Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    pfBlockerNG blocked access to pfsense

    Scheduled Pinned Locked Moved pfBlockerNG
    4 Posts 2 Posters 250 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      Doody
      last edited by

      This morning I had no internet access and couldn't even ping my pfsense routers IP address at 192.168.1.1 from the LAN so I had to power cycle the router and after a reboot I was able to access the internet again, I tried to login to the router to atttempt to figure out what happened and was greeted with a block page with the message (I also tried from different clients on the LAN)

      Referer Client Type Group Evaluated Domain Feed
      Unknown 192.168.1.84 Unknown Unknown Unknown Unknown

      I had to restore to a previous configuration from the pfsense shell to get back into the pfsense web interface and have immediately disabled PfblockNG for the time being.

      What's the best way to determine what happened here and resolve the problem so I can re-enable PfblockNG?

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG Offline
        Gertjan @Doody
        last edited by

        @Doody

        If a LAN device "92.168.1.84"can't even ping "192.168.1.1" (pfSense, right ?), and you think it's pfBlocker ... that's quiet impressive.

        Visiting the pfSense web GUI, using "http://192.168.1.1" and you this :

        5dc6db32-4ae5-4458-ba74-7f9580e6383c-image.png

        isn't normal at all.
        Best solution : have a talk with the admin. I don't know what he doing, but we all agree that he might do it's job a bit better ( 😊 )

        As usual :
        What pfSense version ? pfBlockerng version ?
        The fact that IP(s) (and not host names) are blocked, this means you have IP settings (feeds, etc) :
        This page :

        547d93d2-d8c5-40eb-a8fb-8ac92821f3f1-image.png

        and the IPv4, IPv6 etc pages.

        If, by accident, you use a IP feeds that contains "192.168.1.0/24" and you have pfBlockerng filter your LAN, then, yeah, that will be an issue.
        This is just an example of course, IP feeds shouldn't contain RFC1918. networks.

        Shows also your :
        2a7ee0ea-7a28-41fb-af85-7d28fac27297-image.png

        settings.

        My personal advise : use Null blocking :

        956e3c88-1565-4ea3-9f48-5226b9492ca8-image.png

        @Doody said in pfBlockerNG blocked access to pfsense:

        What's the best way to determine what happened here and resolve the problem so I can re-enable PfblockNG?

        Compare the config you used 'before' and the current one.
        The differences will be minor, and all pfBlockerng settings will explain the 'why'.

        Go here : Diagnostics > Configuration History and you see there is a GUI tool just for that.
        ( I never used it myself ^^ )

        No "help me" PM's please. Use the forum, the community will thank you.

        D 1 Reply Last reply Reply Quote 0
        • D Offline
          Doody @Gertjan
          last edited by Doody

          @Gertjan said in pfBlockerNG blocked access to pfsense:

          @Doody

          If a LAN device "92.168.1.84"can't even ping "192.168.1.1" (pfSense, right ?), and you think it's pfBlocker ... that's quiet impressive.

          Well it seems more than a coincidence that I had to power cycle my router and then was unable to access the web interface of my Pfense router as it was blocked by PfblockNG even though I had made no changes to any config.

          I do use IP feeds

          014c8d70-8e8a-4c6f-baca-f13fbcb01f6f-image.png

          So it's highly possible that this IP address had been added during a blocklist update.

          Thanks I will compare the config.

          pfBlockerNG 3.2.8
          pfsense 2.8.1-RELEASE (amd64)

          94000137-6d77-4e0a-8e4a-a2379aec91bc-image.png

          I don't seem to have the option Null block (logging)

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG Offline
            Gertjan @Doody
            last edited by

            @Doody said in pfBlockerNG blocked access to pfsense:

            I don't seem to have the option Null block (logging)

            Go to Firewall > pfBlockerNG > DNSBL and make you you use :

            e477723c-2f9d-445d-b325-e32415b6cbbd-image.png

            and also :

            1b7e3ec8-cf98-4955-8352-d455fa756a09-image.png

            No "help me" PM's please. Use the forum, the community will thank you.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.