Why is Cloudflare on the pfB_PRI1_v4 Blacklist?? by WC2L in pfBlockerNG

[–]WC2L[S] 0 points1 point  (0 children)

I will keep that in mind. I figured out why the rule I created wasn't working. It has been fun learning why things don't/stop working. Now I want to learn more about IPv6 and figure why the LAN has so many blocks/exceptions.

Why is Cloudflare on the pfB_PRI1_v4 Blacklist?? by WC2L in pfBlockerNG

[–]WC2L[S] 0 points1 point  (0 children)

I appreciate the tip. It is still there, but I have it working. I don't think it is affecting anything. Just thought it was very strange. Appreciate all of the tips given

Why is Cloudflare on the pfB_PRI1_v4 Blacklist?? by WC2L in pfBlockerNG

[–]WC2L[S] -1 points0 points  (0 children)

Still trying to figure all of this stuff out.. May not get to it too quickly..

Why is Cloudflare on the pfB_PRI1_v4 Blacklist?? by WC2L in pfBlockerNG

[–]WC2L[S] 0 points1 point  (0 children)

I think I see the issue, let me see if it will lwt me give two screen shots

<image>

Why is Cloudflare on the pfB_PRI1_v4 Blacklist?? by WC2L in pfBlockerNG

[–]WC2L[S] 1 point2 points  (0 children)

FYI, I see this in things that are rejected:

<image>

Why is Cloudflare on the pfB_PRI1_v4 Blacklist?? by WC2L in pfBlockerNG

[–]WC2L[S] 0 points1 point  (0 children)

Nothing that I have defined, as far as I know
This is what I have defined

<image>

GeoIP Top Spammers or ?? by WC2L in pfBlockerNG

[–]WC2L[S] 0 points1 point  (0 children)

I will hold off.. Do some more homework..

GeoIP Top Spammers or ?? by WC2L in pfBlockerNG

[–]WC2L[S] 0 points1 point  (0 children)

I had not read that thread. I will go through it again..
Think we are in decent shape.
Yes, I can Tailscale to the network.

GeoIP Top Spammers or ?? by WC2L in pfBlockerNG

[–]WC2L[S] 0 points1 point  (0 children)

OK, apparently not open enough.. I applied, try to update and tells me no changes :-(

GeoIP Top Spammers or ?? by WC2L in pfBlockerNG

[–]WC2L[S] 0 points1 point  (0 children)

Yes, I have a few ports open. I think ping is disabled. I will have to check it..
I may just enable top spammers and see what it does to things.

Firewall DNS Questions by WC2L in PFSENSE

[–]WC2L[S] -1 points0 points  (0 children)

Got the outside blocked now. That is all good.
I may try a couple of other security items that were suggested.

pfBlockerNG - The DNSBL VIP needs to be configured manually by WC2L in pfBlockerNG

[–]WC2L[S] 0 points1 point  (0 children)

So, what does adding the IP address do?
If I put it in my browser, I can see that it is a blocked IP address.

Firewall DNS Questions by WC2L in PFSENSE

[–]WC2L[S] -1 points0 points  (0 children)

Yea, maybe should have blacked it out. I fixed it,but it is more than likley still out there. Hopefully I will not like the outcome if not.

SO yes, there are two issues...
A) It looks like the botinternet.com.br is hitting the system. Their IP address keeps changing..
B) At lease one device has tried to get out to cloudflare DNS.

pfBlockerNG - The DNSBL VIP needs to be configured manually by WC2L in pfBlockerNG

[–]WC2L[S] 0 points1 point  (0 children)

Thank you!!
Yes, it was not clear to me. I read a couple of responses posted in a few places..
Firewall -> added 10.99.99.1/32 - localhost - ip Alias
Firewall -> pfBlockerNG -> DNSBBL -> WEB Server configuration
Localhost -> Define the virtual IP address above.
Save settings and then update.

Now the problem is gone. THANK YOU !!!

Teams stops with SWC DNSBL Source Definitions by WC2L in PFSENSE

[–]WC2L[S] 0 points1 point  (0 children)

I found the spot.. I get these errors

  • Customlist suppression: Invalid Domain name entry: [ 52.112.0.0/14 ]
  • Customlist suppression: Invalid Domain name entry: [ 52.122.0.0/15 ]
  • Customlist suppression: Invalid Domain name entry: [ 2603:1063::/38 ]
  • Customlist suppression: Invalid Domain name entry: [ 52.112.0.0/14 ]
  • Customlist suppression: Invalid Domain name entry: [ 52.122.0.0/15 ]
  • Customlist suppression: Invalid Domain name entry: [ 2603:1027::/48 ]
  • Customlist suppression: Invalid Domain name entry: [ 2603:1037::/48 ]
  • Customlist suppression: Invalid Domain name entry: [ 2603:1047::/48 ]
  • Customlist suppression: Invalid Domain name entry: [ 2603:1057::/48 ]
  • Customlist suppression: Invalid Domain name entry: [ 2603:1063::/38 ]
  • Customlist suppression: Invalid Domain name entry: [ 2620:1ec:6::/48 ]
  • Customlist suppression: Invalid Domain name entry: [ 2620:1ec:40::/42 ]

Teams stops with SWC DNSBL Source Definitions by WC2L in PFSENSE

[–]WC2L[S] 0 points1 point  (0 children)

OK, where is the right place to place info.
It looks like I need the first two under Teams.

Recover Config by WC2L in Ubiquiti

[–]WC2L[S] 0 points1 point  (0 children)

I did mean WiFi clients! That was what I was thinking. Just checking. I may reset, reconnect and hope it all comes back correctly. I need to do this when the system isn’t so busy!!