Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    pfBlockerng->Threatgate migration, how to?

    Scheduled Pinned Locked Moved Netgate Nexus
    10 Posts 4 Posters 490 Views 10 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • beerguzzleB Offline
      beerguzzle
      last edited by

      Netgate 1100, fresh install (via USB installer) of 26.07. So I'm poking around in the Nexus GUI, and pondering Threatgate. It took me a while to get to where I'm at with pfBlockerNG, so I am wondering if there are any how-to guides for migration. I use Maxmind GeoIP to block some foreign countries, and I use ASN assignments for company traffic like Google, Apple, Facebook (I totally block FB traffic in/out, they are evil).

      Does Threatgate work with AS assignments? Can pfBlockerNG and Threatgate both run at the same time during migration?

      The wowee discovery I saw in a Netgate blurb is that they expect people to be using Nexus by the end of the year. Good luck with that.

      Netgate 1100 and Netgate 2100, latest pfsense+ version

      tinfoilmattT 1 Reply Last reply Reply Quote 0
      • tinfoilmattT Offline
        tinfoilmatt LAYER 8 @beerguzzle
        last edited by

        The wowee discovery I saw in a Netgate blurb is that they expect people to be using Nexus by the end of the year.

        Where is that?

        block out log on { ix0 } inet from any to any
        block out log on { ix0 } inet6 from any to any

        1 Reply Last reply Reply Quote 0
        • beerguzzleB Offline
          beerguzzle
          last edited by

          “The new GUI for pfSense Plus” on https://netgate.com/blog , dated August 3, 2026. Third paragraph in the section “Accessing the new GUI”. I choked when I saw that. Converting from pfbockerng to threatgate looks non-trivial and a lot of people rely on pfblocker. So a conversion guide would be a big help.

          Netgate 1100 and Netgate 2100, latest pfsense+ version

          1 Reply Last reply Reply Quote 1
          • beerguzzleB Offline
            beerguzzle
            last edited by

            I'll expand this blurb to request a general how-to on migrating from the PHP interface to Nexus, in terms of coreDNS/zero-trust and Threatgate. In my case, I'm using unbound and pfblocker. I'm still staring at the netgate docs for Nexus. I would guess that the sequence would be, per Configuring CoreDNS:

            • move unbound to port 5353
            • enable CoreDNS at port 53, so it does resolution first, then unbound second
            • test DNS
            • turn on zero trust egress mode, futz with firewall rules for that, test
            • then turn on Threatgate and migrate from pfblocker to Threatgate (how?)
            • when happy, turn off unbound and pfblockerng and embrace the new Nexus regime..

            Netgate 1100 and Netgate 2100, latest pfsense+ version

            1 Reply Last reply Reply Quote 0
            • beerguzzleB Offline
              beerguzzle
              last edited by

              After staring at the "Configuring the CoreDNS Service" some more I'm confused. Does that doc put CoreDNS first on port 53 and unbound behind it at 5353? If CoreDNS doesn't get an answer, then the query is sent on to unbound? What's the reason for running both DNS servers?

              So I tried the "Easy Setup" in Services/CoreDNS. Yup, it shut off unbound and turned on CoreDNS. Before I did this, I used "sockstat -p 53" to see what process was locked onto port 53. With unbound:

              unbound unbound 84750 3 udp6 *:53 :
              unbound unbound 84750 4 tcp6 *:53 :
              unbound unbound 84750 5 udp4 *:53 :
              unbound unbound 84750 6 tcp4 *:53 :

              After doing the Easy Setup, things looked like so:

              root pfnet-cont 52294 24 tcp4 127.0.0.1:53 :
              root pfnet-cont 52294 26 udp4 127.0.0.1:53 :
              root pfnet-cont 52294 27 tcp6 [::1]:53 :
              root pfnet-cont 52294 28 udp6 [::1]:53 :

              Unbound listens from queries from anywhere but CoreDNS only listens on loopback?? What good is that for having your clients get DNS? Can somebody explain what CoreDNS is really doing?

              Netgate 1100 and Netgate 2100, latest pfsense+ version

              1 Reply Last reply Reply Quote 0
              • M Offline
                mcury Rebel Alliance
                last edited by

                I wouldn't do that.
                ThreatGate is not ready yet.

                dead on arrival, nowhere to be found.

                JeGrJ 1 Reply Last reply Reply Quote 2
                • beerguzzleB Offline
                  beerguzzle
                  last edited by

                  I've come to the conclusion that CoreDNS isn't ready for primetime either. A critical service that you can't see (either in a services widget or in the process list) and only listens to loopback by default? Useless! I've turned off the Nexus controller since I don't need it except for playing around.

                  BTW, I had the Nexus controller bring my 1100 to its knees yesterday. I was logged into both the Nexus and PHP interfaces at the same time, comparing views, plus a terminal shell. Things got really sluggish. Top told me that pfm-controller was running at 190%, load about 6, almost no memory free, had to reboot to get things normal again.

                  Netgate 1100 and Netgate 2100, latest pfsense+ version

                  1 Reply Last reply Reply Quote 0
                  • JeGrJ Offline
                    JeGr LAYER 8 Moderator @mcury
                    last edited by

                    @mcury said in pfBlockerng->Threatgate migration, how to?:

                    I wouldn't do that.
                    ThreatGate is not ready yet.

                    I'd point to my thread (or my last post) here for that.

                    https://forum.netgate.com/post/1247607

                    It's not remotely ready for production as it won't even show you when it is doing things right or wrong, doesn't display stats, logs or status, doesn't create aliases the correct way, cuts lists after 5k entries, won't show when they were last refreshed etc etc, It's missing so much right now, that it would've been better to still label it as a beta feature and release it in the next release with much more work instead of the hot mess it is right now.

                    Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

                    If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

                    1 Reply Last reply Reply Quote 1
                    • beerguzzleB Offline
                      beerguzzle
                      last edited by

                      I would further argue that Nexus itself isn't ready yet, just because of the lack of a complete Dashboard widget set. If I wanted to use Nexus for just for remote management, I would want it to display the same or equivalent Dashboard remotely as what I would see from the PHP Dashboard when logged on locally. It can't even do that. Sheesh.

                      Netgate 1100 and Netgate 2100, latest pfsense+ version

                      JeGrJ 1 Reply Last reply Reply Quote 1
                      • JeGrJ Offline
                        JeGr LAYER 8 Moderator @beerguzzle
                        last edited by

                        @beerguzzle said in pfBlockerng->Threatgate migration, how to?:

                        I would further argue that Nexus itself isn't ready yet, just because of the lack of a complete Dashboard widget set. If I wanted to use Nexus for just for remote management, I would want it to display the same or equivalent Dashboard remotely as what I would see from the PHP Dashboard when logged on locally. It can't even do that. Sheesh.

                        You'd hear no argue against that from me. Missing dashboard overview stuff like widgets, status displays etc. is only icing on the cake really. For us it even starts below that with boxes that are licensed or paying TAC lite for running plus now unable to access all functionality of Nexus just because of some random serial number field not set up or running in a VM on a non-silicon-valley-cloud is getting really strange.

                        Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

                        If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                        Privacy Policy · Cookie Policy