PfBlockerNG
-
Check if you still have aliases and rules from pfBlocker version.
If so, remove it.Thanks marcelloc,
I did find a firewall rule that referenced a pfBlocker version and removed it. I don't see any aliases that were used by the old pfBlocker.
This still caused the same error. -
It's strange that there are no aliases. (url tables) listed? Are you sure you checked it properly?
Try to run this command from the shell :
pfctl -sa (and at the end of the output, do you see any pfblocker tables?)
Also try to delete all files in
/var/db/aliastables (then reboot)
-
I just upgraded from pfSense 2.1.5 to 2.2 and pfblocker disappeared from Firewall menu; however, all my blocklists are still there, because pfblocker was setup to use aliases only.
Now:
-
how do I install pfblockerNG? Is pfblockerNG going to recover my config or will I have to enter the settings again? I'm asking just to be sure I'm not going to make a mess…
-
18 block rules are present in my WAN interface Firewall setup (1 row for each IBlockList list I'm using) do I have to manually delete them before installing pfblockerNG?
-
-
You will need to re-configure, as it doesn't share the same settings.
I would recommend that you create aliases with more than one list. No real need to have a rule per list.
If you want to stay with "Alias" rules, you can modify the existing rules from pfblocker, and change the "alias table" setting and change the description to :
pfb_ then the name of the aliastable
(more details in the alias settings tab) -
I created an Alias for each list because, with one "big" list, pfblocker crashed with pfSense's message "PF was wedged/busy and has been reset".
So, I'm going to follow this procedure:
-
delete any previous firewall rule created by pfblocker;
-
delete any Alias also created by pfblocker;
-
enter the setting again in the new package pfblockerNG.
-
-
I created an Alias for each list because, with one "big" list, pfblocker crashed with pfSense's message "PF was wedged/busy and has been reset".
Enable "De-duplication" in the General Tab. You will see the total size of the Block lists shrink substantially.
-
Hey guys,
I set up a few lists from BlockList.de and have it set to run via cron. I'm getting the errors below. What am I doing wrong?
CRON PROCESS START [ 02/21/15 13:00:00 ]
Updates Found
Updates Found
UPDATE PROCESS START[ pfB_Africa_v4 ] exists, Reloading File
[ pfB_Africa_v6 ] exists, Reloading File
[ pfB_Top_v4 ] exists, Reloading File
[ pfB_Top_v6 ] exists, Reloading File[ White Listed IPs_custom ] exists, Reloading File
[ http://lists.blocklist.de/lists/ssh.txt ]
** TERMINATED - Header contains Blank/International/Special or Spaces[ SSH-BlockList_custom ] Loading Custom File
–--------------------------------------------------------
Original Masterfile Outfile [ Post Duplication count ]
–--------------------------------------------------------
952 952 952 [ Passed ]
–--------------------------------------------------------[ http://lists.blocklist.de/lists/ssh.txt ]
** TERMINATED - Header contains Blank/International/Special or Spaces
\ Email-BlockList_custom ] exists, Reloading File===[ Aliastables / Rules ]================================
No Changes to Firewall Rules, Skipping Filter Reload
Updating: pfB_SSHBlockList
no changes.
UPDATE PROCESS ENDED -
Make sure you set the "Header" in the IPv4 tab for each list. The log usually has all the details to diagnose issues.
** TERMINATED - Header contains Blank/International/Special or Spaces
Also - try to use. "https" when possible.
EDIT:
You can't use "-" in the Header field…
-
Okay, BBScan177,
OKay, call me stupid. Okay, very stupid. How do I set the header for each list? When making the list is says to make a unique header. I saw the area and put the same thing in the "header" area as I did for the "List Description" and "List Name". So now that I know that's not correct, what do I do?
Sorry, I feel stupid.
Thanks!
-
I usually setup an Alias for "Malicious", "Ads", "IBlock", "Mail" etc (group common lists into one alias) and for each list enter a unique name for each list/header. If the List source has multiple lists, then use a prefix like so:
blocklistde_ssh
blocklistde_spam -
I am missing something? Attached here is a partial screen cap of what I have set up.
-
Unfortunately you can't use "-" in the header name. I also added that to a previous post above.
-
I"ve read so much on these posts my head spins! I try to go back and look at something that I wanted to research and can't find it.
Thank you very much for letting me know. I appreciate it.
Time to make the changes!
-
Well, most of it worked! But, there is an error below. It doesn't say much for the SSH block list.
I'm sorry, I hope this isn't something stupid again. I'm very excited with the new pfBlockerNG and want to use it to it's fullest! See the attached screen cap.
-
Can you copy that url and test it in the browser?
Some site have rate-limiting if you download too many times. When you test it in the browser, and if you get a rate limiting error, disable that list for 24hrs and then re-enable it.
Blocklist.de also has all those categories in a single download file if you want to try that one.
-
Yes, I was able to copy and paste the url in to my browser and it came up. I did the "All" as you suggested. I'll see if it updates.
What other lists are good to add? I've looked around and it can get confusing. I've seen lists from BlueTack and I-Blocklist. Are they redundant or any good?
The spammers and hackers can sure make things painful.
-
It looks like it updated okay! I'm excited, thank you very much!
Please let me know if there are other lists you consider good and/or use!
-
I posted some Lists here
https://forum.pfsense.org/index.php?topic=86212.msg486648#msg486648Here are a couple more:
http://www.infiltrated.net/blacklisted
http://www.infiltrated.net/webattackers.txtI tried the Blocklist.de (ssh) and it worked fine on my test? Its strange that you had this error?
as that would indicate that the URL was incorrect (localfile).[pfB_SSH_BlockList SSH_BlockList ] Local File Failure
-
Thank you so much for your help. I'm going to play with this some more tomorrow.
Have a great evening!
-
One more question, about Suppress lists:
I noticed that Bluetack Level 1 blocks Apple range of addresses: 17.0.0.0/8
With that list working on pfblockerNG, my iPad can't get software auto updates.
I think that, manual editing the Suppress Alias will not work, because the Help in the "Suppress" sections says:
"A Blocked IP in a CIDR other than /24 will need to be Suppressed by an 'Permit Outbound' Firewall Rule"
So, how do I pass those addresses?