PfBlockerNG
-
Hi, I updated from pfsense 2.2 to 2.2.1 and my pfBlockerng config got wiped. The package was uninstalled and reinstalled according to the logs
pfBlocker package does not exist any more. No configuration from there will be carried over to pfBlockerNG. Restart from scratch.
-
Hi Seqteq,
There is a checkbox in the General Tab called "Keep Settings" that needs to be enabled. On all new installations it has been defaulted to "On".
Its strange that your posted log has "pfBlocker" when it should be "pfBlockerNG"
Ah, thanks I'll check that tomorrow.
Just noticed the ng was missing in the log. I was definitely using ng in 2.2 and ng is definitely what got installed after the 2.2.1 update. iDunno. I adopted 2.2 for this appliance early, before the ng release, but that got replaced like the day after ng dropped. -
There's no way the package would reinstall in 1 second. Probably you have too many boxes to keep track of what actually was there.
-
Hello
Got Something strange with PpBlockerNG on alerts tab
Fatal error: Call to undefined function subnetv6_expand() in /etc/inc/util.inc on line 714
Any idea what is going wrong ?
Thanks
-
pfBlockerNG v1.06 has been Merged by the Devs.
Changelog:
-
Previously when deleting all IPs in the pfBlockerNGSuppress Alias, it would not
clear the widget Suppression Counter. This version fixes that issue as reported by user "Panz". -
Merged recent changes in pfSense diag_dns.php into pfblockerng_diag_dns.php to keep code base current.
-
Change Release to "Stable" from previous "Beta" Status.
Notes -
The issue reported by "stanthewizard" above is partially due to a missing function in pfSense (subnetv6_expand). I expect that I will need to submit a new Pull Request to fix this issue. I provided him a workaround to fix his issue for now.
-
-
And I thank you for that again
-
There's no way the package would reinstall in 1 second. Probably you have too many boxes to keep track of what actually was there.
That was it, it's been a busy year.
-
Hi, Thanks for a great pkg.
I'm having problem with port forwards and UPnP & NAT-PMP.
I use this settings for pfBlockerNG:
Marked all lists
Top 20 and Asia is blocked, both rest blocked inbound.
I have added custom lists from Bluetack ads/proxy/spyware and from Squidblacklist ads. All deny both
Set rule order pfSense pass/match | pfB_pass/match | pfB_block/rejectTIA
-
I'm having problem with port forwards and UPnP & NAT-PMP.
You need to describe what is your problem…
I use this settings for pfBlockerNG:
Marked all lists
Top 20 and Asia is blocked, both rest blocked inbound.What all lists? The country lists? So you blocked whole world inbound, or what? I don't understand your description at all. Plus, block is default on WAN. Are you actually running any service locally that you need to limit access to?
-
I'm having problem with port forwards and UPnP & NAT-PMP.
You need to describe what is your problem…
I use this settings for pfBlockerNG:
Marked all lists
Top 20 and Asia is blocked, both rest blocked inbound.What all lists? The country lists? So you blocked whole world inbound, or what? I don't understand your description at all. Plus, block is default on WAN. Are you actually running any service locally that you need to limit access to?
Never mind, me who has got all wrong :( Changed to outbound only and now it's working
-
I heard there was host blocking option on it's way?
-
I just wanted to drop a thank you for a great package. Runs excellent with all the bells running. Error log is empty.
Thanks again guys. BBcan177 nice job. Your work is appreciated. ;Dps: just finished reading this post in its entirety and what did you guys "NOT" cover. The post is a manual in its own right. Your patience shows. ::)
-
Here is another Threat Source for pfBlockerNG :
This feed is provided by : bambenekconsulting.com
These lists cover the following type of Threats:
-
Banjori
-
Bebloh/URLZone
-
Cryptolocker
-
Cryptowall
-
Dyre
-
Geodo
-
Hesperbot
-
Matsnu
-
Necurs
-
P2P GOZ
-
PT GOZ / New GOZ
-
Pushdo
-
Qakbot
-
Ramnit
-
Symmi
-
Tinba / TinyBanker
Here is a list of all the Feeds available: All Feeds
I would recommend using the two main IP lists which encompass all of the individual Lists:
c2 IP Feed Master Feed of known, active and non-sinkholed C&Cs IP addresses.
c2 All Indicator Feed Master Feed of known, active and non-sinkholed C&Cs indicators
Use the "html" Format to download these Lists. Download frequency of atleast once per day.
** Please read their License and please donate to the charity they run called the "Tumaini Foundation".
If you see Alerts to any of these Lists, please take additional measures to clean up any infections as these IPs are very malicious. So please put these lists into its own Alias.
-
-
«You don't have permission to access /feeds/c2-ipmasterlist.txt on this server.»
-
Hmm, apparently people hammered the poor guys. :D
-
It seems to be fixed now. Post back if you continue to have any issues.
-
If your interested to read up on Bambenek Consultings work:
"The New Scourge of Ransomware: A Study of CryptoLocker and Its Friends"
Published on Mar 19, 2015
By Lance James and John Bambenek
https://www.youtube.com/watch?v=X994Rdt-36oMeat of the video starts at around the 9-10min mark.
-
Here is another Threat Source for pfBlockerNG :
This feed is provided by : bambenekconsulting.com
These lists cover the following type of Threats:
-
Banjori
-
Bebloh/URLZone
-
Cryptolocker
-
Cryptowall
-
Dyre
-
Geodo
-
Hesperbot
-
Matsnu
-
Necurs
-
P2P GOZ
-
PT GOZ / New GOZ
-
Pushdo
-
Qakbot
-
Ramnit
-
Symmi
-
Tinba / TinyBanker
Here is a list of all the Feeds available: All Feeds
I would recommend using the two main IP lists which encompass all of the individual Lists:
c2 IP Feed Master Feed of known, active and non-sinkholed C&Cs IP addresses.
c2 All Indicator Feed Master Feed of known, active and non-sinkholed C&Cs indicators
Use the "html" Format to download these Lists. Download frequency of atleast once per day.
** Please read their License and please donate to the charity they run called the "Tumaini Foundation".
If you see Alerts to any of these Lists, please take additional measures to clean up any infections as these IPs are very malicious. So please put these lists into its own Alias.
Thanks for this and your work on pfBlockerNG; a welcomed upgrade to
pfBlocker.Just started using pflockerNG and have a suggestion. When clicking on
the 'Cancel' button instead of reloading the page, it should take you
back to the previous page. For example, when editing/adding an
alias/list would take you back to the main alias/list page.Maybe others like the current function. Just seems that when canceling
should go to the previous page, a reload does not convey that whatever
was done was canceled.Thank You
-
-
Hi All,
The filter function for the alerts doesn't seem to be working properly (pfSense 2.2.1, pfBlockerNG 1.06).
For example right now when I have a look at my alerts only within the last 2 hours I have 5 entries with destination port 25.
In the total list (500 entries, around 2 days) there are around 100 entries with destination port 25.When I set a filter for destination port = 25 it displays only three items (out of the approximate 100) and when I change the filter to ^25$ then only one entry (the most recent one) is displayed.
Any idea what I can try to be able to correctly filter by destination port? -
When clicking on the 'Cancel' button instead of reloading the page, it should take you
back to the previous page.In my setup, this is what it does, so not sure why it doesn't do that for you? The code for this is in pfSense base code, (pkg_edit.php). What theme are you using?