Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    pfBlockerNG-Devel 3.2.14 - try blocking pornsite

    Scheduled Pinned Locked Moved pfBlockerNG
    7 Posts 3 Posters 2.6k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • antgallaA Offline
      antgalla
      last edited by

      Re: PFblockerng-devel

      I am trying to block pornsite using pfBlockerNG DNSBL via a custom DNSBL group list (with the Action set to Unbound). I have also configured a firewall rule to force and redirect all network DNS requests back to pfSense.However, the website is still accessible and the block is not working as intended. Could you please review my setup to see if there is something I missed or configured incorrectly?

      SteveITSS 1 Reply Last reply Reply Quote 0
      • SteveITSS Offline
        SteveITS Rebel Alliance @antgalla
        last edited by SteveITS

        @antgalla can you post some screenshots? (Of the rules not the porn)

        DNS recipes are at https://docs.netgate.com/pfsense/en/latest/recipes/index.html#dns

        To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
        Only install packages for your version of pfSense.
        Upvote 👍 helpful posts!

        antgallaA 1 Reply Last reply Reply Quote 0
        • antgallaA Offline
          antgalla @SteveITS
          last edited by

          @SteveITS , its working now. But I need to force all browsers to disabled "Use Private DNS" to work the blocking

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG Offline
            Gertjan @antgalla
            last edited by Gertjan

            @antgalla said in pfBlockerNG-Devel 3.2.14 - try blocking pornsite:

            But I need to force all browsers to disabled "Use Private DNS" to work the blocking

            You mean, you had to select manually :

            65240c05-7804-4652-ae5b-236bdce458da-image.png

            This is the Firefox DNS setting, other browser have the same DNS selections options.
            Default is probably the "Default Protection", which means : my browser, and your browser will first use the DNS the offers the most money (for your dns requests).
            This means that by default, you can do what you want : installing pfBlockerng, use a pihole, do whatever you want, but the DNS requests will go to some DNS resolver somewhere on the internet, and you don't control (filter) that DNS server.

            Btw : I haven't tried this :
            When you activate : pfSense : Firewall > pfBlockerNG > DNSBLDNSBL > SafeSearch
            and select them all :

            e80c78c5-2212-491a-95ef-d2415fef944f-image.png

            then the/my browser can't use DoH/DoT and would probably fall back by using the DNS that the device got when asking for a DHCP lease, which would (should !) be 192.168.1.1 or the pfSense resolver.
            But this is probably Firefox doing so. Most other browser (you know who they are) will insist in talking to some upstream commercial tracker ... euh DNS resolver.

            edit :

            You probably will ask : "Wait, ... if a pfSense LAN device can pick it's own DNS server (any DNS server on the Internet), it will bypass my pfSense for it's (all) DNS request ?" and that's right.
            It all boils down to : it's doesn't matter what you know and don't know about DNS, but what the end user (LAN) knows ^^ (they also use Google, social media ans AI now)
            Your mission : know more then them about this DNS subject.
            When you're ready, go read this one : Redirecting Client DNS Requests

            No "help me" PM's please. Use the forum, the community will thank you.

            antgallaA 1 Reply Last reply Reply Quote 0
            • antgallaA Offline
              antgalla @Gertjan
              last edited by

              @Gertjan yes that's what I mean turn of DNS resolver/Secure DNS in browser.

              But what are the version of ur pfblocker? I have a minimal difference in our gui. pls see photo belowdnsbl.png

              GertjanG 1 Reply Last reply Reply Quote 0
              • GertjanG Offline
                Gertjan @antgalla
                last edited by

                @antgalla

                My pfBlockerng, 3.2.16 (pfBlockerng for pfSense Plus 26.03.1) is 99,9+ % identical.

                20d12c9e-c472-4d70-900a-765327b3e572-image.png

                If you don't use any pfBlockerng's functionalities, activate at least :
                "DoH/DoT/DoQ Blocking" and select everything in "DoH/DoT/DoQ Blocking List"

                No "help me" PM's please. Use the forum, the community will thank you.

                SteveITSS 1 Reply Last reply Reply Quote 0
                • SteveITSS Offline
                  SteveITS Rebel Alliance @Gertjan
                  last edited by

                  @Gertjan said in pfBlockerNG-Devel 3.2.14 - try blocking pornsite:

                  If you don't use any pfBlockerng's functionalities, activate at least :
                  "DoH/DoT/DoQ Blocking"

                  It's been a while since I last tested but in my experience one must enable some list in order to get SafeSearch to actually work. Otherwise AFAICT pfBlocker doesn't bother loading the rest of the DNSBL config. It is sufficient to create a non functional DNSBL Group:

                  name: Placeholder
                  DNSBL Source Definitions: (leave blank)
                  Update Frequency: never
                  DNSBL Custom_List: bogusname.example.com

                  To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
                  Only install packages for your version of pfSense.
                  Upvote 👍 helpful posts!

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.