Home › FAQ
FAQ
Questions, answered.
Open a question for the full answer and links into the user guide. Answers come from the user guide and the project README.
0 of 15 answers opened
Getting startedHow do I install pfBlockerNG?
+✓Show answerHide answer
Run the one-line installer from pkg.pfblockerng.com over SSH as root; it detects your pfSense edition and version. It may also be available in System › Package Manager. The UI lives under Firewall › pfBlockerNG.
- Open the package repository at pkg.pfblockerng.com and pick a channel (Stable for production).
- Run that channel's copy-ready command on the firewall over SSH as root. It is safe to re-run.
- Confirm pfBlockerNG appears under System › Package Manager › Installed Packages.
- Open Firewall › pfBlockerNG and continue with General setup.
Getting startedWhich channel should I choose?
+✓Show answerHide answer
Stable, unless you want prereleases. Testing validates the next stable, Edge opens the next release family and Nightly is rebuilt from the development tip. A firewall subscribes to exactly one channel.
- Stable: production use.
- Testing: prereleases validating the next stable.
- Edge: prereleases opening the next release family.
- Nightly: bleeding edge, rebuilt from the development tip.
- To switch, run the same installer with a different --channel. Back up the pfSense configuration before moving to an older version.
Getting startedWill the setup wizard overwrite my settings?
+✓Show answerHide answer
Yes. The wizard builds an entry-level IP and DNSBL setup, and if pfBlockerNG was configured before, all settings are wiped when it finishes. Skip it if you already have a configuration.
- Back up the pfSense configuration at Diagnostics › Backup & Restore first.
- On a new install, run the wizard from the General page to get a minimal baseline.
- If pfBlockerNG is already configured, tick "Do not show this again" and press Skip.
Getting startedHow do I upgrade?
+✓Show answerHide answer
The Software tab shows your channel and version against the latest and can install updates. A daily check raises one notification per new version. Back up the pfSense config before moving to an older version.
- Open Firewall › pfBlockerNG › Software to compare your installed version with the latest in your channel.
- Install the update from that tab, or run pkg upgrade pfSense-pkg-pfBlockerNG from the shell.
- Upgrades stay within your channel; switch channels with the installer instead.
DNSBLWhy does a listed domain still resolve?
+✓Show answerHide answer
Make sure the client actually queries pfSense Unbound: external or encrypted DNS, VPN resolvers and browser secure DNS bypass it. Then look for a higher-priority allow (feed exception, whitelist, TOP1M, temporary unlock) and apply pending changes.
- Confirm the client uses the pfSense DNS Resolver, not an external, encrypted or VPN resolver.
- Check Reports for a higher-priority allow: feed exception, Permit source, operator whitelist, TOP1M entry or temporary unlock.
- Apply pending DNSBL changes from Update and retry with a fresh query.
DNSBLDoes DNSBL block every encrypted DNS service?
+✓Show answerHide answer
No. DNSBL only sees queries that reach Unbound. pfBlockerNG can help manage known encrypted-DNS endpoints, but enforce DNS policy with deliberate firewall and device configuration too.
- DNSBL evaluates only queries that reach pfSense Unbound.
- Use pfBlockerNG's controls for known encrypted-DNS endpoints as one layer.
- Force or permit client DNS behaviour deliberately with firewall rules and device settings.
DNSBLDo DNSBL updates interrupt DNS?
+✓Show answerHide answer
No. Updates swap the new blocklist into the running resolver without restarting Unbound, so queries keep flowing.
- pfBlockerNG builds a new DNSBL data set in the background.
- It swaps the data set into the running resolver without restarting Unbound.
IP & GeoIPWhy are no IP rules visible?
+✓Show answerHide answer
Check that pfBlockerNG is enabled on General, the group and a source are enabled, the action is Deny, Permit or Match (Alias actions create no rules), interfaces are selected on IP, and the change was applied from Update.
- pfBlockerNG is enabled on General.
- The group and at least one source row are enabled.
- The group action is Deny, Permit or Match, not an Alias action or Disabled.
- The intended inbound and outbound interfaces are selected on IP.
- A pending change was applied from Update.
- The update and parser logs show usable addresses.
IP & GeoIPShould I block whole continents with GeoIP?
+✓Show answerHide answer
Usually not. pfSense already blocks unsolicited inbound traffic on WAN, so GeoIP there only helps with open ports. Prefer permitting selected countries, and protect open WAN ports and outbound LAN traffic.
- pfSense already blocks unsolicited inbound traffic to WAN.
- Use GeoIP where geography is an actual policy requirement.
- Prefer Permit rules for selected countries and protect the specific open WAN ports.
- Protect outbound LAN traffic too.
IP & GeoIPCan I create my own pfB_ alias?
+✓Show answerHide answer
No. The pfB_ prefix is reserved, and pfBlockerNG deletes any pfB_ alias it does not manage. Give your alias another name; it can still reference pfB_* aliases as members.
- Name your own aliases without the pfB_ prefix.
- Add package-managed pfB_* aliases as members where you need them.
FeedsHow do I fix a false positive?
+✓Show answerHide answer
It depends on what blocked it. Find the event in Reports: an IP block needs an IP exception (suppress the address or smallest CIDR), a DNSBL block needs a DNSBL whitelist entry. One does not unblock the other. Reload, verify, and report a bad entry to the feed maintainer.
- Find the event in Reports and check whether IP blocking or DNSBL blocked it.
- IP block: suppress the exact address or smallest justified CIDR.
- DNSBL block: whitelist the required hostname or domain.
- A DNSBL whitelist does not unblock an IP block, and an IP exception does not unblock a DNSBL block.
- Reload the affected component and verify.
- Report a wrong entry to the feed maintainer.
FeedsWhat happens when a feed download fails?
+✓Show answerHide answer
pfBlockerNG reloads the previously downloaded list, keeping your last known good policy. A download-failure threshold on General limits repeated attempts. Check Logs before replacing the source.
- The previously downloaded list is reloaded, so working policy stays in place.
- The download-failure threshold on General limits repeated scheduled attempts.
- Inspect Logs before replacing or disabling the source.
FeedsShould I enable every feed?
+✓Show answerHide answer
No. Feeds are used at your own risk and the Feeds page warns not to enable them all at once. Start from the wizard defaults and add groups one at a time.
- Start from the wizard defaults.
- Add one small, reputable source and apply it from Update.
- Verify the result in Reports before adding the next group.
Help & supportWhere do I get help?
+✓Show answerHide answer
Ask usage questions on r/pfBlockerNG, report defects as GitHub issues, or use the Netgate forum. Include pfSense version, package version and channel, the component and redacted log lines.
- Usage and configuration questions: r/pfBlockerNG.
- Package defects: GitHub issues.
- Community configuration discussion: the Netgate forum.
- Include pfSense version, package version and channel, the affected component and redacted log lines.
Help & supportHow can I support the project?
+✓Show answerHide answer
Star it on GitHub, join on Patreon, help others in the forum, send feedback or patches. Custom, site-specific features are also possible: contact@pfblockerng.com.
- Star the repository on GitHub.
- Join on Patreon or donate via PayPal.
- Help others in the forum, send feedback or code patches.
- Ask about custom, site-specific features at contact@pfblockerng.com.
No questions match. Try another word, or ask on r/pfBlockerNG.
Help pfBlockerNG keep going.
A star helps others discover it. A Patreon pledge funds new features and support.
You've opened 3 answers. If pfBlockerNG saves you time, a star or a Patreon pledge supports our development.
Star on GitHub Join on Patreon Still stuck? Ask on Reddit