PfBlockerNG
-
Hey BBScan177,
I looked at the lists you suggested below. I've looked at them before but ignored them. Can you answer 2 questions?
- On pfBlockerNG it says you can comment out stuff using a # sign. The lists below use a semi colon. Will they still work?
- Lots of people use Google and Yahoo for spamming. I checked the MX record IPs for Google and they weren't listed on either list. Do you know if they ever get put on? The reason I ask is that a lot of people use Gmail.
http://www.spamhaus.org/drop/edrop.txt
http://www.spamhaus.org/drop/drop.txtThis is great!
Lol.. ok for one… BBCan not BBScan ... (you owe me like +100 Karma for my identity crisis!)
The lists that I recommended are all well established lists. You shouldn't have too much trouble with them.
The parsing of the lists will skip any line that starts with a "#". The Spamhaus list parsing is not affected by that trailing ";".
In the Custom Box entry of the Alias, you can enter an IP and follow that with a "#" to allow you to enter a description. This makes it easier to remember months later, why you put an IP in the Custom Box in the first place.
The Spamhaus list will not affect Google/Yahoo. You can readup on the "Spamhaus" blocklists here… https://www.spamhaus.org/drop/
-
Okay BBCan177,
How do I issue karma points on this? I took speed reading when in high school. You can see how much good it did me! lol
Okay, I didn't comprehend what was written on phBlockerNG. Again, this must have to do with my speed reading!
-
Is the CRON suppose to run hourly? If so then why?
-
Is the CRON suppose to run hourly? If so then why?
https://forum.pfsense.org/index.php?topic=86212.msg492936#msg492936
-
pfBlockerNG can't even import the DROP and EDROP lists from Spamhaus. Is there any way to use the old pfBlocker on pfSense 2.2 (package does not seem to be available)?
-
-
pfBlockerNG can't even import the DROP and EDROP lists from Spamhaus. Is there any way to use the old pfBlocker on pfSense 2.2 (package does not seem to be available)?
I think you have mis-configured something in your setup! As there is no issue with those lists. What errors or symptoms do you see in the logs?
-
I think you have mis-configured something in your setup! As there is no issue with those lists.
+1, zero issues with Spamhaus (e)drop.
-
Lazy man's feature request: can you make the widget's aliases clickable? Like, show what's in the alias on hover (like when you hover in Firewall - Rules) and edit the alias when the row is double-clicked. :D
-
So I just tried to use TeamViewer and Pfblockerng is blocking it. Not sure what list but don’t want to disable the whole list just for TeamViewer, so I went in and added www.teamviewer.com into the alias list and it still isn’t working. I figured I added the wrong thing so I thought I would come here and ask if anyone knows how to add TeamViewer to the alias list and keep it from being blocked?
-
Generic hint: Only use such blocklists that fit your needs and that you are able to manage…
-
Why not push the pass of teamviewer to the top of the list so it doesnt hit the block list before the passlist?? ;)
-
Why not push the pass of teamviewer to the top of the list so it doesnt hit the block list before the passlist?? ;)
Where exactly do I go to do that? I still very new with pfsense so please bare with me…
-
So I just tried to use TeamViewer and Pfblockerng is blocking it.
You need to look at the Alerts Tab and see which List is blocking it.
I came across this issue before with TeamViewer and for that case, it was being blocked by a Country Block.. (One of the Top20)You also can't use an alias in the Custom Input settings. They have to be IP addresses.
Try to ping www.teamviewer.com from your desktop and take a look for what is blocking it in the Alerts Tab.
-
Generic hint: Only use such blocklists that fit your needs and that you are able to manage…
Its actually one of the Top 20 sites that is blocking it not one of the list I imported..
-
Add that Blocked IP to a Whitelist Alias. I described how to do that in a post this morning.
-
Something I found out the hard way :), if you comment an IP address/range in IPv4 Custom Address(es) with a #, then it is still active.
For some tests I added the Google address range to an alias list.74.125.0.0/16 # 1e100.net - (Google)
Then I commented it after the testing for later use.
This worked fine in pfBlocker but when I moved the alias list to pfBlockerNG my Nexus 7 could not connect to Google Play anymore.
Kept me confused for a while until I remembered this commented out entry.
I mention it because it may confuse others. -
Add that Blocked IP to a Whitelist Alias. I described how to do that in a post this morning.
That worked thanks!
-
It's strange that there are no aliases. (url tables) listed? Are you sure you checked it properly?
Try to run this command from the shell :
pfctl -sa (and at the end of the output, do you see any pfblocker tables?)
Also try to delete all files in
/var/db/aliastables (then reboot)
Thank BBcan117,
Your post made it clear to me… I kept thinking I was to delete aliases from WebGUI "Firewall" > "Aliases". I now realize I need to delete aliases from /var/db/aliastables/
I've done as you suggested, and I think it is working... So far, no error messages. I'll wait a day to recheck.
Thanks again. -
What am I doing wrong????
Just when I think I'm doing great, I see I'm messing up.
I had China blocked in Country block. I've added 6 lists for and all seemed good. Now I'm getting nailed from China. I see that in County Block China is no longer listed. China by it's self does more than everyone else put together!
Help!