Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    How to set up Bambenek malicious IP table on pfBlocker

    Scheduled Pinned Locked Moved General pfSense Questions
    38 Posts 5 Posters 2.1k Views 5 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F Offline
      FrankZappa
      last edited by

      I keep trying to set up the Bambenek malicious IP list in pfBlocker, but I constantly get "invalid url or host". I've tried to set it up as an alias, but to no avail. I subscribed (user name and password) to Bambenek, but still doesn't work. Any thoughts on what I'm doing wrong?
      7e6c725a-d0aa-49dc-9dbe-aadc84c6b66d-image.png

      8afc01ce-499f-44f7-a031-929cb0bfe723-image.png
      4ccfa0ab-9f2c-43df-93c5-5f27830d916c-image.png

      fireodoF 1 Reply Last reply Reply Quote 0
      • fireodoF Offline
        fireodo @FrankZappa
        last edited by fireodo

        @FrankZappa

        Maybe this could help you?

        Bambenek-Feed

        I use the Bambenek Feed too and the "@" in the email-adress, has to be replaced by "%40" (without quoting).

        Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
        SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
        pfsense 2.8.1 CE
        Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

        F 1 Reply Last reply Reply Quote 0
        • F Offline
          FrankZappa @fireodo
          last edited by FrankZappa

          @fireodo Yes, I have the @ replaced already.

          Here's my URL (with email and code removed)
          https://myemail%40hotmail.com:MyCode@faf.bambenekconsulting.com/feeds/dga/c2-dommasterlist-high.txt

          fireodoF 1 Reply Last reply Reply Quote 0
          • fireodoF Offline
            fireodo @FrankZappa
            last edited by fireodo

            @FrankZappa said in How to set up Bambenek malicious IP table on pfBlocker:

            @fireodo Yes, I have the @ replaced already.

            What happend if you call the Url in a browser?

            When I call your feed (with my credentials) I get this (browser call):
            bambenek.png

            Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
            SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
            pfsense 2.8.1 CE
            Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

            F 1 Reply Last reply Reply Quote 0
            • F Offline
              FrankZappa @fireodo
              last edited by

              @fireodo I get the same thing in a browser

              fireodoF 1 Reply Last reply Reply Quote 0
              • fireodoF Offline
                fireodo @FrankZappa
                last edited by

                @FrankZappa said in How to set up Bambenek malicious IP table on pfBlocker:

                @fireodo I get the same thing in a browser

                That means it has to work - does pfblockerNG shows some errors in the logs?

                Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                pfsense 2.8.1 CE
                Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                F 1 Reply Last reply Reply Quote 0
                • F Offline
                  FrankZappa @fireodo
                  last edited by

                  @fireodo No errors, but it doesn't appear to be working on the pfBlocker widget

                  d13a4d2b-5609-4527-bbd9-df0d4dd8140c-image.png

                  fireodoF 1 Reply Last reply Reply Quote 0
                  • fireodoF Offline
                    fireodo @FrankZappa
                    last edited by fireodo

                    @FrankZappa I see - the last time (in my case) it was updated on 30.11.25:
                    bambenek.png

                    Here is my URL in pfblockerNG:

                    https://name%40mail.net:mycode@faf.bambenekconsulting.com/feeds/dga/dga-feed-high.csv.gz

                    PS. pfblockerNG version: 3.2.8

                    Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                    SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                    pfsense 2.8.1 CE
                    Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                    F 1 Reply Last reply Reply Quote 0
                    • F Offline
                      FrankZappa @fireodo
                      last edited by

                      @fireodo Thanks, I tried your URL with my credentials. Still no Joy. Not sure what gives

                      fireodoF 1 Reply Last reply Reply Quote 0
                      • fireodoF Offline
                        fireodo @FrankZappa
                        last edited by

                        @FrankZappa said in How to set up Bambenek malicious IP table on pfBlocker:

                        @fireodo Thanks, I tried your URL with my credentials. Still no Joy. Not sure what gives

                        Hmmmmm ...

                        Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                        SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                        pfsense 2.8.1 CE
                        Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                        BBcan177B 1 Reply Last reply Reply Quote 0
                        • BBcan177B Offline
                          BBcan177 Moderator @fireodo
                          last edited by

                          Could be rate limiting on their feed. Disable the feed for 24hrs and try again. Or send them a support email with your IP.

