Home › FAQ

FAQ

Questions, answered.

Open a question for the full answer and links into the user guide. Answers come from the user guide and the project README.

0 of 15 answers opened

Getting started

How do I install pfBlockerNG?

+✓Show answerHide answer

Run the one-line installer from pkg.pfblockerng.com over SSH as root; it detects your pfSense edition and version. It may also be available in System › Package Manager. The UI lives under Firewall › pfBlockerNG.

  1. Open the package repository at pkg.pfblockerng.com and pick a channel (Stable for production).
  2. Run that channel's copy-ready command on the firewall over SSH as root. It is safe to re-run.
  3. Confirm pfBlockerNG appears under System › Package Manager › Installed Packages.
  4. Open Firewall › pfBlockerNG and continue with General setup.
README · InstallationLink to this answer
Getting started

Which channel should I choose?

+✓Show answerHide answer

Stable, unless you want prereleases. Testing validates the next stable, Edge opens the next release family and Nightly is rebuilt from the development tip. A firewall subscribes to exactly one channel.

  1. Stable: production use.
  2. Testing: prereleases validating the next stable.
  3. Edge: prereleases opening the next release family.
  4. Nightly: bleeding edge, rebuilt from the development tip.
  5. To switch, run the same installer with a different --channel. Back up the pfSense configuration before moving to an older version.
README · ChannelsLink to this answer
Getting started

Will the setup wizard overwrite my settings?

+✓Show answerHide answer

Yes. The wizard builds an entry-level IP and DNSBL setup, and if pfBlockerNG was configured before, all settings are wiped when it finishes. Skip it if you already have a configuration.

  1. Back up the pfSense configuration at Diagnostics › Backup & Restore first.
  2. On a new install, run the wizard from the General page to get a minimal baseline.
  3. If pfBlockerNG is already configured, tick "Do not show this again" and press Skip.
Getting started

How do I upgrade?

+✓Show answerHide answer

The Software tab shows your channel and version against the latest and can install updates. A daily check raises one notification per new version. Back up the pfSense config before moving to an older version.

  1. Open Firewall › pfBlockerNG › Software to compare your installed version with the latest in your channel.
  2. Install the update from that tab, or run pkg upgrade pfSense-pkg-pfBlockerNG from the shell.
  3. Upgrades stay within your channel; switch channels with the installer instead.
README · Version upgradesLink to this answer
DNSBL

Why does a listed domain still resolve?

+✓Show answerHide answer

Make sure the client actually queries pfSense Unbound: external or encrypted DNS, VPN resolvers and browser secure DNS bypass it. Then look for a higher-priority allow (feed exception, whitelist, TOP1M, temporary unlock) and apply pending changes.

  1. Confirm the client uses the pfSense DNS Resolver, not an external, encrypted or VPN resolver.
  2. Check Reports for a higher-priority allow: feed exception, Permit source, operator whitelist, TOP1M entry or temporary unlock.
  3. Apply pending DNSBL changes from Update and retry with a fresh query.
User guide · FAQLink to this answer
DNSBL

Does DNSBL block every encrypted DNS service?

+✓Show answerHide answer

No. DNSBL only sees queries that reach Unbound. pfBlockerNG can help manage known encrypted-DNS endpoints, but enforce DNS policy with deliberate firewall and device configuration too.

  1. DNSBL evaluates only queries that reach pfSense Unbound.
  2. Use pfBlockerNG's controls for known encrypted-DNS endpoints as one layer.
  3. Force or permit client DNS behaviour deliberately with firewall rules and device settings.
User guide · FAQLink to this answer
DNSBL

Do DNSBL updates interrupt DNS?

+✓Show answerHide answer

No. Updates swap the new blocklist into the running resolver without restarting Unbound, so queries keep flowing.

  1. pfBlockerNG builds a new DNSBL data set in the background.
  2. It swaps the data set into the running resolver without restarting Unbound.
README · FeaturesLink to this answer
IP & GeoIP

Why are no IP rules visible?

+✓Show answerHide answer

Check that pfBlockerNG is enabled on General, the group and a source are enabled, the action is Deny, Permit or Match (Alias actions create no rules), interfaces are selected on IP, and the change was applied from Update.

