Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Issues with 25.11 latest patches and latest pfBlockerNG

    Scheduled Pinned Locked Moved pfBlockerNG
    23 Posts 10 Posters 3.9k Views 12 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      dstacey147
      last edited by

      Running 25.11, just update lastest system patches and PFBlockerNG, now I'm encounting a ton of these notices:

      PHP {$errortype}s

      PHP ERROR: Type: 1, File: /usr/local/pkg/pfblockerng/pfblockerng.inc, Line: 6245, Message: Uncaught TypeError: SQLite3::busyTimeout(): Argument #1 ($milliseconds) must be of type int, string given in /usr/local/pkg/pfblockerng/pfblockerng.inc:6245
      Stack trace:
      #0 /usr/local/pkg/pfblockerng/pfblockerng.inc(6245): SQLite3->busyTimeout()
      #1 /usr/local/pkg/pfblockerng/pfblockerng.inc(5566): pfb_open_sqlite()
      #2 /usr/local/pkg/pfblockerng/pfblockerng.inc(1114): pfb_daemon_filterlog()
      #3 {main}
      thrown @ 2025-12-22 17:39:21
      PHP ERROR: Type: 1, File: /usr/local/pkg/pfblockerng/pfblockerng.inc, Line: 6245, Message: Uncaught TypeError: SQLite3::busyTimeout(): Argument #1 ($milliseconds) must be of type int, string given in /usr/local/pkg/pfblockerng/pfblockerng.inc:6245
      Stack trace:
      #0 /usr/local/pkg/pfblockerng/pfblockerng.inc(6245): SQLite3->busyTimeout()
      #1 /usr/local/pkg/pfblockerng/pfblockerng.inc(5566): pfb_open_sqlite()
      #2 /usr/local/pkg/pfblockerng/pfblockerng.inc(1114): pfb_daemon_filterlog()
      #3 {main}
      thrown @ 2025-12-22 17:40:07
      
      G 1 Reply Last reply Reply Quote 1
      • S Offline
        SakuraChan00
        last edited by

        I am seeing the same thing, my IPv6 is still borked for pkg update/etc

        1 Reply Last reply Reply Quote 0
        • D Offline
          dstacey147
          last edited by

          The issue appearas to be with pfBlockerNG itself, I uninstalled the latest system patches and rebooted, and still get the same errors, uninstalled pfBlockerNG and they go away. Guess I live with ads until they figure it out :-/

          1 Reply Last reply Reply Quote 0
          • G Offline
            gseidler @dstacey147
            last edited by

            I'm having the same errors. Disabled pfBlocker for now until they get this sorted.

            1 Reply Last reply Reply Quote 0
            • M Offline
              marcosm Netgate
              last edited by

              Please try the new version.

              G 1 Reply Last reply Reply Quote 0
              • G Offline
                gseidler @marcosm
                last edited by

                @marcosm no more errors here so far. Thanks!

                1 Reply Last reply Reply Quote 2
                • D Offline
                  dauhee
                  last edited by

                  on version 3.2.13_3 (pfBlockerNG-devel) and have the same issue. No newer version available for me.

                  D 1 Reply Last reply Reply Quote 0
                  • D Offline
                    dstacey147 @dauhee
                    last edited by

                    @dauhee All good here after the 3.2.13_3 update. I uninstalled then reinstalled pfBlockerNG, then rebooted pfsense.

                    1 Reply Last reply Reply Quote 1
                    • M Offline
                      marcosm Netgate
                      last edited by

                      I do see one other way the error can happen. I've just patched that one as well. That should be all of them but I'll keep an eye for any additional reports. Thanks!

                      1 Reply Last reply Reply Quote 0
                      • tinfoilmattT tinfoilmatt referenced this topic on
                      • S Offline
                        Squuiid
                        last edited by

                        Is the consensus now that is fully resolved? Have been holding off updating to 25.11 until the pfblockerNG issues have quietened down, as it tends to be the one that has issues post upgrades.

                        D S 2 Replies Last reply Reply Quote 0
                        • D Offline
                          dstacey147 @Squuiid
                          last edited by

                          @Squuiid Yes, it appears to be fully resolved. I've not had it reoccur since installing the latest (3.2.13_4) pfBlockerNG and I've been running it 5 days now (since shortly after it's release)

                          1 Reply Last reply Reply Quote 1
                          • T Offline
                            tman222
                            last edited by

                            I'm still running into an odd issue where the tables created from IP lists in pfBlockerNG are deleted but not recreated. It seems I can trigger this behavior by toggling a firewall (off or on). The next time pfBlockerNG runs (i.e. it's next hourly scheduled run), the tables are gone, and the widget shows no IP lists loaded. Hovering over the widget it just says "pf errors". To get things back into a working state, I use the Reload option in pfBlockerNG to reload the IP lists, and by doing so the tables are recreated and everything is fine after that. Any ideas what could be causing this? Thanks in advance.

