsockbuf(bsd) values. or set so-sndbuf: 0 (use system value).
      [1763652679] unbound[55760:0] warning: setsockopt(..., SO_SNDBUF, ...) was not granted: No buffer space available
      [1763652679] unbound[55760:0] warning: so-sndbuf 4194304 was not granted. Got 57344. To fix: start with root permissions(linux) or sysctl bigger net.core.wmem_max(linux) or kern.ipc.maxsockbuf(bsd) values. or set so-sndbuf: 0 (use system value).
      [1763652679] unbound[55760:0] warning: setsockopt(..., SO_SNDBUF, ...) was not granted: No buffer space available
      [1763652679] unbound[55760:0] warning: so-sndbuf 4194304 was not granted. Got 57344. To fix: start with root permissions(linux) or sysctl bigger net.core.wmem_max(linux) or kern.ipc.maxsockbuf(bsd) values. or set so-sndbuf: 0 (use system value).
      [1763652679] unbound[55760:0] error: Unknown value in module-config, module: 'python'. This module is not present (not compiled in); see the list of linked modules with unbound -V
      [1763652679] unbound[55760:0] fatal error: failed to startup modules

      Second TOP1M excluding not working at all. Wneh i chhose to exclude ( ca,, org and etc) this settings not saved:
      [PFB_FILTER - 17] Failed or invalid Mime Type: [application/octet-stream|0]
      TOP1M: No TLD Inclusions found.

      pfSense plus 25.11 on Topton mini PC
      CPU: Intel N100
      NIC: Intel i-226v 4 pcs
      RAM : 16 GB DDR5
      Disk: 128 GB NVMe
      Brgds, Archi

      tinfoilmattT 2 Replies Last reply Reply Quote 0
      • tinfoilmattT Offline
        tinfoilmatt @Antibiotic
        last edited by

        @Antibiotic This implicates a configuration issue well beyond that of only pfBlockerNG's. It'd be helpful for you to describe how DNS is configured on this system/your LAN. Screenshots will be even better.

        1 Reply Last reply Reply Quote 0
        • tinfoilmattT Offline
          tinfoilmatt @Antibiotic
          last edited by

          @Antibiotic Might be interesting to see your Advanced Resolver Options under Services / DNS Resolver / Advanced Settings in particular.

          A 1 Reply Last reply Reply Quote 0
          • A Offline
            Antibiotic @tinfoilmatt
            last edited by

            @tinfoilmatt Hello my friend:
            Screenshot_20-11-2025_182127_192.168.10.1.jpeg Screenshot_20-11-2025_182118_192.168.10.1.jpeg Screenshot_20-11-2025_181815_192.168.10.1.jpeg Screenshot_20-11-2025_181659_192.168.10.1.jpeg
            Unbound interfaces:
            1.Network interfaces: LAN1 LAN2 LAN 3 AND localhost only
            2.Outgoing Network Interfaces: OpenVPN interface only

            pfSense plus 25.11 on Topton mini PC
            CPU: Intel N100
            NIC: Intel i-226v 4 pcs
            RAM : 16 GB DDR5
            Disk: 128 GB NVMe
            Brgds, Archi

            tinfoilmattT W 3 Replies Last reply Reply Quote 0
            • tinfoilmattT Offline
              tinfoilmatt @Antibiotic
              last edited by

              @Antibiotic Set Message Cache Size back to default (i.e., 4 MB) and try updating pfB again.

              1 Reply Last reply Reply Quote 0
              • tinfoilmattT Offline
                tinfoilmatt @Antibiotic
                last edited by

                @Antibiotic A full reboot in-between DNS Resolver config change and pfB update wouldn't hurt either.

                A 2 Replies Last reply Reply Quote 0
                • A Offline
                  Antibiotic @tinfoilmatt
                  last edited by