                          "Experience is something you don't get until just after you need it."

                          Website: http://pfBlockerNG.com
                          Twitter: @BBcan177  #pfBlockerNG
                          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                          F 1 Reply Last reply Reply Quote 1
                          • F Offline
                            FrankZappa @BBcan177
                            last edited by

                            @BBcan177 I requested new credentials from Bambenek. However, it doesn't appear to update. I still have the old white text labeled feed. Not sure if I'm entering the setup correctly. Does anyone know what I'm doing wrong?

                            59bda69b-ba7f-40c2-8559-01b8529fcf6a-image.png

                            fireodoF 1 Reply Last reply Reply Quote 0
                            • fireodoF Offline
                              fireodo @FrankZappa
                              last edited by

                              @FrankZappa said in How to set up Bambenek malicious IP table on pfBlocker:

                              However, it doesn't appear to update.

                              For me it looks like it have updated on 20.12.2025 at midnight:
                              1766246726489-59bda69b-ba7f-40c2-8559-01b8529fcf6a-image.png
                              and has 603411 entrys. DNSBL Feeds are white because they are not Aliases in the Firewall.
                              If you want you can look at "/var/db/pfblockerng/dnsblorig" if the Bambenek Feed is populated and on the file-timestamp you can also see when.

                              my 2 cents,
                              fireodo

                              Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                              SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                              pfsense 2.8.1 CE
                              Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                              F 1 Reply Last reply Reply Quote 0
                              • F Offline
                                FrankZappa @fireodo
                                last edited by FrankZappa

                                @fireodo Thanks. I caught the update time after I hit send. So it does appear to update. Thanks for the explanation on feed being in white because they're not aliases. I did check the /var/db/pfblockerng/dnsblorig per your suggestion. However, there's nothing in there.

                                cfe7d933-b677-4595-bd90-769c5ef17008-image.png

                                fireodoF 2 Replies Last reply Reply Quote 0
                                • fireodoF Offline
                                  fireodo @FrankZappa
                                  last edited by

                                  @FrankZappa said in How to set up Bambenek malicious IP table on pfBlocker:

                                  Thanks again.

                                  You're welcome!

                                  Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                                  SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                                  pfsense 2.8.1 CE
                                  Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                                  1 Reply Last reply Reply Quote 0
                                  • fireodoF Offline
                                    fireodo @FrankZappa
                                    last edited by

                                    @FrankZappa said in How to set up Bambenek malicious IP table on pfBlocker:

                                    However, there's nothing in there.

                                    Hummm ... should not be empty ... what you see in:

                                    /var/db/pfblockerng/dnsbl

                                    Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                                    SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                                    pfsense 2.8.1 CE
                                    Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                                    F 1 Reply Last reply Reply Quote 0
                                    • F Offline
                                      FrankZappa @fireodo
                                      last edited by

                                      @fireodo also empty.
                                      5e433a77-cf81-4b7e-9bf9-0c57352766ed-image.png

                                      F 1 Reply Last reply Reply Quote 0
                                      • F Offline
                                        FrankZappa @FrankZappa
                                        last edited by

                                        The log file on update shows the following:
                                        04a01921-7954-4516-ab43-3b74abf9eed1-image.png

                                        Not sure why it says "no domain found" and at the bottom it shows the header file is in "static hold" whatever that means.

                                        BBcan177B fireodoF 2 Replies Last reply Reply Quote 0
                                        • BBcan177B Offline
                                          BBcan177 Moderator @FrankZappa
                                          last edited by

                                          @FrankZappa I think that feed is an IP based feed

                                          "Experience is something you don't get until just after you need it."

                                          Website: http://pfBlockerNG.com
                                          Twitter: @BBcan177  #pfBlockerNG
                                          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                                          1 Reply Last reply Reply Quote 2
                                          • fireodoF Offline
                                            fireodo @FrankZappa
                                            last edited by

                                            @FrankZappa said in How to set up Bambenek malicious IP table on pfBlocker:

                                            The log file on update shows the following:

                                            Maybe you try another domain feed from the Bambenek Site:
                                            https://faf.bambenekconsulting.com/feeds/dga/

                                            PS. Whats your pfsense/pfblockerng version?

                                            Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
                                            SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
                                            pfsense 2.8.1 CE
                                            Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

                                            F 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.