                            tinfoilmattT 1 Reply Last reply Reply Quote 0
                            • tinfoilmattT Offline
                              tinfoilmatt LAYER 8 @tman222
                              last edited by

                              @tman222 pfblockerng.log?

                              T 1 Reply Last reply Reply Quote 0
                              • T Offline
                                tman222 @tinfoilmatt
                                last edited by

                                @tinfoilmatt - I looked through that for relevant information, but all I can see is lines like these:

                                CRON  PROCESS  START [ v3.2.13_4 ] [ 12/25/25 12:15:00 ]
                                pfctl: Table does not exist.
                                pfctl: Table does not exist.
                                pfctl: Table does not exist.
                                pfctl: Table does not exist.
                                pfctl: Table does not exist.
                                pfctl: Table does not exist.
                                
                                  No Updates required.
                                 CRON  PROCESS  ENDED
                                 UPDATE PROCESS ENDED
                                

                                I think the pfctl line shows up six times because I have six IP lists.

                                It also shows this for table usage count after an update:

                                pfSense Table Stats
                                -------------------
                                table-entries hard limit  2000000
                                Table Usage Count         NA
                                
                                

                                Any ideas of what might be going on? Thanks again.

                                tinfoilmattT 1 Reply Last reply Reply Quote 0
                                • tinfoilmattT Offline
                                  tinfoilmatt LAYER 8 @tman222
                                  last edited by

                                  @tman222 Try a Force Reload | Reload All. Ensure no "CRON Event" is running or scheduled to run within a conflicting time.

                                  T 1 Reply Last reply Reply Quote 0
                                  • T Offline
                                    tman222 @tinfoilmatt
                                    last edited by

                                    @tinfoilmatt said in Issues with 25.11 latest patches and latest pfBlockerNG:

                                    @tman222 Try a Force Reload | Reload All. Ensure no "CRON Event" is running or scheduled to run within a conflicting time.

                                    Hi @tinfoilmatt - Yes, after I see this issue occur (i.e. deleted tables), I can fix it via Force Reload / Reload All, which recreates the tables and populates them. It's not clear to me though why the tables are getting deleted in the first place during a subsequent pfBlockerNG update that comes after toggling a firewall rule. Thanks again.

                                    T 1 Reply Last reply Reply Quote 0
                                    • T Offline
                                      tman222 @tman222
                                      last edited by

                                      I'm starting to wonder if I'm just hitting an edge related to this outstanding issue with pfctl:

                                      https://redmine.pfsense.org/issues/16588

                                      M 1 Reply Last reply Reply Quote 0
                                      • M Offline
                                        marcosm Netgate @tman222
                                        last edited by

                                        @tman222 That's unlikely - the latest pfBlockerNG version has a workaround for that.

                                        I can trigger this behavior by toggling a firewall (off or on).

                                        Presumably you mean "firewall rule". When an alias is configured but not used in any rules, its unloaded from pf and that can result in the "pfctl: Table does not exist." message e.g. when running pfctl -t example -Tshow. I expect for pfBlockerNG to handle that case though, otherwise we'd likely have seen many similar reports. Personally I use the lists in alias mode and configure the rules myself; I expect that to work around the issue you're experiencing. If you can reproduce it, provide detailed and exact steps to do so.

                                        Note: the automatic rule management from pfBlockerNG doesn't handle separators and hence they'll become unaligned.

                                        1 Reply Last reply Reply Quote 1
                                        • S Offline
                                          Stonework4958 @Squuiid
                                          last edited by

                                          I just upgraded to 25.11 and it seems having pfblocker enabled causes my DNS resolver to become non-responsive.

                                          A snippet from my pfblockerng.log:

                                          TLD finalize... completed [ 01/17/26 04:14:47 ]
                                          
                                          Saving DNSBL statistics... completed [ 01/17/26 04:16:01 ]
                                          Reloading Unbound Resolver (DNSBL python).
                                          Stopping Unbound Resolver.........................
                                          **Saving configuration [ 01/17/26 04:26:22 ]**
                                          
                                          Removing DNSBL Unbound python integration settings...
                                          DNS Resolver ( disabled ) unbound.conf modifications:
                                            Removed DNSBL Unbound Python mode
                                            Removed DNSBL Unbound Python mode script
                                          Stop Service DNSBL
                                          
                                          Stopping Unbound Resolver.....
                                          Starting Unbound Resolver..
                                          DNSBL enabled FAIL  *** Fix error(s) and a Force Reload required! ***
                                          