                  @tinfoilmatt Did back cache size to default , reboot pfsense and adjust pfblocker to unbound python mode. This problem still the same:
                  Stopping Unbound Resolver
                  Unbound stopped in 1 sec.
                  Additional mounts (DNSBL python):
                  Starting Unbound Resolver Not completed.
                  [1763657162] unbound[25597:0] warning: setsockopt(..., SO_SNDBUF, ...) was not granted: No buffer space available
                  [1763657162] unbound[25597:0] warning: so-sndbuf 4194304 was not granted. Got 57344. To fix: start with root permissions(linux) or sysctl bigger net.core.wmem_max(linux) or kern.ipc.maxsockbuf(bsd) values. or set so-sndbuf: 0 (use system value).
                  [1763657162] unbound[25597:0] warning: setsockopt(..., SO_SNDBUF, ...) was not granted: No buffer space available
                  [1763657162] unbound[25597:0] warning: so-sndbuf 4194304 was not granted. Got 57344. To fix: start with root permissions(linux) or sysctl bigger net.core.wmem_max(linux) or kern.ipc.maxsockbuf(bsd) values. or set so-sndbuf: 0 (use system value).
                  [1763657162] unbound[25597:0] warning: setsockopt(..., SO_SNDBUF, ...) was not granted: No buffer space available
                  [1763657162] unbound[25597:0] warning: so-sndbuf 4194304 was not granted. Got 57344. To fix: start with root permissions(linux) or sysctl bigger net.core.wmem_max(linux) or kern.ipc.maxsockbuf(bsd) values. or set so-sndbuf: 0 (use system value).
                  [1763657162] unbound[25597:0] error: Unknown value in module-config, module: 'python'. This module is not present (not compiled in); see the list of linked modules with unbound -V
                  [1763657162] unbound[25597:0] fatal error: failed to startup modules

                  Will set back to unbound mode in pfblockerNG. sECOND PROBLEM STILL EXIST AS WELL (Loading TOP1M Whitelist...
                  TOP1M Database downloading ( approx 21MB ) ... Please wait ...

                  Failed
                  TOP1M: No TLD Inclusions found.

                  DNSBL - TOP1M changes found - Rebuilding!
                  completed)

                  Can not even restart unbound ( he is simply stopped and didn't react on restart) from main menu during pfblockerNG unbound python mode ON.

                  pfSense plus 25.11 on Topton mini PC
                  CPU: Intel N100
                  NIC: Intel i-226v 4 pcs
                  RAM : 16 GB DDR5
                  Disk: 128 GB NVMe
                  Brgds, Archi

                  1 Reply Last reply Reply Quote 0
                  • A Offline
                    Antibiotic @tinfoilmatt
                    last edited by

                    @tinfoilmatt Nothing changes. The same error and unbound stopped and didnt react in this mode.

                    pfSense plus 25.11 on Topton mini PC
                    CPU: Intel N100
                    NIC: Intel i-226v 4 pcs
                    RAM : 16 GB DDR5
                    Disk: 128 GB NVMe
                    Brgds, Archi

                    tinfoilmattT A 2 Replies Last reply Reply Quote 0
                    • tinfoilmattT Offline
                      tinfoilmatt @Antibiotic
                      last edited by

                      @Antibiotic You never followed-up in this thread. Has your pfBlockerNG install been broken since then? Or did you do something at some point to resolve that issue?

                      A 1 Reply Last reply Reply Quote 0
                      • A Offline
                        Antibiotic @Antibiotic
                        last edited by

                        Btw the cron schedule missing as well

                        Screenshot_20-11-2025_185351_192.168.10.1.jpeg

                        pfSense plus 25.11 on Topton mini PC
                        CPU: Intel N100
                        NIC: Intel i-226v 4 pcs
                        RAM : 16 GB DDR5
                        Disk: 128 GB NVMe
                        Brgds, Archi

                        tinfoilmattT 1 Reply Last reply Reply Quote 0
                        • tinfoilmattT Offline
                          tinfoilmatt @Antibiotic
                          last edited by tinfoilmatt

                          @Antibiotic This feels like package reinstall (without saving settings) at a minimum.

                          You could try for the less drastic procedure described under Firewall / pfBlockerNG / General / Keep Settings—but it doesn't seem like that would resolve issue you're now seeing with Unbound.

                          1 Reply Last reply Reply Quote 0
                          • A Offline
                            Antibiotic @tinfoilmatt
                            last edited by

                            @tinfoilmatt Please read name of post. This is fresh installation of 25.11 RC and fresh installation of pfblockerNG. From scratch

                            pfSense plus 25.11 on Topton mini PC
                            CPU: Intel N100
                            NIC: Intel i-226v 4 pcs
                            RAM : 16 GB DDR5
                            Disk: 128 GB NVMe
                            Brgds, Archi

                            tinfoilmattT 1 Reply Last reply Reply Quote 0
                            • tinfoilmattT Offline
                              tinfoilmatt @Antibiotic
                              last edited by

                              @Antibiotic Not so fresh if you (at least) made ill-advised Unbound configuration changes.