  1. pfBlockerNG is enabled on General.
  2. The group and at least one source row are enabled.
  3. The group action is Deny, Permit or Match, not an Alias action or Disabled.
  4. The intended inbound and outbound interfaces are selected on IP.
  5. A pending change was applied from Update.
  6. The update and parser logs show usable addresses.
User guide · FAQLink to this answer
IP & GeoIP

Should I block whole continents with GeoIP?

+✓Show answerHide answer

Usually not. pfSense already blocks unsolicited inbound traffic on WAN, so GeoIP there only helps with open ports. Prefer permitting selected countries, and protect open WAN ports and outbound LAN traffic.

  1. pfSense already blocks unsolicited inbound traffic to WAN.
  2. Use GeoIP where geography is an actual policy requirement.
  3. Prefer Permit rules for selected countries and protect the specific open WAN ports.
  4. Protect outbound LAN traffic too.
IP & GeoIP

Can I create my own pfB_ alias?

+✓Show answerHide answer

No. The pfB_ prefix is reserved, and pfBlockerNG deletes any pfB_ alias it does not manage. Give your alias another name; it can still reference pfB_* aliases as members.

  1. Name your own aliases without the pfB_ prefix.
  2. Add package-managed pfB_* aliases as members where you need them.
README · WarningLink to this answer
Feeds

How do I fix a false positive?

+✓Show answerHide answer

It depends on what blocked it. Find the event in Reports: an IP block needs an IP exception (suppress the address or smallest CIDR), a DNSBL block needs a DNSBL whitelist entry. One does not unblock the other. Reload, verify, and report a bad entry to the feed maintainer.

  1. Find the event in Reports and check whether IP blocking or DNSBL blocked it.
  2. IP block: suppress the exact address or smallest justified CIDR.
  3. DNSBL block: whitelist the required hostname or domain.
  4. A DNSBL whitelist does not unblock an IP block, and an IP exception does not unblock a DNSBL block.
  5. Reload the affected component and verify.
  6. Report a wrong entry to the feed maintainer.
User guide · FAQLink to this answer
Feeds

What happens when a feed download fails?

+✓Show answerHide answer

pfBlockerNG reloads the previously downloaded list, keeping your last known good policy. A download-failure threshold on General limits repeated attempts. Check Logs before replacing the source.

  1. The previously downloaded list is reloaded, so working policy stays in place.
  2. The download-failure threshold on General limits repeated scheduled attempts.
  3. Inspect Logs before replacing or disabling the source.
User guide · FAQLink to this answer
Feeds

Should I enable every feed?

+✓Show answerHide answer

No. Feeds are used at your own risk and the Feeds page warns not to enable them all at once. Start from the wizard defaults and add groups one at a time.

  1. Start from the wizard defaults.
  2. Add one small, reputable source and apply it from Update.
  3. Verify the result in Reports before adding the next group.
Help & support

Where do I get help?

+✓Show answerHide answer

Ask usage questions on r/pfBlockerNG, report defects as GitHub issues, or use the Netgate forum. Include pfSense version, package version and channel, the component and redacted log lines.

  1. Usage and configuration questions: r/pfBlockerNG.
  2. Package defects: GitHub issues.
  3. Community configuration discussion: the Netgate forum.
  4. Include pfSense version, package version and channel, the affected component and redacted log lines.
User guide · FAQLink to this answer
Help & support

How can I support the project?

+✓Show answerHide answer

Star it on GitHub, join on Patreon, help others in the forum, send feedback or patches. Custom, site-specific features are also possible: contact@pfblockerng.com.

  1. Star the repository on GitHub.
  2. Join on Patreon or donate via PayPal.
  3. Help others in the forum, send feedback or code patches.
  4. Ask about custom, site-specific features at contact@pfblockerng.com.
Patreon · AboutLink to this answer
Found your answer?
Help pfBlockerNG keep going.

A star helps others discover it. A Patreon pledge funds new features and support.

Star on GitHub Join on Patreon Still stuck? Ask on Reddit
Top