                                          
                                          ====================
                                          
                                          [1768641990] unbound[90804:0] warning: setsockopt(..., SO_SNDBUF, ...) was not granted: No buffer space available
                                          [1768641990] unbound[90804:0] warning: so-sndbuf 4194304 was not granted. Got 57344. To fix: start with root permissions(linux) or sysctl bigger net.core.wmem_max(linux) or kern.ipc.maxsockbuf(bsd) values. or set so-sndbuf: 0 (use system value).
                                          [1768641990] unbound[90804:0] error: bind: address already in use
                                          [1768641990] unbound[90804:0] fatal error: could not open ports
                                          
                                          ====================
                                          
                                          
                                          Stopping Unbound Resolver......................................................
                                          Removing DNSBL Unbound python mounts:
                                            Unmounting: /usr/local/bin
                                            Removing: /var/unbound/usr/local/bin
                                            Unmounting: /usr/local/lib
                                            Removing: /var/unbound/usr/local/lib
                                            Removing: /var/unbound/usr/local
                                            Removing: /var/unbound/usr
                                          
                                          Starting Unbound Resolver.
                                          DNSBL disabled - Unbound conf update FAIL *** Fix error(s) and a Force Reload required! ***
                                          
                                          
                                          ====================
                                          
                                          [1768642024] unbound[61579:0] warning: setsockopt(..., SO_SNDBUF, ...) was not granted: No buffer space available
                                          [1768642024] unbound[61579:0] warning: so-sndbuf 4194304 was not granted. Got 57344. To fix: start with root permissions(linux) or sysctl bigger net.core.wmem_max(linux) or kern.ipc.maxsockbuf(bsd) values. or set so-sndbuf: 0 (use system value).
                                          [1768642024] unbound[61579:0] error: bind: address already in use
                                          [1768642024] unbound[61579:0] fatal error: could not open ports
                                          
                                          ====================
                                          
                                          
                                          Stopping Unbound Resolver....
                                          Starting Unbound Resolver.............................
                                          Removing DNSBL Unbound python mounts:
                                            Removing: /var/unbound/usr/local
                                            Removing: /var/unbound/usr
                                          
                                          Starting Unbound Resolver.. Not completed. [ 01/17/26 04:29:20 ]
                                          [1768642069] unbound[13160:0] warning: setsockopt(..., SO_SNDBUF, ...) was not granted: No buffer space available
                                          [1768642069] unbound[13160:0] warning: so-sndbuf 4194304 was not granted. Got 57344. To fix: start with root permissions(linux) or sysctl bigger net.core.wmem_max(linux) or kern.ipc.maxsockbuf(bsd) values. or set so-sndbuf: 0 (use system value).
                                          [1768642069] unbound[13160:0] error: bind: address already in use
                                          [1768642069] unbound[13160:0] fatal error: could not open ports
                                          error: SSL handshake failed
                                          . Not completed. [ 01/17/26 04:29:20 ]
                                          [1768642028] unbound[64568:0] warning: setsockopt(..., SO_SNDBUF, ...) was not granted: No buffer space available
                                          [1768642028] unbound[64568:0] warning: so-sndbuf 4194304 was not granted. Got 57344. To fix: start with root permissions(linux) or sysctl bigger net.core.wmem_max(linux) or kern.ipc.maxsockbuf(bsd) values. or set so-sndbuf: 0 (use system value).
                                          [1768642028] unbound[64568:0] error: bind: address already in use
                                          [1768642028] unbound[64568:0] fatal error: could not open ports
                                          error: SSL handshake failed
                                          
                                          Removing DNSBL Unbound python mounts:
                                            Removing: /var/unbound/usr/local
                                            Removing: /var/unbound/usr
                                          
                                          DNSBL is disabled
                                          
                                          *** DNSBL update [ 0 ] [ 1115987 ] ... OUT OF SYNC ! *** [ 01/17/26 04:29:22 ]
                                          

                                          This tanked my network. Ideally, pfblockerng would have a configurable option to fallback to the previous working config when reloading unbound fails.

                                          Interestingly, System > Advanced > System Tunables > kern.ipc.maxsockbuf is already set to 4262144 which is higher than what was requested. We also see bind errors which might mean pfblocker is attempting to start unbound before it has fully stopped? I'm not exactly sure what is happening in the log... But the end result is unbound stops responding and I have to disable pfblockerng or reboot the entire system (which only works until the next cron).

                                          S 1 Reply Last reply Reply Quote 0
                                          • S Offline
                                            Stonework4958 @Stonework4958
                                            last edited by

                                            Update:

                                            I upped my kern.ipc.maxsockbuf to 8388608 (8m) and added some custom options to my dns resolver unbound custom options:

                                            so-sndbuf: 6m
                                            so-rcvbuf: 6m
                                            

                                            This seems to have resolved my issue. But I'd still definitely consider the failed reload behavior as a bug that should be handled.

                                            GertjanG 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                                            Privacy Policy · Cookie Policy