Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfblocker issue

    pfSense Packages
    2
    5
    1.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      deanot
      last edited by

      I am not sure if this is the wrong forum, if it is I am sorry in advanced.

      pfblocker, is setup and has some countries blocked, is also working…...... maybe.

      Every Time or most times I log in, the widget shows that pfblocker is running, but there are no country block list showing up.  If I force a reload, they are all back there again, so naturally I am wondering if they are actually doing anything, if they are working, if they are loaded or if it is just a bug with the widget.

      Has anyone seen this? have advise?

      Many thanks.

      PFSense System Specs.
      –---------------
      Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
      4 CPUs: 1 package(s) x 4 core(s) 4 port HP Branded Intel Ethernet Card

      1 Reply Last reply Reply Quote 0
      • BBcan177B
        BBcan177 Moderator
        last edited by

        Hi deanot,

        Its not normal at all… Does anything strange show in the pfblockerng.log? Do you only have continent/country blocking and no other block lists?

        What did you select as the "List action" for these Aliases?

        When this happens again, goto the Firewall Tab, and hover-over any of the pfB_ rules and it should popup a table with the IPs that are referenced in the table...

        Also try to run the following command from the shell when its acting this way to see if the tables are still active in pf..

        pfctl -vvsTables

        "Experience is something you don't get until just after you need it."

        Website: http://pfBlockerNG.com
        Twitter: @BBcan177  #pfBlockerNG
        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

        1 Reply Last reply Reply Quote 0
        • D
          deanot
          last edited by

          Hi, thanks for the reply…

          Nothing weird is in the log but it saving a configuration... that is it.

          Continent and Country are the only blocks as of now, I blocked China, Russia and North Korea as of now.

          List action for all of the above is to Deny Both.

          Going into the firewall, I did not see anything under floating.  When I just forced a refresh, the Widget started working and now the rules are under the floating tab within firewall.  Hovering over the rules gives me all the blocked IP addresses.

          I will need to wait for it to do it again, to run the command.  With the rules missing from the floating tab, I am pretty sure they are not working.

          It seems to run fine, at a guess it happens when CRON runs.  I have not changed really anything, from install I just choose the countries and let it do it's thing.

          Kinda weird don't you think?

          PFSense System Specs.
          –---------------
          Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
          4 CPUs: 1 package(s) x 4 core(s) 4 port HP Branded Intel Ethernet Card

          1 Reply Last reply Reply Quote 0
          • D
            deanot
            last edited by

            I was watching the log within PFBLOCKERNG, the CRON ran at 7:00am my time with these results…

            UPDATE PROCESS ENDED [ 05/24/15 6:46:50 ]
            CRON  PROCESS  START [ 05/24/15 7:00:00 ]

            No Updates required.
            CRON  PROCESS  ENDED
            UPDATE PROCESS ENDED

            The rules were still in place and working at this time.

            PFSense System Specs.
            –---------------
            Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
            4 CPUs: 1 package(s) x 4 core(s) 4 port HP Branded Intel Ethernet Card

            1 Reply Last reply Reply Quote 0
            • D
              deanot
              last edited by

              Resolved, turns out there was an IP conflict which was shutting it down…

              PFSense System Specs.
              –---------------
              Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
              4 CPUs: 1 package(s) x 4 core(s) 4 port HP Branded Intel Ethernet Card

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.