                              A 1 Reply Last reply Reply Quote 0
                              • A Offline
                                Antibiotic @tinfoilmatt
                                last edited by

                                @tinfoilmatt I think this soft should work at any way. Doesn't matter what we will change in unbound. But anyway this is RC not stable version, time to correct bugs still to go.

                                pfSense plus 25.11 on Topton mini PC
                                CPU: Intel N100
                                NIC: Intel i-226v 4 pcs
                                RAM : 16 GB DDR5
                                Disk: 128 GB NVMe
                                Brgds, Archi

                                tinfoilmattT 1 Reply Last reply Reply Quote 0
                                • tinfoilmattT Offline
                                  tinfoilmatt @Antibiotic
                                  last edited by

                                  @Antibiotic Or it's an issue with your system configuration. I would personally have to troubleshoot your system myself to develop a hunch one way or the other.

                                  1 Reply Last reply Reply Quote 0
                                  • W Offline
                                    Wolf666 @Antibiotic
                                    last edited by

                                    @Antibiotic you should enable python module on general settings.

                                    Modem Draytek Vigor 130
                                    pfSense 2.4 Supermicro A1SRi-2558 - 8GB ECC RAM - Intel S3500 SSD 80GB - M350 Case
                                    Switch Cisco SG350-10
                                    AP Netgear R7000 (Stock FW)
                                    HTPC Intel NUC5i3RYH
                                    NAS Synology DS1515+
                                    NAS Synology DS213+

                                    A 1 Reply Last reply Reply Quote 0
                                    • A Offline
                                      Antibiotic @Wolf666
                                      last edited by

                                      @Wolf666 The pictures were made in unbound mode not a python mode. That why this is option not ticked. When unbound python mode enabled in pfblockerNG this settings going ON by auto.

                                      pfSense plus 25.11 on Topton mini PC
                                      CPU: Intel N100
                                      NIC: Intel i-226v 4 pcs
                                      RAM : 16 GB DDR5
                                      Disk: 128 GB NVMe
                                      Brgds, Archi

                                      GertjanG 1 Reply Last reply Reply Quote 0
                                      • GertjanG Offline
                                        Gertjan @Antibiotic
                                        last edited by

                                        @Antibiotic said in Fresh install pfblockerNG on pfSense 25.11 RC a lot problems:

                                        When unbound python mode enabled in pfblockerNG this settings going ON by auto.

                                        I was somewhat surprised to read this, but is is the case.
                                        Settings in a package (pfBlockerng) will modify pfSense 'core' (unbound) settings.

                                        warning: so-sndbuf 4194304 was not granted. Got 57344

                                        I translate :
                                        I want 4 million, only got 50k ..... that's some ressource missing, and you need 80 (!!) times more.
                                        This can't be a simple RAM, you should have enough of it.
                                        Some "buffer size", see pfSense advanced settings ?

                                        No "help me" PM's please. Use the forum, the community will thank you.
                                        Edit : and where are the logs ??

                                        tinfoilmattT 1 Reply Last reply Reply Quote 0
                                        • tinfoilmattT Offline
                                          tinfoilmatt @Gertjan
                                          last edited by

                                          @Gertjan said in Fresh install pfblockerNG on pfSense 25.11 RC a lot problems:

                                          see pfSense advanced settings

                                          Services / DNS Resolver / Advanced Settings / Advanced Resolver Options / Message Cache Size

                                          GertjanG 1 Reply Last reply Reply Quote 0
                                          • GertjanG Offline
                                            Gertjan @tinfoilmatt
                                            last edited by

                                            @tinfoilmatt

                                            This :

                                            127235a2-d185-4b63-aa03-08d6d842e51b-image.png

                                            is some internal unbound cache.

                                            The errors, imho, talks about something else.
                                            I have this "kern.ipc.maxsockbuf(bsd) value" set to :

                                            ab11ca5f-7aeb-4ef7-8ca9-3d0b81f2d8e4-image.png

                                            a bit more as 4 million ^^
                                            Under System > Advanced >System Tunables

                                            Btw : I'm just making noise here, as I didn't install the RC yet (as it is less candidate as release to me ^^).

                                            No "help me" PM's please. Use the forum, the community will thank you.
                                            Edit : and where are the logs ??

                                            tinfoilmattT 2 Replies Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.