pfBlockerNG-Devel 3.2.14 - try blocking pornsite
-
I am trying to block pornsite using pfBlockerNG DNSBL via a custom DNSBL group list (with the Action set to Unbound). I have also configured a firewall rule to force and redirect all network DNS requests back to pfSense.However, the website is still accessible and the block is not working as intended. Could you please review my setup to see if there is something I missed or configured incorrectly?
-
@antgalla can you post some screenshots? (Of the rules not the porn)
DNS recipes are at https://docs.netgate.com/pfsense/en/latest/recipes/index.html#dns
-
@SteveITS , its working now. But I need to force all browsers to disabled "Use Private DNS" to work the blocking
-
@antgalla said in pfBlockerNG-Devel 3.2.14 - try blocking pornsite:
But I need to force all browsers to disabled "Use Private DNS" to work the blocking
You mean, you had to select manually :

This is the Firefox DNS setting, other browser have the same DNS selections options.
Default is probably the "Default Protection", which means : my browser, and your browser will first use the DNS the offers the most money (for your dns requests).
This means that by default, you can do what you want : installing pfBlockerng, use a pihole, do whatever you want, but the DNS requests will go to some DNS resolver somewhere on the internet, and you don't control (filter) that DNS server.Btw : I haven't tried this :
When you activate : pfSense : Firewall > pfBlockerNG > DNSBLDNSBL > SafeSearch
and select them all :
then the/my browser can't use DoH/DoT and would probably fall back by using the DNS that the device got when asking for a DHCP lease, which would (should !) be 192.168.1.1 or the pfSense resolver.
But this is probably Firefox doing so. Most other browser (you know who they are) will insist in talking to some upstream commercial tracker ... euh DNS resolver.edit :
You probably will ask : "Wait, ... if a pfSense LAN device can pick it's own DNS server (any DNS server on the Internet), it will bypass my pfSense for it's (all) DNS request ?" and that's right.
It all boils down to : it's doesn't matter what you know and don't know about DNS, but what the end user (LAN) knows ^^ (they also use Google, social media ans AI now)
Your mission : know more then them about this DNS subject.
When you're ready, go read this one : Redirecting Client DNS Requests -
@Gertjan yes that's what I mean turn of DNS resolver/Secure DNS in browser.
But what are the version of ur pfblocker? I have a minimal difference in our gui. pls see photo below

-
My pfBlockerng, 3.2.16 (pfBlockerng for pfSense Plus 26.03.1) is 99,9+ % identical.

If you don't use any pfBlockerng's functionalities, activate at least :
"DoH/DoT/DoQ Blocking" and select everything in "DoH/DoT/DoQ Blocking List" -
@Gertjan said in pfBlockerNG-Devel 3.2.14 - try blocking pornsite:
If you don't use any pfBlockerng's functionalities, activate at least :
"DoH/DoT/DoQ Blocking"It's been a while since I last tested but in my experience one must enable some list in order to get SafeSearch to actually work. Otherwise AFAICT pfBlocker doesn't bother loading the rest of the DNSBL config. It is sufficient to create a non functional DNSBL Group:
name: Placeholder
DNSBL Source Definitions: (leave blank)
Update Frequency: never
DNSBL Custom_List: bogusname.example.com